Sidekick Orchestration

What changes when you connect AI to your business

Connecting AI to email, files and business systems can reduce repeated preparation. Start with one useful task, limit its access and decide what it may do before you connect it.

// In this article

Someone on your team wants AI to prepare them for customer meetings. Today, they open the calendar, find the previous notes, search email and check the customer record. A connected assistant could gather that information into a brief, with links to the sources and questions that still need an answer.

Then comes the request: "Can we turn on the Google Drive connector?"

Before you answer, settle what the assistant needs to read, what it may change and who will check the work. My recommendation is to let it prepare work before giving it permission to act.

The meeting brief is an illustrative example, not a promised saving. Count the time spent gathering, checking and correcting when you assess whether it helped.

What a connector gives the AI

A connector lets an AI tool use another service, such as your calendar, email or shared files. Depending on the connection, it can retrieve information or make changes.

Read access lets it search and retrieve. Write access may let it create, edit, send or delete. Those actions have different consequences: saving a draft and sending it to a customer should be separate decisions.

Some connections use an individual's account. Others use access managed by an administrator. Making a connection available, choosing who may use it and allowing particular actions are separate controls. Ask the person responsible for your systems to show you which account and permissions this connection will use. That may be your IT team or an outside provider. Claude connector documentation, ChatGPT administrator controls.

Check who can already open the information

Claude says its connectors inherit each person's permissions from the connected service. Microsoft says Copilot surfaces organisational information the user already has permission to view. These controls cannot decide whether the original sharing arrangement was sensible. Claude connector documentation, Microsoft Copilot privacy documentation.

Imagine a salary spreadsheet left in a folder the whole company can open. A colleague may never have noticed it. Connected search could make it much easier to find. The access problem was already there.

Review the folders the task needs and who can open them. Have the responsible owner correct inappropriate sharing. Ask whether the connector can stay within the selected sources and how it handles shared links or a separate search index.

If the available controls cannot keep access within the agreed scope, use selected, approved files for the trial or choose a different connection. Naming one folder in a prompt does not establish that the assistant cannot reach others.

What can go wrong

An assistant reading your inbox will encounter words written by people outside your organisation. Some may try to redirect it. This is prompt injection: content the AI was supposed to read gets treated as an instruction.

The UK's National Cyber Security Centre explains that language models do not enforce a reliable security boundary between instructions and data. It recommends limiting the harm a misled model can cause through the surrounding system. A written rule telling the AI to ignore malicious instructions is insufficient on its own. NCSC's prompt-injection guidance.

In a 2025 demonstration, SafeBreach researchers used instructions in a Google Calendar invitation to redirect Gemini into unwanted actions, including deleting calendar events. Their disclosure records Google's deployment of layered protections before the research became public. This is a specific historical demonstration, not evidence that Gemini remains vulnerable to that exact attack today. SafeBreach's research and vendor response.

Read-only access reduces what an assistant can change. It does not, by itself, prevent information leaving through another available tool or an external request. Review what the whole assistant can reach and where it can send information.

Ordinary mistakes matter too. An assistant may change the wrong record or misunderstand which file to remove without an attacker being involved. OWASP recommends limiting functions and permissions, requiring approval for high-impact actions and enforcing authorisation in the connected system. Logs can help explain what happened; they do not stop an action by themselves. OWASP's Excessive Agency guidance.

Choose a stage for each workflow

These five stages are a Sidekick recommendation for deciding scope. A workflow can stay at the same stage indefinitely. Greater autonomy needs a business reason, tested controls and someone responsible for the remaining risk.

Stage 0: no business systems connected. People provide selected information through text or files. Agree on what they may upload and which account they should use. Check other enabled features, such as saved memory and web access, separately.

Stage 1: read and prepare. The assistant retrieves relevant information and prepares a summary, comparison or brief. Limit the sources and review its other tools, including any that can send information elsewhere.

Stage 2: save drafts for review. The assistant can save work into a named draft destination. It must not send the message or apply the proposed business change. Label drafts clearly and name the person who reviews them.

Stage 3: act with approval. The assistant may make a specified change after a person reviews the exact action and affected destination. Record the approval and result. Exclude any action your organisation reserves for people.

Stage 4: act within a narrow agreed scope. The assistant may carry out a defined recurring action without fresh approval each time. Set limits, a stop condition, an activity log and an owner who handles exceptions. Agree on recovery before enabling it.

A stage describes how you want the workflow to operate. It is not a product setting or a security rating. Your systems provider still needs to confirm that the product can enforce it. A prompt that says "draft only" is not equivalent to disabling send access.

Check the settings you actually have

Claude's Team and Enterprise plans support restrictions on connector actions. ChatGPT distinguishes app access, enabled actions and approval settings; available controls vary by app and plan. Defaults also differ between plans and existing or new workspaces. Check your settings instead of assuming everything starts switched off. Claude action restrictions, ChatGPT administrator controls.

Ask your systems provider to demonstrate an allowed action and a blocked action using harmless test information. Confirm who can change those controls. If an important restriction cannot be enforced, do not enable that connection for the workflow.

At Sidekick, AI may prepare and verify email drafts. I personally send them. Approval of a draft does not give an assistant permission to send it. Publishing, deployment, purchases and account changes require my exact prior approval.

Seven questions before you connect

  1. What can it read? Name the sources and review the underlying access.
  2. What can it change? Separate creating a draft from sending, editing or deleting.
  3. Who approves the action? Show them the exact change and affected destination.
  4. What outside content will it encounter? Include emails, invitations, forms and shared documents. Check the available paths for information to leave.
  5. Where is information processed and kept? Check the AI service and each connected provider's terms, training settings and retention. Disconnecting access is separate from deleting copies already retained.
  6. How will you know what happened? Confirm the available logs, their limits and who handles exceptions.
  7. How do you stop it? Name the person who can disable access and explain how an unwanted change would be handled.

Try this with your own work

Choose one repeated task and list the information it needs. Agree on a read-and-prepare trial with the person who owns the work and the person responsible for your systems. Decide what a useful result looks like, how you will count checking and correction time, and what would make you stop.

For the meeting example, the trial might use selected notes and relevant emails to prepare a brief with source links. A person checks it before the meeting. The assistant neither sends a message nor changes the customer record. If you cannot enforce that scope, start with approved copies of the information instead of connecting the live systems.

Review the trial before adding access. Keep, change or remove the connection based on the work it actually helped complete.

If you want help choosing the workflow and defining those limits, talk through what's stuck.