Sidekick Orchestration

Is my data safe with AI? What will IT say?

What connecting AI actually means, the difference between reading and acting, and what your IT provider will want to see before anything is connected.

// In this article

Two fair questions usually stop an AI project before it starts: is my information safe, and what will IT say? Here is how we handle both, in plain terms.

This page explains our approach. It is not a security certificate. We will never tell you your data is safe based on a web page.

Where the work runs

Sidekick is a service. The work runs in your own AI account or another account your business controls, connected to the tools you already use, such as Microsoft 365 or Google Workspace.

That matters for three reasons. You choose the plan and settings. You can see and remove access at any time. And after delivery, we do not have ongoing access to your account unless you explicitly share something for support.

Two kinds of access

Most of the worry comes from not knowing what “connecting AI” actually means. There are two kinds of access, and they are very different.

Reading. The AI can look at information, for example your inbox or a folder of files, so it can prepare a brief or a draft. Reading means that information is sent to the AI provider to be processed, so the provider’s plan and settings matter.

Acting. The AI can change something, for example save a draft, update a record or send a message. Acting can change your records, so it needs tighter rules and usually a person approving each result at first.

We start with reading where we can. We add acting only for specific work, once you have seen the results and set the rules. A promise to “only create drafts” does not limit what a connection can do. The permission does. That is why we show the exact permissions, so your IT provider can check them.

What your IT provider will want to know

If your company has an IT provider or an internal IT lead, they will have questions. Good. Before anything is connected, we give them:

  • Which accounts and tools would be connected, and which stay out.
  • The exact permissions requested for each connection, using the provider’s own names, and what each one allows.
  • Whether each connection only reads or can also act.
  • What information is in bounds and what is excluded.
  • Who on your side reviews results and approves access.
  • A read-only first step, if they prefer to start there.

Their decision is simple. Are these connections acceptable? Where should the file-access boundary sit? Who is the admin contact? Normally that takes one or two short conversations, not a project. If they say no to something, we work within that.

What Sidekick does and does not do

  • We do not use your information for model training, and we do not sell it to third parties.
  • Access is granted by you or your IT provider through your own accounts, and can be removed the same way.
  • We document the boundary before launch: what is in bounds, what is excluded, and who approves access.
  • We do not keep ongoing access after delivery unless you explicitly share something for support.
  • We do not decide what is in bounds. You do.

What we cannot promise

We cannot promise that an AI provider will never make a mistake, or that your information is safe in every case. What a provider does with information depends on the service, plan and settings you choose. We help you review those against how sensitive your work is, and we write down the boundary before launch.

Anything with real consequences, such as a message to a client or a change to a record, is checked by a person on your side until you decide otherwise. If your work involves regulated or highly private information, say so early. Some work should stay manual, and we will tell you when we think so.

You do not need to prepare anything for a first conversation. If you want to bring your IT provider, that is welcome. Many of the questions above are easier to answer with them in the room.