AI Governance

Your AI Agent Seems Friendly. But What Have You Given It Access To?

IT Club Editorial7 minutes read6 October 2026
WhatsAppEmail

IT Club — Powered by Altitude AI (opens in a new tab)

An approachable AI assistant icon beside permission controls for email, calendars, files and business apps.

Keep up with IT Club

Add IT Club as a preferred source in Google Search.

AI agents are being presented as persistent, approachable assistants that can work across connected apps. This practical guide for SME owners and managers examines the human-factors gap between a friendly interface and an agent’s actual access, with specific checks for data, actions, approvals and oversight.

AI agents are starting to arrive with names, characters and more conversational ways of working. A friendly interface can make new technology easier to approach. It can also make it easier to forget that the system behind it may be able to read information or take actions across connected services.

That is a human-factors concern, not evidence that a company is deliberately trying to manipulate people. The practical point is simpler: how an agent feels to use and what it is technically allowed to do are separate questions.

An agent is more than its interface

Meta introduced Muse as a personal AI agent. Meta says Muse can work across applications, send email and book travel through its own secure virtual machine. Meta also describes controls that let users choose connected apps, set access levels, approve certain sensitive actions, inspect an audit trail and disconnect services. Those are Meta’s descriptions of its product and controls; businesses should check the options available in their own account and configuration.

OpenAI describes its dots as persistent, always-on agents powered by GPT-6 Astra, with their own cloud computers. OpenAI says they can work towards goals continuously, connect to thousands of applications through plugins and learn preferences and context over time. OpenAI’s setup guide says access varies by plan and region and lists a UK limitation at launch. Check the current guidance before assuming a feature is available to every UK business.

These examples are not ordinary chat windows. An agent may keep working towards a goal, use connected tools and act on information beyond the message you are looking at. Its avatar or writing style does not tell you how much data it can see, how long access lasts or which actions it can take.

Friendly is not a security control

People naturally respond to social cues such as a name, a voice or a familiar character. A pleasant interface can make a complicated product less intimidating, which is useful. But it may also make a permission request feel more like a routine conversation than a decision about business access.

That does not mean a face always increases trust, or that a particular design has been shown to change how users behave. It means the presentation should not be used as evidence that an agent is safe, reliable or acting in your organisation’s interests. A reassuring “Leave it with me” is not a description of the access being granted.

Separate two kinds of trust

Interface trust: Does this feel clear and comfortable to use?

Technical trust: Is its access limited, visible, reviewable and appropriate for the task?

Ask what the software can do

Before connecting an agent to a work account, mentally set aside its name, face, voice and personality. Assess it as software that will receive specific access. These questions make that assessment concrete:

  1. 1What information can it read: email, calendars, documents, customer records or financial data?
  2. 2Which applications and accounts can it connect to, and can you choose them individually?
  3. 3Can it only read, or can it also edit, delete, send, approve, book or buy?
  4. 4Can it contact people as you or as your business?
  5. 5Does it work only when you ask, or can it continue working in the background?
  6. 6Which sensitive actions need your approval before they happen?
  7. 7Can you see a record of what it did, and can you revoke access promptly?

If you cannot find clear answers, do not treat a friendly explanation as a substitute for them. Start with a smaller, well-defined task and less access, then expand only when there is a clear business reason.

Before you connect an AI agent

  • List the data and applications it will be able to reach.
  • Separate read access from permission to change or send information.
  • Set approval points for sensitive or costly actions.
  • Know where activity is recorded and who will review it.
  • Confirm who can stop the agent and remove its access.

Friendly interface. Serious permissions. Treat both accordingly.

Give access for the task, not the personality

A useful starting point is least privilege: give software only the access it needs for a defined job. If an agent is meant to summarise appointments, that does not automatically justify permission to email customers or change bookings. If it is meant to draft a reply, decide whether it should be able to send that reply itself.

The same discipline applies to ongoing work. Check whether the agent needs access after the task ends, whether its permissions can be reviewed, and what happens if it misunderstands an instruction. For a deeper look at logging, human approval and stopping an agent, read our guide to AI agent access and control.

AI agent access and control: what businesses need →

The key is not to reject friendly design. A good interface can make technology more usable. Just make sure people can see what an agent is allowed to do before they rely on how it presents itself.

The same distinction applies to AI avatars used in customer conversations. Our related article looks at the trust questions raised by a generated face; this one focuses on the permissions behind an agent that can act across services.

AI is getting a face. Will that make us trust it too much? →

The IT Club rule

Judge an AI agent by its permissions, not its personality.

Thinking about using AI agents in your business?

Ask IT Club. We’ll help you understand the permissions, risks and controls in plain English.

Ask the IT Club Advisor →

Found this useful? Forward it to someone who might too.

Sources and further reading

Descriptions of product capabilities and safeguards below are claims from the companies that make those products. Check the current product and account documentation before relying on a feature.

Meta: Introducing Muse, a personal AI agent →

OpenAI: Introducing dots →

OpenAI Help: Getting started with your dot →

Plain-English Takeaway

Judge an AI agent by its permissions, not its personality.

Need help putting this into practice?

IT Club helps you understand the technology. If you need implementation, support or consultancy, the teams behind IT Club can help.

Altitude IT (opens in a new tab) — IT support, cyber security, Microsoft 365 and technology operations.

Altitude AI (opens in a new tab) — AI discovery, automation, governance and implementation.

Enjoyed this article?

Follow The IT Club Briefing on WhatsApp for short daily technology updates and practical business insights.

Have a question we should answer?

Ask the IT Club Advisor