Answer
How do you keep AI out of systems it should not touch?
By not connecting them. Every other control is a rule that can be misread, and disconnection is the only one that cannot.
By not granting the connection in the first place. Every other control depends on a rule being interpreted correctly at a moment nobody is watching, and disconnection does not depend on interpretation at all.
The instinct is to write a rule: do not access the payroll folder, do not read the legal correspondence, do not touch the production database. Rules of this kind work most of the time and fail in the situation where they matter — an unusual request, a plausible reason, a path that was not anticipated in the wording. A boundary that depends on interpretation is not a boundary, it is a preference with good intentions.
So the first control is connection. What is not connected cannot be read, and no instruction is required. This sounds trivial and it is regularly violated in practice, because connections are granted broadly at setup time for convenience and never narrowed. Auditing what each tool can currently reach, once, usually produces a surprise and a short list of things to disconnect.
The second is scope within a connection, which matters because most integrations grant more than the job needs. A mailbox connection reaching one label rather than everything. A drive connection reaching one folder. A database connection using an account with access to specific tables. These are configured at authorisation and are much harder to add afterwards, so the effort belongs at setup.
The third is separation of the material itself. Where sensitive content sits in the same location as the material a system needs, no permission scheme can separate them, and the practical fix is to move the sensitive content somewhere the connection does not reach. This is ordinary information housekeeping and it is more effective than any access rule, because it removes the possibility rather than governing it.
The fourth applies to local machines and is the one most often overlooked. An assistant running on a laptop can generally read everything that user can read — the home directory, the credential files, the browser data, the mounted shares — and none of that was granted deliberately. Running the work in a dedicated directory, under a dedicated account, is what turns an unbounded reach into a stated one.
There is a residual case worth naming: material that arrives into a permitted location. A sensitive document dropped into the folder the system reads is now reachable regardless of every decision above. This is a process problem rather than a technical one, and the honest mitigation is to tell people which locations are connected, which is a sentence most businesses have never said out loud.
The system cannot reach what it was never given, and that is the only sentence on this subject with no exceptions.
Siddharth Sharma, Context Theory
Related questions
Is a policy document enough?
For staff behaviour, it is necessary and it is not a technical control. A policy tells people which locations are connected and what not to put there, which addresses the residual case. It does nothing about what a system can reach, and treating it as though it does is how businesses end up with a document and an unbounded connection.
How do you find out what a tool can currently reach?
Check the permissions at the source rather than the settings in the tool: the account it authenticates as, the scopes on that authorisation, and what that account can access in the underlying system. Tool-side settings describe intent and the source-side permissions describe capability, and the second is what matters.
METHOD
Every figure below carries its source and the date it was verified. Nothing on this page is asserted.
The numbers on this page.
| What | Value | Specific to |
|---|---|---|
| Firms that never responded to a web enquiry at all | 23% | Category-wide |
| Sub-15-minute compliance — automated routing vs manual only | 62.5% vs 39.1% | Category-wide |
Oldroyd, McElheran & Elkington, "The Short Life of Online Sales Leads", Harvard Business Review (March 2011) · 1.25M inbound leads across 2,241 US firms · verified
2026 speed-to-lead benchmark · verified
What is specific to this page.
| Kind | Claim | Check it against |
|---|---|---|
| Constraint | A rule about what not to access depends on correct interpretation at an unwitnessed moment and fails on the unanticipated path, whereas an ungranted connection removes the possibility without requiring interpretation. | Testing an access prohibition against a request that reaches the prohibited material by an unanticipated route. |
| Software | Connections are typically granted broadly at setup for convenience and never subsequently narrowed, so a single audit of what each tool can currently reach reliably produces items to disconnect. | Listing the current authorisation scope of each connected tool against what its job requires. |
| Workflow | Where sensitive material shares a location with material a system needs, no permission arrangement separates them, so relocating the sensitive content is the only effective control. | Inspecting the contents of each connected folder or mailbox for material outside the intended scope. |
| Procurement | An assistant on a local machine inherits everything the user account can read, including credential files, browser data and mounted shares that were never deliberately granted, which a dedicated account and directory converts into a stated reach. | Listing what the account the assistant runs under can read on the machine and the network. |
Each row would be wrong on another industry's page. Where a sourced figure exists it is in the table above instead; these are the constraints that shape the work and do not happen to be numbers.
Start with the measurement.
Reading about a benchmark is not the same as knowing your own number. The audit produces yours, measured rather than estimated.
$497 · delivered in 5 business days · credited against month one