Answer
What does it mean to give an AI agent access to your computer or business systems?
It means the agent inherits your permissions. Whatever the account can reach, the agent can reach, including things you forgot it could.
It means the agent acts with the permissions of the account it runs under. The first question is not whether you trust the model, but what that account can already reach. Usually more than anyone remembers.
The mental model people arrive with is a new employee being shown around. The accurate model is a session opened under an existing identity. When an agent runs on a laptop, it can generally read what that user can read: the whole home directory, the credential files the tools left there, the browser profile, the mounted network drives, the cached tokens for every service anyone signed into. Nothing was granted deliberately. It came with the account.
The same applies to business systems through connectors. Attaching an agent to a mailbox is attaching it to every message in that mailbox, including the ones from the accountant and the solicitor. Attaching it to a customer database is attaching it to every record, not to the records relevant to the job. Most tool interfaces are scoped at the level of the system rather than at the level of the task, so the default grant is nearly always wider than the work requires.
This is why the useful control is a separate identity rather than a careful prompt. An agent that runs under its own account, in its own directory, with its own credentials and its own permissions on the systems it needs, has a boundary you can inspect and change. An agent running as you has a boundary that is a list of everything you have ever been given access to, which nobody has read.
The second control is the working area. Agents should operate somewhere that can be inspected and discarded: a dedicated folder, a copy of the data, a branch, a container, a test account. This is not only a safety measure. It substantially improves the work, because an agent that cannot damage anything can be allowed to try things, and trying things is what the loop is for.
The third is knowing what leaves the machine. Any file the agent reads may end up in the request that goes to the model provider, because that is how the system works — reading a file means putting its contents into context. The practical rule is that access and disclosure are the same decision. If a document should not be sent to an external service, it should not be in a directory the agent can read, and no instruction about not using it substitutes for that.
None of this is an argument against granting access. An agent with no access is a slower search engine. It is an argument for granting access deliberately, at the level of an identity and a directory, rather than by default at the level of a person who has accumulated permissions for a decade.
An agent does not get the access you intended to give it; it gets the access the account already had, which is rarely the same thing.
Siddharth Sharma, Context Theory
Related questions
Is a read-only connection safe?
Safe from damage, not from disclosure. A read-only grant removes the ability to change anything and leaves the ability to read everything, and reading is the operation that moves content off the machine. For sensitive systems the meaningful restriction is which records the connection can see, which is a different setting from whether it can write.
What is the minimum sensible setup for a small business?
A dedicated account for the agent, access to one system rather than all of them, a working folder that contains copies rather than originals, and a written note of what that account can reach. The note matters because permissions accumulate quietly, and the only reliable way to know the boundary six months later is to have written it down when it was drawn.
METHOD
Every figure below carries its source and the date it was verified. Nothing on this page is asserted.
The numbers on this page.
| What | Value | Specific to |
|---|---|---|
| Firms that never responded to a web enquiry at all | 23% | Category-wide |
| Sub-15-minute compliance — automated routing vs manual only | 62.5% vs 39.1% | Category-wide |
Oldroyd, McElheran & Elkington, "The Short Life of Online Sales Leads", Harvard Business Review (March 2011) · 1.25M inbound leads across 2,241 US firms · verified
2026 speed-to-lead benchmark · verified
What is specific to this page.
| Kind | Claim | Check it against |
|---|---|---|
| Software | An agent inherits the ambient permissions of the account it executes under, including credential files, browser profiles, mounted drives and cached service tokens that were never granted for this purpose and are rarely enumerated by the person granting access. | Listing what the intended account can already read on the machine and on the network before the agent is installed. |
| Constraint | Access and disclosure are a single decision for an agent, because reading a document places its contents into the request sent to the model provider, so an instruction not to use a file is not a control over whether the file leaves the machine. | The request payload of any tool-using model call that followed a file read, or the provider's documented handling of tool results. |
| Workflow | Most connectors scope at the level of a system rather than a task, so attaching an agent to a mailbox or a customer database grants the whole store rather than the records relevant to the job, making the default grant wider than the work requires. | The permission scopes offered by any mailbox or customer-record integration at the point of authorisation. |
| Procurement | A disposable working area improves agent output as well as limiting damage, because an agent that cannot break anything can be permitted to attempt approaches it would otherwise have to be prevented from trying. | Comparing completion rates for the same task run against originals and against a discardable copy with the same tool set. |
Each row would be wrong on another industry's page. Where a sourced figure exists it is in the table above instead; these are the constraints that shape the work and do not happen to be numbers.
Start with the measurement.
Reading about a benchmark is not the same as knowing your own number. The audit produces yours, measured rather than estimated.
$497 · delivered in 5 business days · credited against month one