Ep. 63: What Should Your AI Have Access To?
In this episode I cover how AI access and permissions have changed since ChatGPT launched back in 2022, from zero connections and basically zero worry to the current YOLO approach of vibe coders and early adopters. I share what I currently give Claude access to, what my biggest concern is, and offer a read/write/act framework that you can use to decide what your AI should touch.
Let’s Set the Stage
Fair warning: this episode isn’t going to be about me telling you what to do. I really just want to use this episode to highlight how I believe AI sentiment has changed over the past 4 years, and offer up some thinking points, along with some questions that you can ask yourself to determine what you want to do with your AI. Of note, I’m specifically talking about YOUR personal AI and your personal software/tools/information. I’m not discussing what I think these AI companies should or should not have access to…mainly because I don’t want to. Double of note: If at any point during this episode you find yourself saying: “I don’t even know how to connect AI to my other software,” as per always, simply ask the robots.
From Zero Access to AI Everywhere
Let’s start at the beginning. When ChatGPT hit the scene way back in November of 2022, there were really no concerns that I can recall as it related to access. There may have been “what-ifs,” but generative AI was not actually connected to any software or inside of any of the tools that we used on a daily basis, so there was no actual concern to be had.
It wasn’t until a year later, roughly late 2023, when the ability to even connect AI to your software became a thing, when Google let Bard (Google’s chatbot before it was renamed Gemini) pull information from Gmail, Docs, Drive, Maps, YouTube, and Google Flights and hotels.
Real talk, I don’t remember this and honestly have no recollection of Bard, and that’s likely because most people never used Bard (ChatGPT had 10x the traffic at the time). It simply was never the default tool for most people and the name only lasted for about a year.
The true mainstream “AI is in my email” era didn’t really come about until last year, 2025, following the release of MCP (Model Context Protocol — aka how AI connects to software) in November of 2024. For my nerds in the audience, check out episode 51, WTF is MCP?, for the full rundown regarding that specific piece of technology.
So by June 2025, both ChatGPT and Claude had access to Google Workspace, and paying users had the option to grant the robots access to their tools. Thus began the time of really having to think about what we wanted our AI to have access to and what we wanted to keep as strictly ours.
2026: The Year of Agentic AI
If we zoom out, 2026 has really been the year of agentic AI, but developers and early adopters and vibe coders were getting a taste in 2025. I do believe that the release of Claude Code in June of 2025 definitely contributed to the willingness of vibe coders and risk-tolerant early adopters to grant AI access to their workspaces, as they were having firsthand experiences with the capabilities and understanding the possibilities.
Claude Cowork launched in January of 2026, and brought with it the concept (and reality) of agents for the average Jane and Joe, and definitely pushed along early adopters’ willingness to grant AI access to things like Google Workspace.
But, regarding the sentiment held by the general public in 2025, there was absolutely significant hesitation in granting AI access to sensitive workspaces. Based on what I saw on things like Reddit and newsletters I subscribed to, even the early adopters were cautious. Of course there were the YOLO folks who lived by the “move fast and break things” mantra, but for the most part, the early adopters were cautious and the general public was a “that’s gonna be a no for me dog.”
What I’ve Actually Given Claude Access To
Now, I have no hard data on this and I can’t speak to everyone’s experience, but between June of 2025 and present day (October 2026) my own personal willingness to grant AI (Claude especially) access to my workspace and other apps has definitely increased. Here’s what that looks like right now:
- Limited access to Drive
- Access to PowerPoint
- Access to Excel
- Access to my web browser via Claude in Chrome
- Access to calendar via Granola
- Access to podcast transcripts via Descript connector
Claude does not have access to my email, but I can’t help but wonder if it’s just a matter of time (though I truly don’t see a use case for having AI in my email. I just leave shit unswared and unread and it bothers me zero), but that does bring me to the biggest concern I actually have, which is NOT privacy, it’s prompt injection.
My Real Concern: Prompt Injection
Prompt injection is when someone hides instructions inside content like an email, a document, or a webpage that are meant for the AI, not for you. The AI follows these instructions without you realizing it, and bad things could happen.
This means that depending on the permissions you’ve set, when you grant AI access to your inbox, it can read an email that someone has sent with hidden instructions, follow any malicious instructions, and do something like send that person confidential information that it also has access to.
Now, this would require AI to be able to both read and act, which means that if you read the ‘fine print’ when granting AI access to things, you’re already on the path to setting yourself up for success.
A Framework for Deciding What AI Should Touch
AI tends to be most ‘dangerous’ when it can actually do things. Which brings me to my next point: a framework you can use, and questions you can ask yourself, when you’re thinking about what your AI should have access to.
Two questions to ask yourself before connecting AI to anything:
- Read, write, or act? Aka can it see stuff, change stuff, or do stuff?
- Mine, or other people’s? Does this have access to my info/data, other people’s info/data, and can it only interact with my stuff or are other people involved?
Thinking points:
- Low-stakes: read-only, your own stuff (ex: your Drive)
- High-stakes: can act and touches other people (ex: email that can send)
I can’t tell you what you should choose or what’s right for you, and honestly my own answers to these questions varies depending on the task and the specific platform, but this framework is a great starting point.
Privacy: I Don’t Really Care
When it comes to privacy, honestly, I don’t really care. I feel like I get an email every day that some important information from some company I use has possibly been compromised, every app on my phone seems to be tracking everything even after I turn it off, you just think about something and you get an ad for it on IG, there are cameras literally everywhere (I live in LA county), and I have Global Entry (in case you don’t have Global Entry, at some airports you just walk through the corridor and it scans your face without you even needing to stop at a kiosk).
I’m just not under the impression that I actually have privacy any more, and so I’m not really concerned about it, meaning that isn’t a top factor when I’m deciding whether or not AI should have access to something. Again, I’m most concerned with prompt injections and bad humans hacking me.
I will, however, say that when it comes to training and granting these companies access to my data, it’s an immediate hell no for me. Not because of anything privacy-related, but because fuck them. I’m not here to pay them every month and then allow them to train on my work for free. So I always turn that off out of principle.
What About Your Client’s Data?
The question worth sitting with is “what about access to your client’s data?” You may or may be directly using AI for client work, but it is worth noting that transcripts have client information and data, and many online notetakers work via AI. You may not care about your data being out there, but what about your clients? I think the answer to this question will be largely personal, industry-dependent, and thus ultimately up to you with how you want to handle it.
For what it’s worth, I’m definitely seeing more come out on the legal side/disclaimer side of things regarding disclosing AI use and asking for permission.
Flipping the script, I will say that as a client, I would love it if my therapist used AI if she felt it helped her be more present during sessions and made her post-session work easier. I do however realize that everyone doesn’t feel the same, especially regarding sensitive health information while living in a country like the US that very much penalizes you for actually needing to use the healthcare system.
Benefit vs. Risk:
In my opinion, AI access ultimately comes down to benefit vs. risk. Every day, AI gets more capable, more people use it, and it becomes easier to experience first-hand the benefit that it can have. When that very real, very tangible benefit outweighs the risk of something possibly happening related to data compromise or a workspace mistake, folks become more willing to grant AI access to their stuff.
Speaking from experience, and even with something as simple as changing permissions in Claude from “allow once” to “always allow,” when the benefit is clear, the risk starts feeling way less risky.
How I Used AI This Week
Each episode I share a quick example of how I used AI that week.
This week I connected Claude to Descript (one of the video editing software tools that I use) and had it go through the transcripts from my podcast and pull quotes that I could use for social media.
As we know, the better the input the better the output, so my first step was actually to have Claude go look at my Instagram and look at posts from the past month or so and see the quotes that I had used, so it understood what type of quotes I was looking for.
I did have to go back and forth with Claude a few times to get quotes that I was truly happy with, but such is the case when building a new tool or workflow. Worth noting, one of the changes I made that was the most helpful was allowing it to pull copy from across sentences and paragraphs, as oftentimes a single idea is spread across a transcript, not contained in a single sentence.
When all was said and done, Claude had produced about 100 quotes, and while I’d say only about 50% are usable, overall I’m super happy with this use case and will definitely be returning to the well.
Da Wrap-up
At the end of the day, what your AI should have access to is ultimately up to you. My suggestion is to take the read → write → act approach and not just give carte blanche access from the jump, but as always, you’re in charge. Just make sure you’re fully aware of the risks, and consider who all it affects and impacts.
As always, endlessly grateful for you and your curiosity.
Catch you next Thursday.
Maestro out
