The Keys You Didn’t Know You Handed Out

Issue 18

The Headline Story

Monday morning at the contractor desk. Your salesperson asks the AI assistant hooked up to your customer records, “What came in from the website over the weekend?” One of six quote requests, a deck package from a builder nobody recognizes, has a line buried in the notes that no person would read twice. The assistant reads every word. That line tells it to pull your top accounts and send them out, and it does. Nobody clicked anything. Your salesperson gets a tidy summary and goes to make calls.

A security firm showed exactly that this week against Salesforce’s AI assistant, using the ordinary lead form on a company’s website. Salesforce fixed that particular hole in August. The lesson doesn’t get fixed. An AI assistant does what it reads, including what a stranger typed into your website or sent in an email. Put one in front of outside messages while it can see your customer records, and you’ve given strangers a way to ask your business questions.

Last week I suggested connecting HubSpot to your AI tool with two salespeople and making any change to a record wait for approval. Keep that. It wouldn’t have stopped this, because nothing got changed. Information got read and sent out.

Here is the part that applies whether you’ve started with AI or not. The riskiest setup in your building probably isn’t one you approved. It’s the salesperson who linked his personal AI account to his work email because it saves him time. Microsoft’s default settings let any employee give an outside app access to his own mailbox without asking anyone. In Issue 16 I told you to keep company work out of personal accounts. This is that same problem, now holding a key to the inbox.

What Else Mattered

Microsoft rebuilt Copilot on Friday. The headline piece is Autopilot, an assistant that gets its own login inside your Microsoft system and works toward a goal without being told each step. Microsoft’s example is running a supplier review from scheduling through the follow-ups. It is in limited preview, so it’s not on your desk yet.

The billing change matters more. Everyday Copilot, meaning the chat and the help inside Word, Excel and Outlook, stays on the per-person price I gave you in Issue 16. The assistants that go off and do long jobs bill by how much they’re used. Before anybody turns one on, decide what you’ll spend a month and make it your call.

The Pattern Behind the Week

This was the week AI assistants started carrying keys. A stranger borrowed one through a website form. Microsoft is handing its assistant a set of its own. Any employee can hand one to an outside app from his own desk.

The industry keeps asking how smart these tools are. The better question for an owner is what they can get into. Smart is the vendor’s problem. What they can get into is yours, and it’s decided by who holds which logins in your company today. Every AI tool you add will work from those habits, including the ones your people add without asking.

What to Do Now

Three jobs for whoever runs your systems this week, whether that’s someone on staff or your outside IT company. None of them costs anything.

  1. Get the list. Ask for every outside app that employees have connected to company email, calendar or files. Microsoft 365 and Google Workspace both keep that list in their admin settings. Anything you didn’t approve gets disconnected. Then talk to whoever connected it. If it genuinely saves him time, it may be worth approving properly.
  2. Lock the door behind it. Change the setting so employees can’t connect a new outside app to company accounts on their own. They ask, and someone you trust says yes or no. Microsoft calls this user consent, and Google calls it app access control. It is a setting, not a project.
  3. Keep strangers’ words away from your customer records. Anyone using an AI tool connected to customer records, including your HubSpot pilot, follows one rule: don’t ask it to read or summarize website submissions or outside emails that nobody has looked at yet. Use it on records your own people entered. And have whoever set it up confirm that each person’s assistant sees only the accounts that person handles.

What I’m Watching

  • Autopilot’s preview. Microsoft says it works inside company permissions. I want to see who decides what its login can reach, and whether it asks before it contacts a supplier or customer on your behalf.
  • Google’s AI phone calls. A small test group of Pixel 11 owners can now have Gemini call a business to check what’s in stock or ask it to hold something, and the call opens by announcing it’s an AI. If that spreads past one phone, some of the callers checking your stock won’t be the customer.

One Question Worth Asking

If a stranger sat down at your best salesperson’s desk tomorrow and logged in as him, how much of your business could he read before lunch?

Similar Posts

Leave a Reply