Key Takeaways
- AI access to an inbox and CRM can be safe enough for a defined job when permissions are narrow, sensitive actions require human approval, and someone reviews the activity.
- As at 5 October 2026, Google's full Gmail scope allows reading, composing, sending and permanently deleting all email, so an enquiry assistant needs a careful permissions check.
- As at 5 October 2026, Microsoft application mail permissions can cover every mailbox unless access is scoped and organisation-wide grants are removed.
- Incoming emails can contain instructions aimed at an AI assistant, so inbox automation needs limits on actions and human approval before sensitive changes.
- Australian businesses should check Privacy Act coverage and the OAIC's AI guidance before connecting customer personal information to an AI service.
Yes, but clicking Allow is only the start. I'd judge an inbox and CRM automation on three choices: what access the AI gets, what the AI can do without asking, and who checks the record afterwards.
Is It Safe to Give AI Access to Your Email and CRM?
An assistant preparing enquiry replies has a different risk from an assistant sending replies, deleting messages and changing customer records. The job should decide the access.
OWASP identifies excessive functionality, excessive permissions and excessive autonomy as causes of excessive agency. My practical test is: what can the automation do, what can it reach, and what can it do without asking?
Then I want a record of what happened and a named person reviewing exceptions. The OAIC says AI due diligence should not be a 'set and forget' approach. Approval and monitoring belong in the design before customer data enters the system.
What Permissions Does Clicking Allow Give an AI Tool?
The permission name matters more than the product demo. These examples reflect Google's scope descriptions, Microsoft's permission models and Microsoft's application mail roles as at 5 October 2026.
| Permission | What access means | What I'd check |
|---|---|---|
| Gmail full access: https://mail.google.com/ | Read, compose, send and permanently delete all Gmail email. | Why does this job need permanent deletion? |
| Gmail gmail.readonly | View email messages and settings. | Which messages does the workflow actually retrieve? |
| Gmail gmail.compose | Manage drafts and send emails. | Where is approval enforced before sending? |
| Microsoft delegated access | Acts on behalf of a signed-in user, within that user's access. | Does that user already have unnecessarily broad access? |
| Microsoft application mail access | Can read all mailboxes or send as any user, depending on the granted role. | Has access been limited to the required mailbox? |
Google's compose scope includes sending. A promise to 'only draft' therefore needs an approval rule in the workflow; that permission alone does not enforce the promise.
Microsoft supports mailbox scoping through Exchange Online RBAC for Applications. But broad permissions are additive: Microsoft says organisation-wide unscoped permissions in Entra ID need to be removed. Ask your IT provider to confirm both parts.
What Does Least Privilege Look Like in a Small Business?
Least privilege means giving the connection the smallest access needed for its job. Google recommends the most narrowly focused scope possible; Microsoft recommends minimum permissions.
For an enquiry workflow, I'd start with the enquiries mailbox and the customer details needed to prepare a reply. I'd keep deletion, forwarding and unrelated records outside the workflow.
On the CRM side, I'd request reading access where no update is needed. HubSpot private apps let businesses authorise what each app can request or change. Other CRMs need their own check.
The practical build is: read the enquiry, gather useful context, prepare a reply, hold the reply for approval, then record the outcome. My Gmail enquiry reply guide covers that workflow.
What Is Prompt Injection, and Why Does Email Need Human Approval?
Prompt injection is an attempt to make an AI follow instructions embedded in content the AI reads. OWASP treats prompt injection as a security risk. Anyone who can email your business can put words in front of an inbox assistant.
For example, an email could tell the assistant to forward previous correspondence to a new address. That's an illustrative attack, not a customer instruction I'd let the system execute.
I'd treat incoming email as untrusted content and require approval for sending, forwarding, deleting or consequential CRM changes. The reviewer should see the proposed action and its source. A human gate reduces exposure; it does not guarantee every attack will be caught. See how human approval works in automation.
What Does Australian Privacy Law Expect When AI Uses Customer Data?
As at 5 October 2026, the OAIC defines a small business as having annual turnover of $3 million or less. Coverage has exceptions, including health service providers and businesses trading in personal information. Turnover alone does not settle your obligations.
For covered organisations, the OAIC's AI guidance calls for due diligence, privacy by design and a Privacy Impact Assessment. APP 6 generally limits use or disclosure to the collection purpose, subject to exceptions. OAIC also recommends avoiding personal information, particularly sensitive information, in publicly available generative AI tools.
That recommendation concerns public tools; it is not a blanket ban on business AI. Check the actual product terms. As at 5 October 2026, Google Workspace says customer data is not used for model training without prior permission or instruction, and Anthropic's commercial terms prohibit training on Customer Content from the covered services.
A wrong disclosure can have consequences: covered organisations must notify affected individuals and the OAIC of breaches likely to cause serious harm. This is general information. Check with the OAIC or your adviser, including any automated decision obligations relevant to your workflow.
What Should You Ask Before Granting Access?
I'd ask the builder to show these answers before connecting a live inbox:
- Which mailbox, CRM records and permissions does the job need?
- Which actions require approval, and where is approval enforced?
- Where does customer data go, and which training terms apply?
- What activity is recorded, and who reviews failures?
- How do we stop the system and remove access?
Google Workspace administrators can block third-party apps. HubSpot supports token rotation if a private app token is compromised. Ask for the equivalent exit procedure in your setup.
I'd stop at unexplained full-mailbox access, default sending without approval, missing activity records or vague data-use answers. To find out what's involved, start with a permissions audit: list connected email apps, CRM integrations and their access. The time needed depends on your setup; don't approve a build before that picture is clear.
For an Australian service business that wants AI automation designed, built and run with a person approving anything sensitive, Truespeak is built for exactly that. I run the same pattern in my own business: Hermes and Sevana, Truespeak's own system, watches inboxes and files, asks for approval and reports only problems. Truespeak's method gathers only useful context, protects the human gate and records the outcome.
After launch, Truespeak's managed AI operations covers monitoring, fixing failures, reviewing exceptions and improving rules. Start with a discovery call and one clearly defined job.
Frequently Asked Questions
Does Gmail have a drafts-only permission that prevents sending?
Google describes gmail.compose as permission to manage drafts and send emails. Human approval before sending must therefore be enforced in the workflow rather than assumed from that scope.
Can a Microsoft 365 AI app be limited to one mailbox?
Microsoft supports mailbox scoping through Exchange Online RBAC for Applications. Organisation-wide unscoped permissions must also be removed because permissions are additive. Ask your IT provider to confirm the effective access.
Are business emails used to train AI models?
Check the specific product and contract. As at 5 October 2026, Google Workspace excludes training on customer data without prior permission or instruction, while Anthropic's commercial terms prohibit training on Customer Content from the covered services.
Does being under $3 million turnover mean the Privacy Act does not apply?
Turnover alone does not determine coverage. The OAIC lists exceptions affecting small businesses, including health service providers and businesses trading in personal information. Check the OAIC guidance or ask your adviser.
Sources
Checked 4 Oct 2026.
- Google Gmail API Scopes
- Microsoft Graph Permissions Overview
- Exchange Online RBAC for Applications
- OWASP Excessive Agency
- OWASP Prompt Injection
- HubSpot Private Apps Overview
- Control Which Apps Access Google Workspace Data
- Generative AI in Google Workspace Privacy Hub
- Anthropic Commercial Terms
- OAIC Guidance on Privacy and Commercially Available AI Products
- OAIC Small Business Privacy Guidance
- About the Notifiable Data Breaches Scheme
