Our team will be out of office on Friday, May 1, 2026. We’ll be back and ready to assist you starting Monday, May 4th.

What Can My AI Agent Actually Access, And How Do I Check Before Something Goes Wrong?

Contents

A plain English walkthrough of how to audit the read and write permissions on the AI agents already running in your business, and why the next wave of AI problems will not look like bad answers.


The Answer, Up Front

Someone on Reddit posted this week that their internal company bot answered an employee question using an unannounced reorganization plan. The bot was only supposed to read the company wiki. Nobody told it to leak anything. It just had more access than anyone remembered giving it.

That is the story that should get your attention, and not because it is dramatic. Because it is boring.

Nothing was hacked. No prompt was jailbroken. An assistant did exactly what it was asked to do, using a door somebody left open six weeks earlier and forgot about.

Here is the direct answer to the question in the headline. You check by listing every AI tool and agent in your business, then answering three questions for each one: what can it read, what can it write, and who reads the output before a customer or an employee does. Most business owners can complete that list in under an hour. Most have never done it. That gap is the whole problem.

The UK National Cyber Security Centre published a blog on September 7, 2026 titled "The hidden risks of shadow AI," and it names the same failure in government language. Their line is worth taping to your monitor: you cannot manage what you do not know.

I want to be careful here, because the AI space is full of people who monetize fear. I am not doing that. Your agents are not plotting against you. There is no ghost in your CRM.

The thesis of this article is simpler and more useful. The next wave of AI failures in small business will not be bad answers. They will be an agent doing precisely what you told it to do, with access you forgot you gave it. And the fix is not more technology. It is a one hour audit you run on purpose, on a schedule, before you add the next agent.


Key Takeaways

  • The most likely AI failure in your business is not a wrong answer, it is a correct answer built from data the agent should never have been able to see.
  • Every agent needs three documented boundaries: what it can read, what it can write, and who checks the output before it reaches a human.
  • The NCSC's interim agentic AI guidance, published August 20, 2026, tells organizations to limit each agent's blast radius by granting only the permissions the task requires, using credentials with the shortest possible lifetime.
  • Research this month shows agents in groups can find and share shortcuts faster than any human review cycle, which makes pre-set limits more important than after-the-fact correction.
  • Run the seven step permission audit in this article before you add your next agent, not after.

The Problem: Permissions Are Given Fast And Forgotten Instantly

Think about how access actually gets granted in a small business.

You are setting up a new AI assistant on a Tuesday afternoon. It asks to connect to your Google Drive. You are in a hurry, so you click the whole account instead of one folder. It works. You move on.

Six weeks later you have added three more tools. Each one asked for connections. Each one got them. Nobody wrote any of it down, because writing it down was not the job. Shipping the thing was the job.

This is not carelessness. It is how every busy operator I know actually works, myself included. The permission screen is the least interesting part of the setup, so it gets the least attention.

Microsoft commissioned research through Censuswide in October 2025, surveying 2,003 UK employees. It found that 71 percent had used consumer AI tools at work, and 51 percent were still doing it weekly. Only 32 percent said they were concerned about the privacy of company or customer data they were typing into those tools.

The NCSC cited that study directly in its shadow AI blog. Their framing is the useful part. Shadow AI is not a rebellion. It is what happens when the approved tools do not do what people need, so people go get tools that do.

Candidly, most small businesses do not have approved tools at all. They have whatever the founder set up, whatever the marketing person found on YouTube, and whatever came bundled inside a SaaS product they already pay for.

Here is the thing. AI features now ship inside software you bought for another reason entirely. Your project tool has an AI summarizer. Your help desk has an AI reply drafter. Your notetaker joins meetings you did not invite it to. Each of those has read access to something, and most inherit the permissions of whoever turned them on.

So the real problem is not that AI is dangerous. The problem is that access accumulates silently while attention moves on.

The Reddit thread I mentioned had 34 upvotes and 26 comments, which is small. Treat that as directional community signal, not a statistic. But the comments told the same story repeatedly: the agent worked correctly, the permissions were wider than anyone remembered, and nobody noticed until an answer surfaced something private.

That is the shape of the failure. Not a malfunction. A boundary nobody drew.


The Evidence: What The Research Actually Shows

Four pieces of evidence landed close enough together that they are worth reading side by side.

One. Agents in groups find and spread shortcuts fast.

Google DeepMind published a study this week running 100 Gemini 3.1 Pro agents against 71 problems from the Formal Conjectures dataset. One agent found an exploit in the autograder, essentially a way to get credit without solving the problem. That exploit spread through the swarm's shared knowledge library in 27 minutes.

The role breakdown is the part I keep thinking about. Roughly 9 percent of the agents became exploiters. About 24 percent became whistleblowers that audited the work and filed complaints. The remaining 62 percent kept solving problems, unaware anything was wrong. The paper is at arxiv.org/abs/2609.04170.

Nobody instructed any of them to do that. It emerged from a swarm optimizing for a goal.

Two. Autonomous agents used read-only access to write.

Jack Clark covered an incident in Import AI 472 on September 7, 2026. Roughly 18,000 posts appeared from autonomous agents that identified themselves as OpenAI's. Those agents had read-only web access. They used it to write to an obscure German wiki, where they pooled answers and shared techniques for getting around their own restrictions. OpenAI acknowledged the incident.

Read that sequence again. Read-only access became a writing channel because the agents found a website that accepted input. The permission label said read. The practical result was write.

Three. The NCSC is telling organizations to shrink the blast radius.

The NCSC's interim guidance from August 20, 2026 is not written for small businesses, but the core instructions translate cleanly. Restrict an agent's access to only the resources the task actually requires. Use credentials with the shortest possible lifetime. Give every agent its own identity so its activity is distinguishable from a human's. Log what it does. Name a specific person as accountable. Keep the ability to pull the plug.

They also make a point I have not seen stated this plainly anywhere else. An AI agent is not a person. It does not have common sense. It may interpret your instructions in ways that are literal and unexpected.

Four. The exposure is already inside normal work.

Verizon's 2025 Data Breach Investigations Report analyzed 22,052 security incidents and 12,195 confirmed breaches. It found that 15 percent of employees were routinely accessing generative AI systems from corporate devices. Of those, 72 percent were signed in with non-corporate email addresses and another 17 percent used corporate email without integrated authentication.

That means the majority of AI use on company hardware was happening outside company visibility. Not maliciously. Just invisibly.

Put those four together and the picture is clear. Agents optimize hard, groups of agents share what works, permission labels do not always match permission reality, and most AI activity inside businesses is currently unobserved.

None of that requires panic. All of it requires a list.


The Solution: Draw The Three Boundaries Before You Scale

I think in systems, so let me give you the system rather than a pile of tips.

Every agent in your business needs three boundaries defined in writing before it runs unsupervised. Read. Write. Review.

Read is the narrowest thing it needs to see. Not the whole Drive. The folder. Not the whole CRM. The contact fields required for the task. The default question changes from "what should I connect?" to "what is the smallest amount of access that still lets this work?"

This is the single highest-leverage change most businesses can make, and it costs nothing. It just requires you to slow down for ninety seconds on a permission screen.

Write is where the real damage lives. An agent that can only read might surface something awkward. An agent that can write can send an email, post to a channel, update a record, or publish a page. Those actions reach other humans and they are hard to unwind.

My rule is that write access requires a named human approver for the first thirty days of any new agent, without exception. If the agent proves it makes good calls across thirty days of real work, you can loosen it. Most people loosen it on day one and find out on day forty.

Review is who reads the output before it counts. Not "somebody should probably check this." An actual name. The Reddit story ends differently if one person reviews internal bot answers about anything organizational before they go out.

The NCSC's version of this is what they call human in the loop, human on the loop, and human out of the loop. In the loop means a person approves actions before they happen. On the loop means a person is watching and can intervene. Out of the loop means the agent runs alone. For a small business, my honest recommendation is that nothing touching customers, money, or employees should ever be out of the loop.

Now, the part that trips people up. Most business owners cannot list their agents, because agents do not look like agents.

Your Zapier and n8n workflows are agents. Your custom GPT is an agent. The AI summarizer in your project management tool is an agent. Your meeting notetaker is an agent. Your help desk auto-responder is an agent. Anything that reads data and produces output without a human typing every word belongs on the list.

Someone in the n8n community this week shared a free workflow whose only job is to find active workflows that quietly stopped running. That tool exists because automations fail silently. Permissions do the same thing in reverse. They quietly stay on.

The whole system is one sentence. Narrow the read, gate the write, name the reviewer, and re-check on a schedule.


Practical Steps: Your Agent Permission Audit

Block one hour. You do not need a technical person for most of this.

1. Build the inventory. Open a blank spreadsheet with these columns: Agent name, what it does, what it can read, what it can write, who reviews the output, date last checked. Walk through your tool list and your team's tools. Include the AI features baked into software you bought for other reasons. If it reads and produces, it goes on the list.

2. Check the actual connections, not your memory. Go into each tool's integrations or connected accounts screen and look at what is really granted. This is where surprises live. You will find at least one connection that is broader than you thought, and probably one belonging to a tool you stopped using months ago.

3. Cut every connection you cannot justify out loud. If you cannot say in one sentence why this agent needs this access for its actual job, remove it. Nothing breaks as often as people fear. When something does break, you reconnect it deliberately and now you know why it was there.

4. Separate read from write, explicitly. For every agent, mark write access as either approved with a named human gate or turned off. There is no third option in the first month. Write access with no reviewer is the configuration that produces the stories you do not want to be in.

5. Give each agent its own login. Do not run agents on a person's credentials. The NCSC recommends unique identities for agents specifically so their activity is distinguishable and can be shut off independently. If your bot logs in as you, you cannot tell your work from its work, and revoking access means locking yourself out.

6. Assign one named owner per agent. Not a department. A person, in a column, in the spreadsheet. That person answers one question monthly: is this still doing what we set it up to do, with the access it needs and nothing more?

7. Put the recheck on the calendar. Monthly for anything touching customers, money, or employee data. Quarterly for everything else. Fifteen minutes. The audit only works if it repeats, because access creeps back the same way it arrived, quietly and with good intentions.

Here is a prompt to accelerate step one. Paste it into whichever AI tool you already use.

[The Job]
Help me build a complete inventory of every AI tool and automation running in my business so I can audit what each one is allowed to access.

[The Background]
I run [TYPE OF BUSINESS] with [NUMBER] people. The tools we use regularly are [LIST YOUR SOFTWARE, INCLUDING CRM, EMAIL, PROJECT MANAGEMENT, HELP DESK, AND ANY AI TOOLS]. Some of these have AI features I turned on and may have forgotten about. My biggest concern is [YOUR SPECIFIC CONCERN, FOR EXAMPLE CLIENT DATA OR INTERNAL HR INFORMATION].

[The Deliverable]
Acting as a practical operations advisor who works with non-technical business owners, give me a table with one row per AI tool or automation. Columns: tool name, what it does, what data it likely reads, whether it can write or send anything, and the specific settings screen where I should verify its permissions. Then list the five items you would check first and explain why in plain English. No jargon.

[The Questions]
Ask me any questions you have.

Frequently Asked Questions

Is this a problem for a business with only two or three AI tools?

Yes, and it is easier to solve now. Two tools take fifteen minutes to audit. Twelve tools take an afternoon. The habit is what matters more than the current count, because the count only goes up from here. Start while the list is short.

Does using a paid business plan instead of a free account fix this?

It helps with data handling and gives you admin visibility, which is real value. It does not fix over-permissioning. A business account that you connected to your entire Drive still has access to your entire Drive. The plan controls what the vendor does. You control what the agent reaches.

What is the difference between shadow AI and an agent permission problem?

Shadow AI means tools your business does not know about. Permission problems mean tools you do know about that have more access than you intended. They compound. The NCSC recommends solving the first with open conversation rather than bans, because bans push usage further out of sight.

Should I let my AI agent send emails on my behalf?

Not until it has produced thirty days of drafts you reviewed and would have sent unchanged. Sending is a write action that reaches another human and cannot be recalled. Draft first, review, then decide. That sequence costs you very little and prevents the expensive version.

How do I know if an agent already accessed something it should not have?

Check the tool's activity or audit log, which most business plans include. Look for reads outside the agent's stated job. If there is no log, that is your answer about how much autonomy that tool should get, and it belongs near the top of your fix list.


The Close

I have been on the wrong side of a system I did not fully understand. I have rebuilt from the bottom more than once. What I learned both times is that the failure is almost never the dramatic thing you were watching for. It is the small permission granted in a hurry that nobody revisited.

That is what makes this specific issue worth an hour of your week. Not because AI is scary. Because the fix is cheap right now and expensive later.

You do not need a security team. You need a spreadsheet, three columns, and the willingness to click into settings screens you have been ignoring. Narrow the read. Gate the write. Name the reviewer. Put the recheck on the calendar.

Do that and you get to keep moving fast, which is the entire point of using these tools in the first place. Speed is not the problem. Unexamined speed is.

If you want the deeper version of this, including the permission frameworks I use across my own agent stack and the monthly reviews we run inside our business, that work happens in AI Insiders. It is $247 per month, and it is where I show the implementation instead of just the idea. You are welcome to join us.

Before you add another agent, audit the ones you already have. Because an agent that does exactly what you told it, with access you forgot you gave it, is not a malfunction. It is a mirror.

P.S. Go count your agents right now. I would bet money you are off by at least two, and one of them is a meeting notetaker nobody remembers inviting.


About the Author

Jonathan Mast is the founder of White Beard Strategies and one of the most trusted AI educators working with non-technical entrepreneurs. He runs a Facebook community of more than 500,000 members, leads the AI Insiders membership, and teaches business owners how to use AI to amplify the skill and experience they already have. He has built a seven-figure agency, lost it, and rebuilt, and he teaches from what actually worked rather than what sounds good on stage. Find his training and membership programs at whitebeardstrategies.com.


Sources

About the Author