AI agent permissions checklist
Review the smallest useful connection grants before giving an agent access.
Choose the systems
Example: Sam is preparing inbox replies, scheduling proposals and file notes. Select only the systems your task needs.
Selections stay in this browser tab. No account is connected by this checklist.
Write the action rule too: AI agent approval policy.
Read the controls on the security page.
Sam’s permissions checklist
3 systems selected · sources checked 28 September 2026
This is a review worksheet. A draft may require a send-capable scope, so check both the provider grant and the agent’s approval hold before connecting.
Gmail
- ReadFor message contents, review gmail.readonly. For headers and labels only, review gmail.metadata.
- DraftKeep a reply as an unsent draft. Gmail lists gmail.compose for managing drafts, but that scope also permits sending; confirm an approval hold in the agent itself.
- Send or changeGrant gmail.send only when sending is needed. Require approval of the recipient, subject and body before each send.
- Never grant for this taskDo not grant the full mail.google.com scope for inbox triage; it also permits permanent deletion.
- RevokeIn Google Account, open third-party connections, inspect the app, then remove its access to your Google Account.
- MonitorReview sent mail, drafts and the connection’s access after a trial task.
Gmail API scopes · Google connected apps · checked 28 September 2026
Google Calendar
- ReadFor availability alone, review calendar.events.freebusy. For event details, review calendar.events.readonly.
- DraftPrepare an event proposal outside the calendar. Calendar does not list a separate draft-event scope.
- Send or changeGrant calendar.events only when creating or editing events is needed; approve attendee invitations and changes before writing.
- Never grant for this taskDo not grant broad calendar access for scheduling proposals; it includes sharing and permanent deletion.
- RevokeIn Google Account, open third-party connections and remove the app’s account access.
- MonitorCheck new invitations, changed events and unexpected calendar sharing.
Calendar API scopes · Google connected apps · checked 28 September 2026
Google Drive
- ReadPrefer files selected for the task. Review drive.readonly only if wider file reading is necessary.
- DraftPrepare a new file or a proposed edit for review. The drive.file scope can create and modify files the app uses; it is not a draft-only grant.
- Send or changeTreat file sharing and permission changes as external sends. Hold them for approval and inspect the recipient list.
- Never grant for this taskDo not grant full drive scope for a task limited to selected files.
- RevokeIn Google Account, open third-party connections and remove the app’s account access; also review files shared with it.
- MonitorReview changed files, sharing settings and Drive activity for the files involved.
Drive API scopes · Google connected apps · checked 28 September 2026
How it works
Choose the systems a specific task needs. Each section separates reading, preparing a draft and taking an external action.
Review the provider documentation, grant only what the task needs, record a revocation path and inspect activity after the first run. Sources checked 28 September 2026.
Sources and checked dates
- Gmail API scopes
- Calendar API scopes
- Drive API scopes
- Slack OAuth scopes
- Meta WhatsApp Business Platform Cloud API
- GitHub App permissions
- Stripe API keys
- Shopify app access scopes
- Notion connection capabilities
- HubSpot app scopes
- Chrome extension permissions
- Google connected apps
- Google connected apps
- Google connected apps
- Slack app removal
- GitHub App revocation
- Shopify app uninstall
- Notion connection management
- HubSpot connected apps
Limits
- This checklist is advice. It does not grant, restrict or revoke access in any connected system.
- Draft is often an agent workflow hold, not a provider permission. Check the exact consent screen and account role before connecting.
- WhatsApp and a browser with saved logins have connection-specific access paths. Confirm the actual controls in your setup.
Common questions
- Can I give an agent draft access without send access?
- Sometimes. Gmail’s compose scope also permits sending, and other systems may have no draft-only grant. Hold the final action in the agent and test the connection’s actual permissions.
- What should I grant first?
- Select one task and one system. Start with the narrowest read access that can complete it, then add write or send access only after reviewing the exact action.
- Does copying this checklist change my accounts?
- No. The Markdown is a review worksheet. Change or revoke each grant in the provider or integration settings.
- What should I check after disconnecting?
- Confirm the token or app access was removed, then review the provider’s recent activity and any separately shared files, repositories or browser sessions.
Related tools
- AI agent approval policy
Create a reviewable starting policy for agent actions and approvals.
Review access, approvals and receipts before handing recurring work to your operator.
Hand off your first task tonight.
Tell us your email and what you'd hand off first. We'll send your access details and help you set up your operator.