DocsSign inInstall Kastel
All articles
Getting started

What to prepare before connecting an AI to your email, storage and CRM

Plugging an AI into your organisation’s tools is the easy part. The preparation that matters comes down to three questions, asked source by source before the first click.

By Alexis PratJuly 31, 20265 min read
The short answer

Before the first connection, ask three questions of every source: who is responsible for this source, what does it hold that is sensitive, and who is allowed to read what from it. The connection itself is the easy part. The access decision is the real work, and it should be written down before the AI reads its first line.

The Friday-afternoon OAuth click

On a Friday afternoon, someone enthusiastic clicks “Allow” and connects the company mailbox to an assistant. The whole operation takes two minutes, and that is precisely the problem. Deciding what an AI may do with ten years of archives, with the negotiations, the HR files that arrived in CC and the exchanges with the lawyer, is the actual work. Nobody put it on the schedule, because the button never asks for it.

The consent screen asks a connection question, never a governance question. It asks whether the application may access the account. It does not ask who answers for that account, what sensitive material it holds, or on whose behalf the AI will be reading. Those three questions remain yours, and they come before the click.

Three questions, asked of every source

The first question is about ownership: who in the organisation answers for this source and can arbitrate what it exposes? The second is about content: what does this source hold that is sensitive, including what ended up there by accident? The third is about the right to read: who is allowed to read what from it, and therefore which slice should an AI working for that person receive?

Those answers have to live somewhere. In Kastel, they are written into your organisation’s memory as one rule per person: the right to read is attached to the responsibility of whoever the AI works for, and the filter applies it on every read. You decide what each AI is allowed to see, and that decision carries an author and a history. That is what separates a written rule from a ticked box, and it is the heart of what we call context governance.

Email, storage, CRMOne rule per person, not one checkbox per toolThe slice the AI readsThe rest, out of reach
One rule per person applies across every source at once: the AI receives its slice, and the rest sits outside what is sent.

The traps specific to each source

Email is the most deceptive source, because one person’s mailbox mixes everything: client, HR and legal matters cross in the same thread, and a disciplinary file arrives in CC between two quotes. Delegations and shared mailboxes add a further layer: when three people read the same inbox, who is “the” reader whose right to read the AI inherits? Until that question has a written answer, the mailbox waits.

File storage has a different flaw: its permissions are inherited from folders nobody understands any more. A subfolder opened “temporarily” to the whole company years ago is still open, and the sensitive folder filed in the wrong place inherits the wrong parent’s permissions. An AI connected to that storage reads whatever the permissions allow, including the ones nobody remembers granting.

The CRM looks tidier than it is. It holds customer and prospect data, which comes with obligations of its own, and above all it holds salespeople’s notes, written meeting after meeting by people who never imagined an AI would read them one day. What a salesperson jots down for themselves about a difficult contact was not written to be repeated.

A sensible order to connect in

The sensible order starts with the source whose scope is clearest, the one with an identified owner and the best-understood content. Connect it, then check what the AI actually reads from it by asking questions you already know the answers to. Tighten the rule wherever the reading goes further than you intended, and only then extend, source by source. Connecting everything at once means discovering the problems in production, through questions asked by your teams rather than by you.

Making that gradual extension practical is what Kastel’s catalogue is for: it attaches your existing sources through more than fifty connectors, from email to the CRM by way of file storage, each one respecting the access rights already in place on the connected account. The reading scope, meanwhile, applies across every source at once: one rule per person, not one checkbox per tool. The rule you write for the first source already protects the second, including the sensitive folders a connection must never expose.

Try it on one source, on your own machine

You can test this preparation without asking us anything. Install Kastel’s free core on your own infrastructure, plug in your own AI keys and a single source, the simplest one. Then ask the AI a question whose answer sits in what you meant to exclude: the excluded slice stays out of its reach, and you can open the rule that decided it. The day you wonder who can see what when an AI plugs in, the answer will be written on your side, not ours.

Ready to connect the first source?

The connection guide follows exactly this order: install the core, write the rule, connect one first source, check what the AI reads from it, then extend.

Follow the connection guide