Blog

Before you connect AI to your inbox: the permission scale no one sets

Meta AI has started connecting to Gmail and Google Calendar, and ChatGPT Voice is already carrying out tasks on the computer. The question is no longer whether the AI gets it right, but what it can do without asking first — and there's a simple scale to answer that before you grant access.

August 11, 2026 · Agência Primeira Página

Before you connect AI to your inbox: the permission scale no one sets

On July 25, 2026, Meta announced that Meta AI now connects to users' Gmail and Google Calendar — delivering daily briefings, handling recurring tasks, flagging schedule conflicts, and running entire projects on its own. That same week, OpenAI expanded ChatGPT Voice to carry out tasks on the computer by voice command. The shift is smaller than it looks in the announcement and bigger than it looks in practice: the assistant stopped just responding and started acting.

And that changes the question your company needs to ask. Until now the question was "does the AI get it right?". From now on it's a different one: "what can it do without asking me first?"

Why "everything" is expensive and "nothing" is useless

Whoever grants full access finds out the problem the first time something goes public: a reply sent to the wrong client, a rescheduled appointment that couldn't be moved, a file shared with someone who shouldn't have seen it. Whoever grants nothing keeps the assistant in the role of an intern who only offers opinions — and then the time savings, which was the whole point, never materializes.

The way out isn't choosing between the two extremes. It's classifying the actions before turning on access.

The scale: reversibility and reach

Two questions solve almost every case. Can it be undone? And who sees the damage if it goes wrong? Crossing the two, actions sort into four tiers:

  • Read, summarize, organize. Reversible and invisible to the outside. The assistant reads the inbox, sorts out what's urgent, summarizes the week, puts together the meeting agenda. Grant this without ceremony — this is where most of the time savings live and the risk is lowest.
  • Write without sending. The draft sits waiting on your screen. Reversible, zero reach as long as no one hits the button. Grant it, and keep the button with you.
  • Act outward. Send an email, reply to a client, accept an invite, publish. Here the error leaves your room and reaches someone. It requires explicit confirmation, one at a time, until you have months of history showing that flow can be trusted.
  • Money, deletion, and access. Pay, transfer, cancel, delete, grant someone permission. This isn't a place for an automatic assistant — not even with a simple confirmation. If it ever is, it should require approval from two people, the way banks have done for decades.

Notice that the scale doesn't ask whether the AI is good. It asks what happens when it gets something wrong — which is the only thing you can actually control ahead of time.

Three data questions almost no one asks before clicking "connect"

Connecting an assistant to the company's email inbox isn't the same as connecting it to your personal inbox. The difference has a name and a law behind it.

  • Whose information will it read? Your corporate inbox is full of third-party data: clients, patients, suppliers, candidates. You're accountable for that data under LGPD (Brazil's data protection law), and "the tool that read it" doesn't transfer that responsibility.
  • What does the provider do with the content? Corporate accounts from serious providers offer a mode where submitted content isn't used for training. That needs to be in writing in the contract, not assumed — and the rules differ between the free and paid versions of the same product.
  • Where is it stored and for how long? Storage location and retention period change what you need to disclose in your privacy policy. If the assistant keeps a history, that history is your problem too.

How we do it in practice

Here at the agency we run automated routines that read email inboxes every day, and the list below came out of what went wrong before it went right:

  • A separate account, never your own. The assistant logs in with its own identity, with the minimum access needed. When something strange happens, you know who it was — and you can shut it down without taking down your own account.
  • Start with the most tedious inbox. Triage and summary of low-risk messages. The gain shows up fast and mistakes are cheap. No one needs to start by delegating the reply to the client.
  • Log everything it did. Without a searchable history, you can't prove the assistant acted correctly, nor find out where it acted wrong. That's worth more than any amount of prompt fine-tuning.
  • Review scheduled on the calendar. Permission granted for one project is still active months later, when no one remembers why it was given. A quarterly review takes care of that.

Where it's still worth it

None of this is an argument for staying out. An assistant that reads the inbox and hands back, every morning, what needs a reply today saves the decision-maker's first hour of the day — and that hour is the most expensive one in the company. The point is that this gain doesn't depend on granting full access; it already happens at the first tier of the scale, which is precisely the lowest-risk one.

If your company is thinking about putting AI to work for real, not just to answer questions, this conversation about scope and permission is part of the project from day one — it's what we cover in AI implementation for businesses. And if the question is when to hand the entire decision over to the machine, we wrote about the criterion in when to let AI decide on its own.

Source

This piece was inspired by the July 28, 2026 edition of the Café com AI newsletter, from IA Club. The facts were checked against public sources: Meta's July 25, 2026 announcement about Meta AI's agentic capabilities with the Muse Spark 1.1 model, including connection to Gmail and Google Calendar, daily briefings, and recurring tasks, in initial availability limited by region.