message.comDevelopers

AI tools and safe connections

Connect approved sources and supported actions with explicit workspace boundaries.

Reviewed against the implementation · September 25, 2026

Choose the supported connector

Public knowledge ingestion, agent-only customer context and verified private-order lookup serve different purposes. Use the connector designed for the information you need instead of exposing a general database query endpoint.

Keep permissions narrow

Use read-only credentials and selected source scopes for knowledge. The backend applies workspace boundaries and the connector’s allowlisted operations. Retrieved text is source material, not permission to execute an instruction.

Configure task agents

Task agents have a purpose, assigned product and permitted workflow. Review generated results and configure any supported action path separately. A natural-language task does not grant unrestricted writes to a store, CRM or customer account.

Bring your own data

Use the supported data-connector workflow to preview and approve records. Build a restricted HTTPS endpoint or export that exposes only the intended records; do not give the AI raw production database credentials. Test isolation and unknown-customer cases before activation.

Continue with the workflow