AI tools and safe connections
Connect approved sources and supported actions with explicit workspace boundaries.
Reviewed against the implementation · September 25, 2026
Choose the supported connector
Public knowledge ingestion, agent-only customer context and verified private-order lookup serve different purposes. Use the connector designed for the information you need instead of exposing a general database query endpoint.
Keep permissions narrow
Use read-only credentials and selected source scopes for knowledge. The backend applies workspace boundaries and the connector’s allowlisted operations. Retrieved text is source material, not permission to execute an instruction.
Configure task agents
Task agents have a purpose, assigned product and permitted workflow. Review generated results and configure any supported action path separately. A natural-language task does not grant unrestricted writes to a store, CRM or customer account.
Bring your own data
Use the supported data-connector workflow to preview and approve records. Build a restricted HTTPS endpoint or export that exposes only the intended records; do not give the AI raw production database credentials. Test isolation and unknown-customer cases before activation.