Nairobd
All posts

August 19, 2026 · 5 min read

The security questions to ask before an AI agent touches your data

Shoeb Mahfuz

Co-founder, Network & Cybersecurity Engineer

To be useful, an AI agent usually needs real access — read your inbox, look up a customer record, update a CRM field, sometimes send a message on your behalf. That's a new kind of access point into your business, and it deserves the same scrutiny you'd give any system with that level of reach, not less just because it's framed as AI.

Why this is a different risk than a normal integration

A traditional integration does one narrow thing, the same way, every time — sync field A to field B. An agent makes a decision in the moment about what to do next, based on a prompt and whatever data it's given. That flexibility is the whole value of it, and it's also exactly why scoping its access matters more, not less.

The questions worth asking before you say yes

  • What data can it actually read — one system, or everything a broad API key happens to expose?
  • What can it write or change, and is that scoped down to only what the task needs?
  • Where do the API keys and credentials live, and who else can see them?
  • Is there a log of what it actually did, not just what it said it did?
  • What happens when it's confidently wrong — does a mistake get caught, or does it just ship?

If a vendor can't answer these clearly, that's the answer. “It's powered by GPT-4” is not a security posture.

How we approach this in what we build

Scope access to exactly what the task needs, not the broadest key that happens to be convenient. Keep credentials out of the agent's own prompt or memory. Log what actually happened, so a mistake is debuggable instead of a mystery. And keep a human in the loop for anything that changes real data or spends real money, until the system has actually earned that trust in production.

None of this is exotic — it's the same discipline you'd want from any system with write access to your business. AI doesn't get a pass on it just because the interface is a chat window.