Key Takeaways
- Connecting any tool requires an explicit OAuth approval — nothing is read or touched before that exists, and access is scoped per teammate, not shared across the account.
- Six categories of action are server-side gated for every teammate, always: sending email/SMS/voice, ledger posts, payroll, CRM edits, external publishing, and candidate rejection.
- Everything outside a teammate's defined lane is refused and handed back for approval, and every action taken is logged with its reason.
- Custom-built teammates' autonomous reach into every connected tool is still being wired in some cases; the six gated categories above stay fixed regardless.
- Proactive behavior is capped, not unlimited — self-activation up to twice a day, bounded curiosity up to five times a day, one subject per week.
Foster Okonkwo runs a 14-person medical billing service outside Columbus. Before he'd connect anything to his claims system or his inbox, he wanted one question answered honestly: what can this thing actually do on its own, and what can it never do without me finding out first?
That's the real question underneath "is this safe" — not a philosophical one about AI in general, but a specific one about what happens the moment you grant access. The honest answer has two parts: what gets gated no matter what, and what still depends on which teammate and which tool.
What Connecting a Tool Actually Lets an AI Teammate Do
Connecting any tool — Gmail, a CRM, QuickBooks, a claims system — requires an explicit OAuth approval first. Nothing is read or touched before that approval exists, and each connection is scoped and isolated per account, not a blanket key to everything in that tool.
Each teammate is also assigned its own connected systems with a purpose label, not open access to every tool in the business. A billing teammate assigned to the claims system doesn't automatically see the CRM just because both exist in the same account.
This is what a **lane** means in practice: a defined job, the specific systems it reads and writes, and an explicit out-of-lane boundary. Work outside that lane isn't attempted — it's refused and offered back to a person for approval instead.
What an AI Teammate Can Never Do Without Your Approval
Regardless of autonomy level, a fixed set of actions is server-side gated — enforced in the backend, not just a setting a teammate could talk itself out of. Six categories are never autonomous, no matter how the teammate is configured:
1. Sending email, SMS, or voice communication on your behalf
2. Posting an entry to the accounting ledger
3. Sending payroll
4. Editing records in the CRM
5. Publishing anything externally
6. Rejecting a candidate in a hiring pipeline
Every one of these always produces a draft for a person to review, edit, or approve — never a completed action a person discovers after the fact. That distinction is the actual safety mechanism, not a policy promise.
What Happens When a Task Falls Outside a Teammate's Lane
It's refused, not attempted quietly. If Foster's billing teammate hit a claim type outside its defined lane, the honest behavior is to flag it and hand it back — not guess and hope the guess was close enough.
Every action a teammate does take is logged with its reason, creating a real audit trail rather than a black box you have to trust blindly. That log is what lets Foster check, after the fact, exactly why something happened — not just that it happened.
Does This Work the Same Way for a Custom-Built Teammate?
Mostly, but worth being precise here rather than overselling it: pre-built teammates from the ~100-role catalog are further along on autonomous action through every connected tool. For a fully custom-built teammate, that same reach is still being wired on the backend in some cases.
That doesn't change the gated-action list above — those six categories stay gated for every teammate, custom or prebuilt. It means a brand-new custom teammate's day-to-day autonomy might ramp up faster or slower depending on which tools it's connected to.
Meera Deshmukh, who runs a 22-person immigration law firm, hit this directly: she hired a prebuilt Paralegal-Support role from the catalog for document intake, then had a fully custom teammate built for a firm-specific case-status workflow that didn't match any existing role. The prebuilt one was ready to connect to her document system immediately; the custom one needed its connections wired individually before it could act the same way.
Is Sensitive Data Like Patient or Financial Information Actually Protected?
PII anonymization and file virus-scanning are both live safety mechanisms on the platform. For a business handling anything as sensitive as Foster's claims data, that's worth confirming directly against current deployment status before treating it as an ironclad guarantee — the honest answer is "live, worth verifying for your specific use case," not a blanket promise.
Confidentiality policies also travel with the role itself, not just the platform defaults. A finance-adjacent teammate keeps payroll figures confidential the same way a human hire in that seat would; a role handling claims or patient records carries the same expectation, by function, not by name.
Are There Limits on When a Teammate Can Act on Its Own?
Yes — proactive behavior is opt-in and capped, not unlimited. A teammate can self-activate on a schedule up to twice a day, and its bounded "curiosity" about something newly mentioned is capped at five times a day, once per subject per week. It isn't quietly running unlimited background actions.
Why Do the Six Gated Actions Matter More Than a General Safety Promise?
A vague "we take safety seriously" is easy to say and hard to check. Six specific, server-side gated categories are the opposite: each one maps to the exact kind of mistake that's expensive to undo. Sending an email is the one that reaches a real person before anyone catches it. Posting to the ledger or sending payroll is the one that touches money. Editing a CRM record can quietly corrupt data other teammates and people rely on.
Publishing externally is reputational — the one mistake a business can't fully take back once it's public. Rejecting a candidate is the one with a real person on the other end of a decision — see AI for Recruiting for exactly how that gate plays out in a real hiring pipeline. None of these six are hypothetical; they're the specific failure modes that make "the AI did something wrong" expensive, which is exactly why they're the ones locked at the platform level instead of left to a setting.
How Is This Different From the OAuth Access You Already Grant Other Software?
Most businesses already grant OAuth access to several SaaS tools — a scheduling app that reads a calendar, an analytics tool that reads a CRM. The pattern here is the same mechanism, not a new kind of trust: explicit approval, scoped to specific systems, revocable at any time.
What's different is that a teammate's read access can also become write access for specific tasks, which is exactly why the six-category gate and the lane concept both exist — so write access doesn't mean unrestricted write access. See AI for Lead Generation for how the external-communication gate specifically applies to outbound sales work.
Kuvai's Transparency About What It Doesn't Know Yet
A real trust story includes naming the parts that aren't fully nailed down, not just the parts that sound good. One honest example: whether an account-deletion request completes a true hard delete is still being confirmed, not asserted as settled. That's a deliberately unglamorous thing to admit in a piece about safety — and naming it plainly is more useful than a blanket "your data is 100% safe" line that can't actually be checked.
Is It Actually Safe to Connect Your Tools?
The honest version: safety here isn't a claim, it's a mechanism — OAuth approval before any access, a defined lane per teammate, six categories of action that are never autonomous no matter what, and a logged reason for everything else. That's a different question from whether every feature is finished — check the honesty-tagged capability list for anything you're relying on specifically.
For Foster, that meant starting the billing teammate on a narrow lane — draft replies to routine claim follow-ups, nothing sent without review — and widening it once the log showed it consistently got the routine cases right. That's the actual on-ramp, not a leap of faith.
Curious what a teammate built around your own function would actually be allowed to do? Sign Up for Free — no credit card required, free to start, cancel anytime.