Skip to content

What to check before you connect your inbox

On this page

Connecting an email tool takes about forty seconds. It’s also the largest permission most small businesses will grant this year, and pausing over it is the right instinct. The work worth doing sits in the twenty minutes before it, and most of that work happens inside your own account rather than the vendor’s.

  • Four of the checks happen inside your own provider account and your own mailbox. You can make every one of them before you’ve picked a product.
  • The screen where you approve the connection writes the boundary in your provider’s words rather than the vendor’s. It’s the only point in the whole arrangement that does. It’s also the shortest thing you’ll read that day, and the least read.
  • Two questions decide whether this is yours to decide: what your mailbox contains, and who administers it. Google and Microsoft have opposite defaults on the second one.
  • You can withdraw the connection whenever you like. The copy made while it was live stays on the vendor’s retention schedule, which is why these checks belong before rather than after.

Start with what is already connected

Your account already holds grants like this one. The ones sitting there now are almost certainly worse than the one you’re about to add.

Open the page in your own account that lists them. On a Google account it’s under Data and privacy, at myaccount.google.com/linkedapps. On a Microsoft work or school account it’s My Apps. On a personal Microsoft account it’s the consent management page. What you find will be a mail merge tool from 2021, a scheduling app somebody trialed for a week, and a CRM you stopped paying for two summers ago. Something in there may be a mystery to you. Each one still holds a named authorization with a list of permissions attached to it.

Do this first for two reasons, and the second is the one people miss.

The obvious reason is that removing dead access is the highest-value ten minutes of security work available to a small business. It’s worth doing whether or not you connect anything new. Take Google’s own warning at face value: “If you remove access, the app can’t access your Google Account. This may make some features unavailable.” Something may break. Finding that out on a quiet Tuesday is the point.

The less obvious reason is calibration. You’ll read the permission list at the end of a signup flow, under mild pressure. The product will be one you’ve already half decided to buy. So read three of them first, cold, about tools whose jobs you already understand. Ten minutes there makes you a completely different reader of the screen that matters.

One thing worth knowing: tightening the rules later applies from that moment forward. Microsoft is explicit that “Any updates to user consent settings only affect future consent operations for applications. Existing consent grants remain unchanged, and users continue to have access based on the permissions previously granted.” (Microsoft, checked September 7, 2026.) Old grants go away when somebody goes and removes them.

While you’re in there, turn on two-step verification for the provider account itself, if it’s still off. Every grant you issue hangs off that account, and why the mailbox was always the master key makes the case that one afternoon protects more than anything else here.

Whose decision this actually is

If your mail is a personal Gmail or Microsoft account, the decision is entirely yours, and you can skip to the next section. If it runs on Google Workspace or Microsoft 365, there’s an administrator somewhere, and the two platforms behave in opposite ways.

Google Workspace blocks first. An app still waiting for an administrator’s setting is called unconfigured, and “When a user attempts to access an unconfigured third-party app, access is blocked by default.” (Google, checked September 7, 2026.) The request lands on a list in the Admin console for review. An administrator can allow it, dismiss it or block it outright. So on Workspace, the likeliest thing that happens when you try to connect is that nothing happens. The fix is an administrator marking the app as trusted, and it sits on their side rather than yours.

Microsoft 365 allows first. Microsoft’s position is that “By default, all users are allowed to consent to applications for permissions that don’t require administrator consent. For example, by default, a user can consent to allow an app to access their mailbox but can’t consent to allow an app unfettered access to read and write to all files in your organization.” (Microsoft, checked September 7, 2026.) So an employee can connect an AI email tool to their own work mailbox this afternoon, entirely on their own, as long as the setting is still where it starts. Microsoft itself recommends narrowing it: “we recommend that you allow user consent only for applications that have been published by a verified publisher.”

Three practical consequences, depending on which chair you’re sitting in.

If you own the business and administer the mail, both facts are yours to act on today, and the Microsoft one is the more urgent. The question “has anyone here already connected an AI tool to their mailbox” has an answer, and it’s on the enterprise apps page rather than in anybody’s memory.

If somebody else administers your mail, the email to send is short and specific. Name the application, name the permissions it’ll ask for, and ask whether it’s already configured. Sent on Monday, it’s a formality. Discovered on Thursday afternoon, it’s a wall.

And if you administer mailboxes for other people, the connection decision belongs to the firm rather than to one person. Where those boundaries sit for a small practice belongs with a simple AI policy a small firm will actually use.

What is in the mailbox changes the answer

Almost all business mail is sensitive, so asking whether yours is sensitive flags everything and decides nothing.

The useful test is narrower. Does your mailbox routinely carry a category that requires a specific document to exist before anyone connects anything to it? Three come up constantly in small firms.

Protected health information. Under HIPAA a covered entity may let another company create, receive, maintain or transmit protected health information on its behalf. One condition comes first. The covered entity “obtains satisfactory assurance that the business associate will appropriately safeguard the information”, documented in a written contract (45 CFR 164.502(e)(1)(i), checked September 7, 2026). So if patient information arrives in the mailbox as a matter of routine, a business associate agreement comes before the connection, and a great many email products don’t offer one at all.

Customer financial information at a firm inside the FTC Safeguards Rule. The rule’s covered list names “tax preparation firms” directly (FTC, checked September 7, 2026). It requires taking “reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue” and requiring those safeguards by contract (16 CFR 314.4(f)). So the choosing itself is the regulated act, and what that does to picking a supplier is an argument with more in it than this page has room for.

Client confidences held by a lawyer. ABA Formal Opinion 512, issued July 29, 2024, concluded that “a client’s informed consent is required prior to inputting information relating to the representation into such a GAI tool”, where the tool is self-learning. The opinion also treats a boilerplate line in an engagement letter as unlikely to carry that weight on its own.

The practical form of this check takes about ten minutes, and you can run it without a policy document. Search your own sent folder for the three or four things it’d be worst to find, and see whether they’re there. If they are, the question moves past whether the vendor is trustworthy and becomes whether the instrument exists at all. Asking for it while you’re still a prospect costs one email. Asking for it after your staff have grown fond of the software costs a great deal more, because by then the answer you want is the only one you can afford.

Reading the permission list

This is the checkpoint. The words on it are your provider’s rather than the vendor’s, which makes it genuinely different from everything else you’ll read.

On Google’s screen, the mail lines you might see are these, in Google’s own wording. Four of the five are what Google classifies as restricted scopes.

  • “Read, compose, send, and permanently delete all your email from Gmail.” This is full mailbox access.
  • “Read, compose, and send emails from your Gmail account. This scope does not allow immediate, permanent deletion of threads and messages, bypassing the trash.”
  • “View your email messages and settings.” Read only.
  • “View your email message metadata such as labels and headers, but not the email body.” Headers and labels only.
  • “Send email on your behalf.” Sending alone, which Google classifies as sensitive rather than restricted.

(Google, checked September 7, 2026.)

Microsoft’s consent prompt shows display text taken from the permission the app asked for. “Read user mail” is the read-only one. “Have full access to user mail” covers creating, reading, updating and deleting mail. Microsoft notes that it “Does not include permission to send mail”. Sending is a separate line reading “Send mail as a user” (Microsoft Graph, checked September 7, 2026).

Now the judgment, which is where most advice on this subject goes wrong.

A long list is normal here, and you can relax about the length of it. An AI email client that files, drafts, schedules and sends has to read, write and send, and a read-only grant would leave it unable to file a single thread. Calendar and contact lines will usually be there too, and for a product that arranges meetings that’s what you bought. Counting the lines and taking fright is how people fail this check while feeling careful.

The line worth stopping on is the first one. Look at what separates the top two Google entries: permanent deletion that bypasses the trash. Everything an email assistant does works fine with the trash in place. The trash keeps a wrong decision recoverable for thirty days, and it does more work for you than most of the safety features on any vendor’s page. So here is the one place to be firm. A tool asking for the version of the permission where a mistake can’t be walked back should be able to explain why, and the explanation is a fair thing to want before you approve rather than after.

The second habit is a comparison rather than a rule. Hold the list against what the product told you it does. A tool sold as a read-only summarizer, asking to send mail as you, is a mismatch. That mismatch tells you more than any security page will, because only one of those two documents was written under someone else’s constraints.

Then screenshot it. One keystroke, and it’s the only record of what you agreed to that came from somebody other than the vendor. What happens to your mail on the other side of that screen, and how long each piece of it lives, is a separate subject with a real answer: where your mail goes when AI reads it.

What a verified badge is worth

Both platforms verify publishers. Both verifications answer a narrower question than people assume.

Microsoft shows a blue verified badge in the consent prompt, and it’s precise about the meaning: “the organization that publishes the app has been verified as authentic by Microsoft.” Its own FAQ is just as precise about the limits. “The blue verified badge doesn’t imply or indicate quality criteria you might look for in an app. For example, you might want to know whether the app or its publisher have specific certifications, comply with industry standards, or adhere to best practices. Publisher verification doesn’t give you this information.” (Microsoft, checked September 7, 2026.) The badge confirms identity. Care is a separate question.

There’s a stronger signal on the Google side, and it sits behind the screen rather than on it. Every one of those Gmail lines is a restricted scope. Restricted scopes carry a requirement most people have never heard of: “Every app that requests access to Google users’ restricted data and has the ability to access data from or through a third-party server must go through a security assessment from Google-empanelled security assessors.” It stays current, too. “To keep access to any verified restricted scopes, apps must be reverified for compliance and complete a security assessment at least every 12 months after your assessor’s Letter of Assessment (LOA) approval date.” (Google, checked September 7, 2026.)

Read that as a floor and it’s a useful one. A product you can connect to a Gmail mailbox today, in production, with real mail permissions, has been through an independent security assessment within the last twelve months. That’s worth more than a logo on a marketing page. You’ll likely have to find it out for yourself, because a floor everyone shares makes a poor differentiator.

A floor is what it is, though. A security assessment speaks to how a company protects the data it holds. What that company keeps, for how long, what it builds out of your mail, and which other companies see fragments of it all live in the vendor’s own documents. The questions that get real answers out of a vendor is the list to put in writing.

A missing verification says more than a present one. If Google puts an unverified app screen in front of you for a product that’s been selling for two years, that’s a fact about the company’s stage rather than its intentions, and you’re entitled to weigh it however you like.

When the screen itself is the attack

For real businesses, this usually goes wrong at a genuine consent screen belonging to an application that’s pretending to be something else.

Microsoft names it: “Consent phishing attacks trick users into granting permissions to malicious cloud applications. These malicious applications can then gain access to legitimate cloud services and data of users.” Microsoft also explains why your usual instincts stay quiet: “Because a legitimate provider (such as the Microsoft identity platform) hosts the application, unsuspecting users accept the terms.” (Microsoft, checked September 7, 2026.)

Everything on that screen is authentic except the app. The address really is Microsoft’s or Google’s. The padlock is real. The permission list is real, and it’s honestly displayed. The attack skips your password entirely, so two-step verification stays quiet as well, because the door is being opened rather than forced. You’re being asked, correctly and through the proper channel, to hand something over.

Microsoft’s own advice is blunter than most security pages manage. “Don’t rely on application names and domain URLs as a source of authenticity. Attackers like to spoof application names and domains that make it appear to come from a legitimate service or company to drive consent to a malicious application.” Alongside it, a check anyone can run: “Check for poor spelling and grammar. If an email message or the consent screen of the application has spelling and grammatical errors, it’s likely a suspicious application.”

It reduces to one rule, and it’s the most useful sentence on this page. Start the connection from inside the product you decided to buy. Type the vendor’s address yourself, sign in, and click connect there. Then the consent screen in front of you is one you went and asked for, which is the whole difference. A screen you arrived at from a link in a message can render beautifully and still belong to somebody else. The wider version of that instinct, applied to mail that’s after something from you rather than from your software, is suspicious mail and where AI should stay out of it.

Doing it in an order that tells you something

Order matters here for one reason. The connection is reversible and its consequences are not.

Withdrawing the grant ends access from that moment onward, cleanly, from an account the vendor doesn’t control. The copy of your mailbox synced while it was live stays where it is, along with the index built from that copy and the summaries. Those are separate objects on their own retention schedules, and the vendor’s policy decides them rather than a switch. So the reversibility you hold runs forward, which is exactly why the twenty minutes of checks belong before the connection. Where the two handles on a live connection are, and which one belongs to you, is set out in where your email credentials are kept.

The order, then.

  1. Clear the dead grants already on the account. Ten minutes, and worth doing regardless of what you decide next.
  2. Establish whether the decision is yours. Workspace blocks by default and Microsoft 365 permits by default, so the answer depends on which one you’re on. If somebody else administers the mail, send that email now.
  3. Search your own mailbox for the categories that need a document first. If one is there, ask for the document before anything else happens.
  4. Collect the vendor’s documents while you’re still a prospect. That’s when questions get answered fastest and most completely, and today is the easiest this will ever be.
  5. Reach the consent screen from inside the product, read it, and screenshot it. This is the only step where the words belong to your provider.
  6. Connect one mailbox and leave the settings where they arrive. The first afternoon proves very little either way, and what to do with day one is about why a mailbox at rest is the least representative test you’ll ever run.
  7. Put a date in the calendar to look at the grant again. Ninety days is enough. The list of connected apps you were shocked by in step one got that way because nobody ever went back.

The same checks put to Point

Point is an AI email client and connects through the same two doors as everything else here, so every check above applies to it. Here’s which document holds each answer, so the reading is yours rather than mine.

  • Point’s own terms put step five on you, in as many words. Section 4.3 lists the customer’s responsibilities for a connected account. Among them is “reviewing OAuth scopes and permissions before authorizing access”. Alongside it sit having the rights, permissions, notices and consents needed to connect each account, and disconnecting accounts that should no longer be used (terms, checked September 7, 2026). That’s an accurate division of the work, and reading the screen is the part only you can do.
  • The regulated-data question has a direct answer, and its sequence is the point. Section 1.5 states that “Point does not offer HIPAA, business associate, financial-services, tax-return, payment-card, government, education, or other regulated-data commitments by implication”. Any such commitment arrives as a separate written document identifying the covered services, data category and effective date. The terms also record that connected accounts may contain regulated information, and that ensuring the connection is lawful sits with the customer. So if your mailbox carries protected health information or tax return information, those two sentences decide what happens before the sign-in.
  • The documents for step four are published rather than described. The privacy policy itemizes what’s held and what’s derived from it. The terms hold the deletion window and the regulated-data carve-out. The page at subprocessors names the companies, with a version and an effective date on it, so you can notice a change yourself rather than wait to be told about one.
  • There are two handles on the connection, and one of them is yours alone. You can disconnect an account inside Point. You can also withdraw the grant from the provider account you had before you met the company. The second one works on a day when you’ve stopped believing anything the first one tells you.
  • What Point can reach and how much Point does are separate settings. The grant fixes the reach. How much Point does is a dial, and each kind of work holds its own. Every kind of work starts on review, where Point prepares and waits for you. Setting how much your inbox does on its own is where each position ends.
  • A second business connects its own account under its own grant, and each stays on its own side, which is keeping one business isolated from another.

The full inventory of what happens once a mailbox is connected is on the benefits page.

Common questions

How long should all of this actually take?

About half an hour if you do it properly, and the half hour spreads unevenly. Clearing old grants is ten minutes. Checking who administers your mail is five. Searching your own mailbox for regulated categories is ten, and reading the consent screen carefully is two. The part that takes real time is getting a vendor’s documents and asking follow-up questions, and that runs in the background while you do everything else. You can do all of it without a lawyer. The one step that has ever needed one is the regulated-data instrument, if your mailbox turns out to need it.

I am not the administrator of my email. What do I need to ask for?

Name the application, name the permissions it’ll request, and ask whether it’s already configured in the admin console. On Google Workspace that’s a specific action an administrator takes, since unconfigured apps are blocked by default and your attempt to connect will simply fail. On Microsoft 365 the more useful question is whether user consent has been narrowed. If it’s still wide open, you may be able to connect on your own, and being able to is a different thing from being agreed. Ask anyway. The version of this that becomes a problem later is the connection nobody knew about.

Is a long list of permissions a bad sign?

Usually it’s fine, and treating it as a warning is the most common way to fail this check while feeling careful. An AI email client needs permission to read, write and send before it can file, draft, schedule or send, and calendar and contact permissions follow from anything that arranges meetings. Your attention belongs on a specific line rather than on the length of the list. The Gmail permission that includes permanent deletion bypassing the trash gives up the mechanism that makes mistakes recoverable, and an assistant does its whole job without it. The other thing worth attention is a mismatch between the list and what the product said it did.

Should I connect a test mailbox first instead of my real one?

Rarely worth it, and it usually costs you more information than it saves. An empty or synthetic mailbox gives the software nothing to rank, nobody to learn and no real pressure, so what you’ll be evaluating is whether it runs rather than whether it helps. The better version of the same caution is to connect the real mailbox and leave every autonomy setting where it arrives. Then the tool reads and prepares while you form a view. If you genuinely run a second, quieter business, connecting that one first is a reasonable compromise, because the mail in it is real.

I connected something and now I have second thoughts. What do I do?

Withdraw the grant from your own provider account. That one works on your own, without the vendor’s cooperation or a working login on their side. Then ask them in writing to delete the copy and everything derived from it. Those are two different acts, and the first one is entirely within your control. Access stops immediately. What was already synced, indexed and summarized is governed by the vendor’s retention terms, which is why the deletion request is worth making in writing and keeping. Where your mail goes when AI reads it sets out what those objects are and how long each tends to live.

The short version

  • Clear the old grants on your account before you add a new one. Whatever you find there is the real state of your exposure, and the ten minutes are worth spending on their own.
  • Find out whose decision this is before you make it. Google Workspace blocks unconfigured apps by default. Microsoft 365 lets a user consent to mailbox access by default. Those two facts lead to entirely different Mondays.
  • Search your own mailbox for the categories that need a document first. Protected health information needs a business associate agreement. A firm inside the FTC Safeguards Rule needs the safeguards in a contract. A lawyer using a self-learning tool needs the client’s informed consent.
  • Read the consent screen, in your provider’s words, and screenshot it. A long list is normal for this kind of product. The line to question is the one that permits permanent deletion bypassing the trash.
  • A verified publisher badge confirms identity and stops there, in Microsoft’s own words. Google’s restricted-scope security assessment is a real annual floor, and it speaks to how a company protects data rather than to what gets kept.
  • Start the connection from inside the product, by typing the address yourself. A real consent screen for a fake application is the failure mode that beats every other precaution on this list.
  • You can withdraw the grant from an account that is yours alone. The copy made while it was live is a separate question with its own answer.

If what’s holding you up is the underlying discomfort rather than the checklist, why you are right to be careful with AI begins where the feeling does.

Ready for a calmer inbox?

Join the private beta

We're onboarding a few teams at a time. Leave your email, confirm it once, and we'll send an invitation the moment a place opens.

By joining you agree to our privacy policy.

Private beta

What you're joining

It runs on the mail you have

Point sits on top of Gmail or Outlook. Your address, your history and your contacts stay exactly as they are, so there is nothing to migrate.

You set how much Point does

Out of the box everything waits for your review, replies included. You hand over only what you trust, one kind of work at a time.

Join the private beta

We're onboarding a few teams at a time. Leave your email, confirm it once, and we'll send an invitation the moment a place opens.

By joining you agree to our privacy policy.