Before connecting another app to an AI agent, list what it can read, what it can write, and which action still requires human approval.
Most privacy problems do not begin with the model. They begin with permissions nobody reviewed after setup.
In fact, a useful test is this: if this account were compromised, what could the agent do without asking?
Which permission in your current stack would you remove first?