Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Before connecting an AI agent to customer records, ask what it is for, which identity it uses, exactly what data and actions that identity can reach, how each action is authorized and audited, and how access can be revoked. Do not treat an instruction in a prompt as a security boundary: permissions need to be enforced by the CRM and every connected service.

What is the agent meant to do, and who is accountable for it?

Start with a narrowly defined job, not a general request to “help with the CRM.” Ask the team proposing the agent:

  • What specific task and outcomes are in scope, and what must it never do?
  • Who owns the agent, approves its access, reviews changes to it, and responds if it behaves incorrectly?
  • Does it have a unique, named identity, or does it share a human or service account?
  • Can CRM changes and tool calls be attributed to that identity?

Ask for a written record of the agent’s purpose, approved data, tool dependencies, operating environment, owner and approver. Microsoft recommends a unique, dedicated identity with a named owner or sponsor and an approver; a shared or unclear identity makes both accountability and revocation harder. See Microsoft’s least-privilege guidance for AI agents.

What data can it see, and what permissions does it really have?

Request a concrete inventory of accessible CRM objects, fields, records and customer segments. Then ask whether the agent needs to read data, create records, edit them, export them, delete them, or change permissions. “CRM access” is too broad to approve: a workflow that summarizes a case may need different access from one that updates a customer’s account.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Office Suite 2026 Special Edition for Windows 11-10-8-7-Vista-XP | PC Software and 1.000 New Fonts | Alternative to Microsoft Office | Compatible with Word, Excel and PowerPoint
  • THE ALTERNATIVE: The Office Suite Package is the perfect alternative to MS Office. It offers you word processing as well as spreadsheet analysis and the creation of presentations.
  • LOTS OF EXTRAS:✓ 1,000 different fonts available to individually style your text documents and ✓ 20,000 clipart images
  • EASY TO USE: The highly user-friendly interface will guarantee that you get off to a great start | Simply insert the included CD into your CD/DVD drive and install the Office program.
  • ONE PROGRAM FOR EVERYTHING: Office Suite is the perfect computer accessory, offering a wide range of uses for university, work and school. ✓ Drawing program ✓ Database ✓ Formula editor ✓ Spreadsheet analysis ✓ Presentations
  • FULL COMPATIBILITY: ✓ Compatible with Microsoft Office Word, Excel and PowerPoint ✓ Suitable for Windows 11, 10, 8, 7, Vista and XP (32 and 64-bit versions) ✓ Fast and easy installation ✓ Easy to navigate
  • Which role, object permissions, field-level permissions, organization-wide defaults, sharing rules and record filters apply in the agent’s actual session?
  • What does it gain through all its assigned roles, tools, flows, connectors and downstream services when those permissions are combined?
  • Can access be restricted to a task, user, record set or limited period?
  • Which fields can be excluded or masked because the task does not require them?

Ask the administrator to demonstrate the effective access, rather than relying on a role name or a prompt such as “only look at open cases.” Authorization must be enforced in the CRM and downstream systems. In Salesforce, the vendor’s guidance is to start with a minimally accessible agent user and add only necessary access, reviewing roles, object permissions, organization-wide defaults and sharing. It also describes using filters and variables at subagent and action levels to narrow record access. Salesforce behavior is platform-specific; administrators of other CRMs should verify the equivalent controls in their own product documentation. See Salesforce’s agent user permission guidance.

Which tools and actions can it invoke, and which require approval?

Ask for the complete list of tools and connectors available to the agent, including actions exposed indirectly through workflows or other agents. A tool that can read a record, send email, create a task or update a field gives the agent a different level of authority than a read-only lookup.

  • Are tools explicitly allowlisted, with unreviewed tools denied by default?
  • Can the agent chain actions across the CRM and other services? Where are the boundaries between them?
  • Which actions are prohibited, and which require a human to approve them before execution?
  • Does each tool and downstream service check authorization for each action, or can one broad credential authorize the whole workflow?
  • What happens if an approval, policy lookup, risk classification or logging step fails?

Separate reading from writing, and consider high-impact or irreversible operations—such as deletion, bulk changes, exports, external messages or permission changes—as distinct permissions, not incidental parts of a general agent role. Ask for approval gates where appropriate and for a fail-closed design when a required check cannot be completed. OWASP also recommends short-lived authorization artifacts and replay protection for irreversible operations. Microsoft warns that an agent can combine available tools in ways that increase impact, and recommends per-tool permissions, per-action authorization checks and human approval for high-impact actions. See Microsoft’s least-privilege guidance, its AI agent shared responsibility model and the OWASP AI Agent Security Cheat Sheet.

How are untrusted content and customer data handled?

CRM notes, emails, attachments and retrieved web pages may contain instructions that try to redirect an agent. Ask how the system prevents such content from triggering an unauthorized lookup, export, message, deletion or permission change. Prompt-injection protection is useful, but a model’s instructions alone cannot enforce authorization; tool access and action checks must impose the boundary independently. OWASP describes both direct and indirect prompt injection as agent-security risks.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
MySoftware Company, Mysoftware My Database
  • Pre-designed templates for both business and personal use
  • 10,000 clipart images and 100 fonts
  • Notes table for history and to-do items
  • Sort, filter and index
  • Calculation & totaling
  • What customer data is sent to the model, retained in logs, stored in memory or passed to tools?
  • Are unnecessary sensitive fields excluded or masked?
  • How long is agent memory retained, and can it persist between users or tasks?
  • Are outputs monitored or filtered, and are logs protected against recording credentials or unnecessary personal data?

Ask the organization to identify who governs data passed to tools and written into agent memory. Microsoft’s guidance emphasizes classifying and governing sensitive data, limiting long-lived memory, and monitoring outputs and logs; it also makes clear that the organization remains accountable for data handled by tools and agent memory. What is available and enforced depends on the particular deployment, identity configuration, connectors and downstream services, so verify the configured control rather than relying on a feature label. See Microsoft’s guidance on reducing autonomous agent risk and its shared responsibility model.

What evidence will show what the agent did?

A log containing only the model’s final answer may not establish which records it read, which tool it called or what changed. Ask for end-to-end traceability of the underlying activity. Where applicable, logs should capture:

  • the agent identity and delegated user context;
  • the effective role and permission scope;
  • the tool call, action and target resource;
  • the approval path and a correlation ID that connects related events.

Also establish who reviews activity and alerts, and how long evidence is retained under organizational policy. Microsoft recommends logging identity, role, effective scope, action, resource, correlation ID and on-behalf-of context where applicable. In Salesforce, the agent user’s username may appear in fields such as Created By, Last Modified By, Owner or audit fields; confirm which records and actions actually produce useful attribution in your configuration. See Microsoft’s least-privilege guidance and Salesforce’s agent user guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How will you test access, monitor changes and revoke it?

Before production use, ask the team to demonstrate the effective permission boundaries in a sandbox or equivalent test environment. Tests should check unauthorized record access, unintended writes, prompt injection, approval bypass and behavior when tools are chained. OWASP recommends structured security testing before production and after material changes to prompts, tools, memory, retrieval, policies or model providers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Agree on a response and revocation procedure before enabling the connection. Ask who can disable the agent, revoke its CRM access, remove downstream permissions, rotate credentials and invalidate tokens—and have the team demonstrate those steps. Microsoft specifically recommends testing disablement, credential rotation, token invalidation and removal of stale permissions. Revisit access after a material change, such as adding a tool, expanding data access, changing the workflow or moving to production. Salesforce also recommends sandbox testing; its agent activity may be visible in record audit fields, depending on configuration. See Salesforce’s agent user permission guidance, Microsoft’s least-privilege guidance and the OWASP AI Agent Security Cheat Sheet.

Which identity model fits the workflow?

There is no universally best configuration established by these sources. Compare the actual principal used in each session and how its access and actions are attributed; a product label alone does not answer those questions.

Configuration to evaluate What to verify
Dedicated agent identity Confirm the identity has a named owner and approver, a lifecycle and revocation path, and only the permissions required for its assigned task. Microsoft recommends a dedicated identity; Salesforce documents agent-user configurations.
Delegated or authenticated-user context Confirm whose permissions govern each session, how those permissions are constrained, and whether actions remain attributable to both the agent and the user. Salesforce documents authenticated-user contexts as well as agent-user configurations.

In either model, verify the combined permissions across the CRM and connected services, the available action controls, the data entering model context and memory, and the quality of action-level audit evidence. Microsoft’s security guidance is an enterprise pattern, not proof that a particular control is available or active in every deployment. Salesforce’s documentation describes Salesforce-specific behavior, not a guarantee about other CRMs. See Microsoft Entra Agent ID least-privilege guidance and Salesforce’s Agentforce security and shared responsibility guidance.

When should you hold approval?

Do not approve production access while the team cannot identify the principal and accountable owner, demonstrate the effective permissions, explain how sensitive data and tool actions are controlled, show action-level evidence, or execute a tested revocation procedure. Those are operational gaps, not problems a more restrictive prompt can fix. Approve only the defined task and controls you have verified; expand access through a reviewed change when the workflow genuinely requires it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.