iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To find out what an AI agent did, check the activity and recovery history of the service it changed, then review the agent’s connection and account logs for context. To stop it acting again, disconnect it or revoke its permissions. Those are separate steps: removing access does not reverse a completed change, and recovery depends on the affected service.
First, identify the agent, account, and timeframe
Write down the agent’s name, the account it was connected to, the service where you noticed a change, and the approximate time. Check that you are looking at the same provider account the agent used; an app may be connected to one account without having access to your other accounts.
If you use an app connected to ChatGPT, OpenAI documents a way to review connected accounts under Settings > Plugins. Select the relevant app to inspect its connection. Available controls depend on the app, provider account, and workspace settings, and labels or availability may vary by plan, region, account, and product surface. See OpenAI’s connected apps guidance.
Free tools Windows power users keep installed
One-click scans. No signup required.
For a Microsoft-managed Agent ID at work or school, an organization can inspect the agent identity, granted permissions, and sign-in logs in Microsoft Entra. Sign-in records can help establish which identity authenticated and when; they do not necessarily show every change the agent made inside a separate service. Administrators can also review audit records for administrative events. These are Microsoft-specific management controls, not a universal log for consumer AI agents. See Microsoft’s Agent ID sign-in documentation.
#1 Best Overall
Reconstruct what changed in the affected service
Look in the service where the change occurred, because its records are the best place to investigate the change itself. Depending on the service, useful places may include activity or version history, sent items, trash or recovery areas, transaction history, and administrator audit records. The recovery options and retention rules are service-specific; do not assume that an action can be restored just because the agent has been disconnected.
- For email, inspect sent items, drafts, deleted items, and any available message or mailbox activity history.
- For files or documents, look for version history, deleted-file recovery, or the service’s activity log.
- For calendar or workplace changes, check the affected item’s history and ask an administrator about available audit records.
- For purchases or other transactions, consult the provider’s transaction records and its cancellation or dispute process.
Before changing settings, preserve relevant evidence if you may need an investigation: capture screenshots, note timestamps and the agent’s name, and save relevant permission details or logs. Microsoft’s end-user guidance for a suspicious Agent ID says: “Capture a screenshot, note the agent name, and contact your helpdesk or security team for guidance.” See Microsoft’s sign-in process guidance.
Rank #2
Disconnect the agent or revoke access to limit future actions
Choose the control that matches how the agent was connected. Disconnecting a provider account or revoking a permission is a containment step: it limits future access through that grant, but it does not itself undo previous actions.
ChatGPT-connected app
- Open Settings > Plugins in ChatGPT.
- Select the app connected to the account you want to stop using.
- Open its connected-account or connection controls and select Disconnect.
OpenAI says disconnecting stops future access through that account. It does not automatically delete existing conversations or saved memories. Other connected accounts or administrator-managed connections may remain active, so check whether the agent has another route to the same service. See OpenAI’s connected apps guidance.
Microsoft work or school app
- Open the app in Microsoft My Apps.
- Choose Manage your application.
- Review permissions you personally consented to, then choose Revoke Permissions if appropriate.
Microsoft warns that revoking permissions can break some app functionality. My Apps distinguishes permissions you consented to from administrator-consented permissions; a user cannot revoke the latter there. Contact your work or school administrator if the grant is managed by the organization. See Microsoft’s My Apps end-user guidance.
Microsoft Entra Agent ID deployment
An authorized agent owner or administrator can use Microsoft Entra’s agent identity controls to review or manage an Agent ID and its permissions. Disabling identities or changing permissions requires appropriate access; some controls depend on the administrator’s role and licensing. Do not attempt tenant-level changes unless you have the authority to make them. See Microsoft’s Agent ID sign-in documentation and Microsoft Entra Agent ID documentation.
Make future approvals more deliberate
Connection authorization and action approval are different controls. A provider permission grant determines what an app may access; an agent’s approval setting determines when it asks before reading or taking an action. In ChatGPT, permission preferences can affect when you are prompted, but changing that preference does not grant new provider access. To remove existing access, disconnect the app or ask an administrator to disable the connection. See OpenAI’s connected apps guidance and OpenAI’s connector guidance.
Before approving a connection, check who published it and read the listed permissions. Microsoft’s Agent ID consent guidance explains that approval covers the specific permissions shown, rather than unlimited access: “It doesn’t give the agent unlimited access.” Once approved, the agent may use those listed permissions without asking every time, including in the background for configured tasks; additional permissions require a later grant. See Microsoft’s Agent ID sign-in documentation.
Best Value
- Grant only the account and permissions needed for the task.
- Where the product offers it, require confirmation before consequential actions.
- Check whether the connection is personal or organization-managed before relying on a user-level disconnect control.
Know which records answer which question
| Record or control | What it can help establish | What it does not establish by itself |
|---|---|---|
| Agent identity and sign-in logs | Which managed identity authenticated and related sign-in details. | A complete list of every downstream change in another service. |
| Destination service history | Changes recorded by the service, such as edits, sent items, or transactions, where those records are available. | Which connected agent made a change unless the service’s records identify it. |
| Permission or connection settings | Which access grant may still allow future activity and whether it is user- or administrator-managed. | Whether a past action can be recovered or whether all copies of accessed data were erased. |
| Agent-specific telemetry, where available | Potentially, tool approvals and execution results for that particular product. | Comparable logging across every agent. OpenAI’s Codex documentation is a product-specific example, not a guarantee for other agents: OpenAI Codex safety information. |
If the account is managed by your employer or school, you lack permission to change the grant, the history is unclear, or the action could have serious consequences, preserve the records and contact the provider or your organization’s helpdesk or security team.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

