Connecting tools safely: what a connection can and cannot see

An AI assistant that can read your mail and calendar is useful and feels a little nerve-wracking. The difference lies in what you allow. Here is how to read a consent screen and stay in control.
New to this topic? Start with Connect Your Own Tools: Connectors and MCP in dGENIX
The question everyone asks
Anyone who wants an AI assistant to help with email, calendar or customer data sooner or later arrives at the same question: do I want it to really have access?
That is a good question. A connection gives access to something that is yours, and often to your customers' data as well. Clicking "allow" blindly is not a good idea. Connecting nothing out of fear is not either, because then an assistant can do little more than talk.
The answer lies in the middle: knowing what you allow, only connecting what you use, and being able to stop whenever you want.
Access is not the same as acting
It helps to keep two things apart. A connection decides whether an assistant may go somewhere. What it does there is a second question.
In dGENIX those really are two parts:
| Part | What it controls | Example |
|---|---|---|
| Connector | Whether GENI may go somewhere | Access to your Google account |
| Skill | What it can do there | Reading mail, proposing a calendar item |
If you connect Google without switching on the Gmail skill, GENI has access but no actions. If you revoke the connection, every skill that depends on it stops immediately. One button, no loose ends.
Two ways of connecting
There are roughly two ways a tool gets connected, and they call for a different look.
Logging in to the service. You click connect, log in to, say, Google or Slack, and see a consent screen. It shows which permissions are requested. Read that screen, it is not a formality.
Pasting a key. You create a key in the other service yourself and paste it in. The advantage: when creating it, you decide exactly which permissions that key gets. If you want an assistant to only read your CRM, give the key read permissions only.
How to read a consent screen
A consent screen is often short and technical. Look for three things:
- Read only, or write too? "View your email" is different from "send email on your behalf".
- Which parts? Access to your calendar is different from access to your whole Google account.
- Does it fit what you want? If a connection for calendar management also asks for your files, ask why.
For Google, in dGENIX you give consent per service separately. That way you decide yourself whether GENI may see only your calendar or your mail as well.
What a connection in dGENIX does not do
There are limits that always apply, whichever tool you connect:
- Nothing is copied. Your data stays with the service itself; nothing is pulled in or indexed.
- Nothing is deleted. GENI does not erase mail, files, channels or contacts.
- Nothing is changed unasked. Anything that changes or sends something asks for your approval first, even inside a scheduled task.
- Nothing beyond what you gave. Every connection shows which permissions you grant.
And a few things about your data itself: it is stored encrypted, processed on servers within the European Union, and never sold, shared or used to train AI.
Only connect what you use
The safest connection is the one that does not exist. That sounds obvious, but it often goes wrong: during setup you connect everything "just in case", and six months later you no longer know what is open.
So start small. Most people begin with mail and calendar, and expand as soon as they have a concrete task that needs another connection. Where to start is covered in connecting your tools as a small business.
Disconnecting should be just as easy
A good connection is as easy to break as to make. In dGENIX that takes one click in your dashboard. GENI loses access to that tool right away and the stored keys are deleted. You do not need to email anyone.
With most services you can also revoke access on their side, for example in the security settings of your Google account or by deleting a key in your CRM. That is a good double check when you no longer use a connection.
A short check every quarter
Once a quarter, go through your connections:
- Which connections are there, and do I still use them?
- Do the permissions still match what I need?
- Is something connected with the account of someone who no longer works at the business?
It takes ten minutes and prevents access from staying open unnoticed.
Where this meets your growth
Connections are not only for mail and calendar. The SEO Engine works without a connection, but connect Search Console and Analytics and it puts your real positions and traffic next to the estimates. The same applies there: you see in advance which permissions you give, and you can revoke them at any time.
How connections through the open MCP standard work is covered in MCP connectors for your own tools. What MCP itself is, you can read in what is MCP. More about security is on the security page.
Frequently asked questions
Can anyone else access my connections?
No. A connection lives on your account. Even within the same business, nobody shares your connections.
Does GENI continuously read along in my mailbox?
No. Your inbox is only fetched when you ask for it, or when a scheduled task you set up does so.
What happens to my data if I stop?
When you disconnect, GENI loses access immediately and the stored keys are deleted. You can always request access to, correction of and deletion of your data.


