Imagine an assistant whose task is to draft replies from an approved FAQ. It needs access to that FAQ and somewhere to prepare a draft. That task alone does not require permission to send messages, change customer records, or administer a computer.
Separate reading, drafting, and taking action. They are different capabilities. Giving a tool all three at once can make mistakes harder to contain and review.
A useful exercise is to list each permission and finish this sentence: the assistant needs this permission because its assigned task requires it to do this specific thing. If you cannot finish the sentence clearly, reconsider the permission.
Human review should happen before an action when that is the chosen boundary. Reviewing a message after it has already been sent cannot prevent the original send.
Access limits are one part of a design. Also consider which information is approved, how mistakes are detected, who can stop the workflow, and how permissions are removed when a trial ends.
Try the homepage learning challenge to practice matching an assistant’s permissions to a small drafting task. The exercise uses a fictional scenario and does not connect to your accounts.