AI assistantCustomAI integrationResourcesContact
Method, access and validation

AI integration for business: connect without opening everything.

Connecting an AI to your emails, calendar, CRM and documents is rarely a technical problem. It is a problem of scope, permissions and validation. Here is how we handle it.

Direct answer

Integrating AI into a company means giving it delegated, limited and revocable access to specific tools — mailbox, calendar, CRM, document storage — then defining, for each action, whether the agent may act alone or must submit its work for validation. The technical connection uses delegated authorisation from your existing accounts: no password is transmitted and access stays revocable at any time. The real difficulty is not the connection, but writing the rules and handling exceptions.

The four tool families

What an AI can do, and under what condition.

Each family raises a different risk question. Handling an email does not commit the company the way writing into a CRM does.

Tool familyReadPossible actionOur recommendation
Mailbox
Gmail, Outlook, IMAP
Defined inbox or folderDraft, sorting, replySending under validation at first
Calendar
Google Calendar, Outlook
AvailabilityProposal, creation, updateAutonomous creation possible, cancellation not
CRM
HubSpot, Pipedrive, Notion
Records and historyNote, task, follow-up updateFinancial fields read-only
Documents
Drive, SharePoint, Notion
Authorised foldersGeneration, draft depositNever deletion or overwrite

The full connector list and status are on the Sania integrations page. For an internal tool without a standard connector, see custom AI agents.

Method

Six steps to an integration that holds.

01

Choose the process before the tool

You do not integrate "the CRM". You integrate what is needed to prepare a follow-up or qualify a request. The process determines access, never the other way round.

02

Inventory the data actually needed

For each step, which information is indispensable? Anything unnecessary should not be accessible. This is also the basis of the minimisation principle under the Swiss FADP.

03

Grant delegated authorisation

Connection from your Google Workspace, Microsoft 365 or CRM accounts, with a chosen scope. No shared password, no generic account, revocable at any time.

04

Write the validation matrix

For each action: autonomous, requires validation, or forbidden. It is the most useful document of the project, and the most often skipped. See our approach to security.

05

Test on real cases in observation mode

The agent prepares, nobody sends. Compare its work with a colleague's on the same files, including the awkward ones.

06

Open autonomy action by action

Grant autonomy where errors are reversible and detectable. Refuse it elsewhere, however convincing the demo was.

Common cases

The integrations SMEs ask for first.

AI and email

Sort, prioritise, retrieve client context and prepare a reply in the authorised mailbox, without sending without approval.

AI assistant for emails →

AI and CRM

Retrieve a contact's history, write a follow-up note, create a task and flag dormant deals.

AI sales follow-ups →

AI and quotes

Turn a request into a structured draft from your authorised services, flagging what is missing.

Creating quotes with AI →
Costly mistakes

Five ways to get an AI integration wrong.

Granting admin access "to move faster"

A broad scope becomes impossible to audit and blocks any later compliance discussion.

Connecting ten tools on the first attempt

Each integration adds a dependency to maintain and a source of error. One is enough to find out whether the process works.

Allowing automatic sending on day one

One wrong message to a client costs more than a week of saved time.

Using a shared generic account

You lose individual traceability, and with it the ability to explain an action afterwards.

Not planning the exit

How do you revoke access, export configurations and stop the service? Decide before, not during an incident.

FAQ

Frequently asked questions about AI integration.

How do you connect an AI to Gmail or Outlook?

Through delegated authorisation: you grant access from your Google Workspace or Microsoft 365 account, choosing the scope of rights. No password is shared, authorisation is revocable at any time from your admin console, and scope can be limited to a mailbox, folder or label.

Does the AI need access to the whole mailbox?

No, and we advise against it for a first deployment. Restrict it to a functional mailbox, a folder or a period. Start with the narrowest scope that still handles the use case, then widen if results justify it.

Can an AI write into a CRM such as HubSpot or Pipedrive?

Yes, if writing is explicitly authorised. Separate read, create and update rights, then distinguish what the agent does alone from what requires validation. A follow-up note can be automatic; changing an amount or deleting a record should not be.

How long does an AI integration take?

For common tools with a standard connector, the technical connection is quick. The real project time is elsewhere: defining rules, exceptions and validation points. That step decides whether the system will be usable and cannot be compressed.

Can you integrate an internal or industry tool with no public API?

Often yes, but that is a custom project rather than a few-clicks connection. Feasibility and cost depend on available access points and data quality. See custom AI agents.

What happens if a third-party tool changes its API?

An integration is a dependency to monitor. Third-party changes are part of maintenance and can alter a behaviour or break a connection. One more reason to limit integrations to those delivering measurable value.

Does data leave Switzerland?

It depends on the components used and must be documented before go-live: application hosting, where model processing happens, sub-processor list, retention periods. This belongs in project documentation. See security and data.

Do we need an IT specialist in-house?

Not for standard connections, which are made from your usual admin interfaces. However, the person who knows the process must be available: they, not an IT specialist, hold the rules to be modelled.

Editorial transparencyWritten by the Swiss Agent Network Sàrl team, publisher of Sania, and reviewed by Ethan Avon, CEO. The permission recommendations described here are those we apply to our own deployments; they do not replace legal advice on your particular situation. Third-party tool capabilities evolve: check the exact scope of rights offered by your provider at the time of connection. Last updated: 30 July 2026.

List your tools. We will list the access needed.

One conversation is usually enough to know whether the integration is simple, complex or pointless.

Talk about my tools →