Map the data path and the agent’s permissions
Review what a tool can read, what it can do and where copies remain before connecting it to practice information.
Draw the whole path
Start with prompt and files → AI service → output and storage. Add connected email, drives, EHR services, search, logs, backups and support access. A chat window or local editor may send information to a cloud model. Identify the actual services involved, not just the app’s name.
For a HIPAA-regulated workflow, assess the cloud service and applicable BAA alongside your risk analysis and safeguards. Processing or storing PHI can create business-associate obligations even if the provider cannot decrypt it. A signed agreement is one part of the workflow assessment.
Separate READ, ACT and STORE
READ: which files, folders, messages and connected accounts are accessible? Read-only access still exposes their contents. ACT: can the assistant edit, delete, send, submit or purchase? STORE: where do prompts, files, results and logs remain, and who can access them?
Use the narrowest real permission settings available. Remove unused connectors and action tools; require review for consequential actions. “Do not send” in a prompt is an instruction, not a revocation of send permission. Starting in an empty folder does not prove an agent is confined to that folder.
Rehearse with fictional inputs
Test reads, proposed edits and failure behavior with fictional files in a dedicated workspace. Review filesystem grants, network access and connector settings before introducing sensitive information. Keep credentials and patient exports out of a teaching workspace.
A model generates an answer; an agent uses tools; the workspace and services determine access. Switching the model does not automatically change the data permissions or agreements.