productivityatlas.

Research / Chapter 08

Before you connect your data

A practical checklist for permissions, retention and an exit path.

Research edition · 14 September 2026

The report’s observations, prices and forecasts are a dated snapshot. Examples of savings are estimates unless explicitly identified as study results. This is not a fresh verification of every claim.

Sensitive-work checklist

Before a tool touches confidential work, record a yes/no/unknown answer for each item:

  • What exact data does the product receive: prompt, file, transcript, screen, calendar, contacts, source records, or device metadata?
  • Is the data encrypted in transit and at rest? Is end-to-end encryption available?
  • Are model providers and subprocessors named?
  • Is customer content used for model training by default, by opt-in, or by account type?
  • What are retention periods for prompts, outputs, recordings, embeddings, logs, backups, and abuse investigations?
  • Can an administrator set deletion, retention, residency, and connector policies?
  • Does the product support SSO, MFA, SCIM, role-based access, audit logs, legal hold, DLP, and SIEM export where needed?
  • Does AI enforce source-system permissions at retrieval time?
  • Can the agent write, send, buy, publish, delete, or change permissions? Are those rights separated?
  • Is there a preview, approval, undo, rate limit, dry run, and kill switch?
  • Can the customer export data in useful formats and migrate workflows?
  • What happens if the vendor changes the model, removes a feature, raises credit prices, or shuts down?
  • Are health, financial, student, employment, legal, or customer data covered by the right contract and regulatory commitments?
  • Can the organization explain to affected people that transcription, profiling, or automation is occurring?

Suggested editorial privacy score

Use a five-dimension score from 0 to 4, with “unknown” distinct from “bad.” Do not collapse it into a single “safe” label without the dimensions.

Dimension 0 2 4
Data minimization Broad collection, unclear scope Scope documented but broad Task-scoped collection and configurable connectors
Training and retention Default reuse or unclear Opt-out or plan-dependent Contractual no-training plus explicit retention/deletion controls
Access and governance Weak sharing controls Basic admin and permissions SSO/SCIM/RBAC, source permissions, audit/DLP/SIEM
Action safety Broad autonomous writes Some confirmation and logs Least privilege, preview, approvals, rollback, rate limits
Exit and resilience Hard export or lock-in Partial export and migration path Full export, versioned workflows, documented subprocessors and continuity plan

The website should publish the score with evidence links, plan scope, review date, and uncertainty. A free consumer plan and an enterprise contract for the same brand are separate privacy products.