You finally got the Monday status pull working in Claude. Slack summary, sheet update, the whole loop. Then a coworker asks: can you send me how you do that?
The polite answer is to share your setup. The honest feeling is nervousness — because "your setup" is also your mail, your sheets, and half the tools you wired up for other jobs.
People are already past the policy PDF
Okta's AI Agents at Work 2026 survey found that 52% of knowledge workers use AI tools without approval, often on personal accounts. Of those, more than half share internal messages and emails with those tools. Executives still report high confidence that usage is visible and responsible.
That gap is familiar if you are the person who connected the company Claude project. Policies are slow. Personal Claude is fast. So people share access the way they share a Google Doc link — casually, and wider than they meant.
Least privilege is a tool list, not a vibe
Microsoft's guidance on least privilege for AI agents is blunt: if an agent can invoke any available tool, one bad prompt can chain high-impact actions. The practical control is an allowlist — which tools, which actions, for which job.
WorkOS makes the same point in access-control best practices: narrow what the agent can do, instead of hoping the model stays polite.
For a small team, that does not mean building an enterprise identity program first. It means stopping at "here are the three tools for Monday," instead of "here is my whole assistant."
Their catalog vs tools you design
Catalog products are great when you want their library of actions. Zapier MCP is explicit about that job: connect Claude or Cursor to thousands of apps.
That is not the nervous-share problem. When Maja only needs the Monday pull, she does not need every app you ever connected. She still talks to her own chat. She needs a small designed set — hosted, named, and limited — that you can hand over without handing over yourself.
That is the Smia shape: you design the tools, host them on a product server URL, and decide who may call which ones.
What to do on the next "can you send me that?"
- Name the job (Monday status pull), not the assistant.
- Keep the tool list tiny — only what the job needs.
- Share a server URL for that set, not your personal chat with everything attached.
- Leave the rest of your automations on your own connection.
Okta's own advice lands in the same place: make the secure path the easy path. A short, shareable tool surface is easier than a longer policy — and safer than forwarding your Claude.
