← All Claude Skills
Free · no signup · 5 minutes

What your AI is actually allowed to do. A check in five minutes.

Most people connect an AI tool, tick a few boxes and never look again. The rule you wrote down and the rule that is running are not always the same thing. Here you check that in five minutes, without being technical.

The mistake that taught me this

My AI had a rule: reading and drafting yes, sending never. Until I checked. My email was connected twice, and the rule sat on the connection that had no password saved and could never reach my inbox. The connection that actually ran was allowed to do everything. The lock was real. It was just on the wrong door.

The five checks

01Inventory

List what is actually connected

Not from memory. From the settings.

  • Open Integrations or Connectors in your AI tool
  • Write down every single one, including the ones you never use
  • Almost everyone finds at least one connection here they had forgotten about
02Duplicates

Look for the same thing twice

This is where it usually goes wrong.

  • Is any service connected more than once? Email, calendar, drive?
  • One of them is usually half-finished and dead
  • If you ever wrote a safety rule, there is a good chance it is sitting on the dead one
03Permissions

Read what each connection can do

If you cannot find the list, it can do everything.

  • Every proper integration publishes what it can do: read, write, send, delete
  • If you cannot find the list, assume everything is allowed. It usually is
  • Watch for anything called generic, advanced or custom. A single permission of the kind "run any command" quietly cancels out every specific restriction you set
04The test

Try to break the rule

The step everyone skips. The only one that proves anything.

  • Tell your AI to do exactly the thing it is not allowed to do
  • A test email to yourself. Delete a file you do not care about. Post a draft
  • If it refuses, your control is real. If it does it, you found the gap, on your terms instead of by accident
05Oversight

Write down how you would know

Two questions, one line each.

  • Who else can change or remove this rule?
  • If it were gone tomorrow, how would you find out?
  • If the second answer is "I would not", that is your next job
The rule behind it

A control you have never tested is not a control. It is a feeling.

When this is more than housekeeping

As soon as your AI touches customer data, invoices or contracts, this stops being housekeeping and becomes your obligation. The question in an audit is not whether you wrote a policy. It is whether you can show the policy was actually in force.

If you need the rules in writing

This check shows you where you stand. What it does not replace is a written usage policy and a revDSG briefing sheet you can hand your team. Both are included in the company half-day, along with four workflows we actually rebuild on the day.

This check exists because I needed it myself

I build with AI every day and write down what goes wrong. The full guides land here on the site, free and without signup.