Which integrations to avoid
Do not connect everything. Avoid integrations with more permissions than necessary, systems you rarely use, and connections without logging or oversight. Always ask whether the benefit justifies the added risk.
How to limit permissions
Give each integration only the permissions it needs. A CRM connection that only reads contact information does not need write access. For a CMS connection, agree separately who may edit and publish, and which changes need advance approval. In our own Storyblok workflow, the agent sometimes publishes directly; we review the result afterward and correct it where needed.
A practical example
An employee asks Hermes to edit a product description. Hermes reads the current copy from the CMS and prepares an improvement for review. In a draft-first pilot, the employee approves it before publication. Reading, editing, and publishing are separate permissions; restrict each to the agreed workflow rather than assuming that approval itself changes the access rights.
For more on how we set up integrations, see our page on AI automation. To find suitable processes, read our article on automating business processes.