CRM
CRM is especially valuable for support and sales, but reading context, creating activity and changing sensitive data should be separate permissions.
INTEGRATIONS
AI Employees need to work from authorized sources. This layer explains what can be read, what may be written, which controls are required and why every integration depends on the company’s real system and process.
SYSTEM LAYER
These are system categories, not a promise of universal compatibility or a list of connectors already certified for every vendor.
CRM is especially valuable for support and sales, but reading context, creating activity and changing sensitive data should be separate permissions.
ERP access can unlock high-value workflows, but it is exactly where broad permissions should not be granted for convenience.
Email is one of the most cross-functional integrations, but 'can draft' does not mean 'can send any message'.
Calendar looks simple, but create, reschedule and cancel are different authorities and should be treated that way.
The key rule is simple: do not modify an order without an authoritative match and do not turn a commercial possibility into a real state.
Ticketing works as an incident backbone when the process needs state, owner, SLA and explicit handoffs.
Document management is key for Administration and Billing as long as low confidence, sensitive documents and conflicting versions have a review path.
INTEGRATION CRITERIA
Define which system contains the data considered true for each decision.
Separate read, propose, write and sensitive actions into distinct permissions.
Design what happens when the system fails, data is ambiguous or an action requires human approval.
FROM SYSTEM TO PROCESS
The architecture can adapt to other systems when reliable interfaces and a well-defined process exist, but each connector must be validated in the specific environment.