Ten questions to ask before an AI vendor gets access to your CRM
By Manoj Gurumurthy · 2026-10-07 · 6 min read
Every useful AI agent ends up touching your customer data. A voice agent that books site visits needs your calendars. A WhatsApp agent that answers order questions needs your order system. A follow-up workflow needs write access to your CRM.
That is fine, as long as you know exactly what you are handing over. Most security problems with AI vendors are not exotic attacks. They are ordinary access that nobody wrote down. These are the questions we would ask any vendor, including us.
Where the data lives
1. Whose accounts will the system run in? The safest answer is yours: your telephony provider, your WhatsApp Business account, your cloud project, your automation workspace. If the vendor runs everything in their own accounts, you are renting the system, and leaving later means rebuilding it.
2. Which AI model providers will see our data, and what exactly do they receive? A voice agent usually sends audio or transcripts to a speech provider and text to a language model. Ask for the list, ask what each one retains, and ask whether the vendor can use API keys in your name so the contract sits with you.
3. Is anything stored outside our systems? Logs, recordings, transcripts and prompt histories have a way of piling up in a vendor's tools. Ask where each one lives and for how long.
Who can get in
4. What access do you need, and can it be named user accounts? Shared logins and long-lived API keys are hard to audit and harder to revoke. Named accounts with the minimum permissions are easy to review and easy to switch off.
5. Where are credentials kept? The right answer is a password manager or secrets store. The wrong answers are a spreadsheet, a chat thread, or hard-coded in a workflow.
6. What happens to your access at handover? It should be removed by default, and kept only if you sign up for ongoing support.
What the agent is allowed to do
7. What can the agent change on its own? Reading a calendar and creating a booking is one thing. Editing deal values, deleting records or sending payment links is another. Ask for the list of write actions, and keep the risky ones behind a human approval.
8. When does it hand over to a person? Pricing, complaints, legal questions and anything outside the agreed scope should go to your team with a summary attached. Ask to see the handoff rules in writing.
If something goes wrong
9. How will we know it has failed? Workflows break silently when an API changes or a token expires. Ask how failures are detected, who gets alerted, and how fast.
10. Could our own team run this without you? This is the real test of a handover. You should get the code, the prompts and flows, a runbook, and enough training that another engineer could take over tomorrow.
A note on certifications
SOC 2 and ISO 27001 reports are useful, and large vendors should have them. Smaller specialist teams often do not yet. In that case the questions above matter even more, and a vendor who answers them clearly and in writing is often a safer bet than one who points to a badge.
We publish our own answers on our security page. If your team has a questionnaire, send it before the first call.