Ten questions to ask before an AI vendor gets access to your CRM
By Manoj Gurumurthy · 2026-10-07 · 6 min read
Every useful AI agent ends up touching your customer data. A voice agent that books site visits needs your calendars. A WhatsApp agent that answers product questions needs your catalogue and policies. A follow-up workflow needs write access to your CRM.
That is fine, as long as you know exactly what you are handing over. Most security problems with AI vendors are not exotic attacks. They are ordinary access that nobody wrote down. These are the questions we would ask any vendor, including us.
Where the data lives
1. Whose accounts will the system run in? The safest answer is yours: your telephony provider, your WhatsApp Business account, your cloud project, your automation workspace. If the vendor runs everything in their own accounts, you are renting the system, and leaving later means rebuilding it.
2. Which AI model providers will see our data, and what exactly do they receive? A voice agent usually sends audio or transcripts to a speech provider and text to a language model. Ask for the list, ask what each one retains, and ask whether the vendor can use API keys in your name so the contract sits with you.
3. Is anything stored outside our systems? Logs, recordings, transcripts and prompt histories have a way of piling up in a vendor's tools. Ask where each one lives and for how long.
Who can get in
4. What access do you need, and can it be named user accounts? Shared logins and long-lived API keys are hard to audit and harder to revoke. Named accounts with the minimum permissions are easy to review and easy to switch off.
5. Where are credentials kept? The right answer is a password manager or secrets store. The wrong answers are a spreadsheet, a chat thread, or hard-coded in a workflow.
6. What happens to your access if we stop working together? It should be removed the same day, with a written list of every account and key that was switched off.
What the agent is allowed to do
7. What can the agent change on its own? Reading a calendar and creating a booking is one thing. Editing deal values, deleting records or sending payment links is another. Ask for the list of write actions, and keep the risky ones behind a human approval.
8. When does it hand over to a person? Pricing, complaints, legal questions and anything outside the agreed scope should go to your team with a summary attached. Ask to see the handoff rules in writing.
If something goes wrong
9. How will we know it has failed? Workflows break silently when an API changes or a token expires. Ask how failures are detected, who gets alerted, and how fast.
10. Who keeps it running, and how fast do they fix things? An AI system is never finished: APIs change, tokens expire and prompts need tuning. Ask who monitors it, what support hours they keep, how quickly issues are fixed, and what the monthly fee covers versus what is quoted separately.
A note on certifications
SOC 2 and ISO 27001 reports are useful, and large vendors should have them. Smaller specialist teams often do not yet. In that case the questions above matter even more, and a vendor who answers them clearly and in writing is often a safer bet than one who points to a badge.
We publish our own answers on our security page. If your team has a questionnaire, send it before the first call.