Connections let AI read your notes, check your calendar, and organize your inbox. What connecting means, what access to allow, and how to do it all safely.
By the end of this page, you should be able to connect an AI assistant to the apps you already use, know what access you are allowing, and know which permissions to tighten.
Until you connect your AI assistants to your data, they are working blind. The moment you connect your notes, your calendar, or your email, the same AI can go from generic answers to doing real work with your information. Connections are also where the risk lives though, so this page covers what is possible and how to set them up safely.
To write this guide, we audited 39 connected apps across my AI tools and about 800 working sessions from the past ten months. At the end, I will show you what connections I personally use, how I use them, and the workflow I use to process my meetings, track my action items, and bill my clients, all from one prompt.
A connection lets your AI see into another app and take action there: read your notes, check your calendar, create a task, draft an email. Think of a connection like a bridge: it lets your AI cross into the app and do work on the other side. Claude calls these connectors. ChatGPT calls them plugins.
This matters because an AI without connections only knows what you paste into the chat. In our past prompting guide we said to point your AI to your data. Well, connections make this possible.
One more term you will see: custom connectors, sometimes called MCP servers. Anyone can build one, and it allows you to connect niche tools that Claude or ChatGPT do not support out of the box. Nobody has verified the ones you find online though, so be careful with them. I use one I set up myself for Zoho Invoice, my bookkeeping software. More on these in a later issue.
Before you connect anything, know what permissions you are allowing.
Note: Same button, different permissions. Claude's Gmail connection can read and draft but cannot send; you hit send yourself. ChatGPT's can draft and send. Neither is wrong, but you should know the difference.
The setup takes about a minute:
Either way: pick the app, sign in, approve the access screen, done.
Choose the app you use the most. For most people that is Gmail or your calendar. I personally use Notion, since that is where my tasks and client notes live. Start where the AI can help with what you already do every day: usually the calendar, email, and messaging. Quick note: Claude's Gmail, Calendar, and Drive connectors work on the free plan. ChatGPT needs a paid plan to connect apps.
Then put the connection to work with the starter prompts below. They work in ChatGPT and Claude once the matching app is connected; swap the bracketed parts for your own. Start with the read-only ones: reading is the safest first step, and for me, read-only tasks outnumber writes three to one. The last one, combining them, shows where this is headed: several connections working together in one prompt.
Take a look at my inbox and tell me what actually needs my attention today.
Calendar
Take a look at my calendar this week and help me reclaim some of my time. What do I not actually need to be doing?
Files
Find the latest version of my [document] in Drive and summarize what changed.
Combining them
Check my email and my calendar for today. Tell me what is on my schedule and which emails need my attention, pull any related files from Drive, and give me the top three things I should do right now.
Make the AI ask you first. When you connect a new app, set anything that can send, delete, or change things to need your approval, especially anything you do not want it acting on freely. As you get more comfortable and confident in it, give it more freedom: in Claude, switch that tool to "Always allow"; in ChatGPT, relax the plugin's setting. I always start things pretty tight.
This is called least privilege: only give the AI the access the job needs. It is how I run my setup. Anytime the AI needs to read, I allow it. Anytime it is going to write to anything, it needs my approval first. A mistake with limited access stays small.
Also, use your smartest model when connections are involved, especially for work that matters. A weaker model with loose permissions can misread a situation and make changes you did not want.
One more good practice: turn off tools and connectors you are not using. It keeps your setup simple, and it limits what can go wrong.
Here is what this looks like in my own work. The connections I use most are Notion (my hub for tasks, client notes, and time tracking), Krisp for meeting recordings and transcripts, Outlook mail and calendar, and Zoho Invoice, my bookkeeping software, through the custom connector from step 1.
How you instruct the agent matters as much as what is connected. Early on, I named everything myself: pull it from Krisp, add the tasks to Notion, and when something should not go out, I said so: "Go ahead and create a draft invoice in Zoho. Don't send it though." Now most of that lives in one saved skill (we covered skills in the prompting guide): I just tell it to process my meeting, and because the skill has taught it what I want, that one prompt is really talking to four or five apps at once.
Not every meeting needs all of this, but when it runs end to end, it looks like this. The agent calls Krisp or Notion for the meeting recording, extracts the tasks, then reads the full transcript to make sure those tasks are accurate. It adds them to Notion, schedules time on my calendar to work on them, and sometimes gets a head start on a few. It then logs the hours to the client's project in Zoho, since I bill for the call and the work, and sometimes drafts the invoice I send for that work. It can even draft an email to the client in Outlook with a summary or an update on the action items.
On a recent 45-minute client call, the workflow created seven tasks, two contact records, and a searchable meeting record, updated three projects, and verified the changes in about 10 minutes of agent work. For a billable call, it also records the duration and tracks that time against the client's retainer. This saves me about 30 to 60 minutes of post-meeting admin per call. At one of those meetings a week, the high end is about four hours and 20 minutes back each month, more than half a workday, or 52 hours a year.
At five or ten of these calls a week, the time really adds up. At the high end, five calls would give me back about 22 hours a month, or 260 hours a year. Ten would be about 43 hours back each month, more than a full workweek, or 520 hours a year. The agent handles the transcript review, copying, linking, time tracking, and record updates while I move on to something else.
The permissions from step 4 are working the whole time. The reads and the task tracking run on their own. Before anything touches the client, like an invoice or an email, I still manually verify and hit send. That is the point of connections: with the right access and the right limits, the agent can do real work across your apps instead of just answering questions.
My rules, in short: the AI can always read. Anything it writes needs my approval. I still hit send myself.
My agent once wrote tasks into the wrong Notion database, a collaborator's instead of mine. Not a big deal this time: I caught it, deleted the stray tasks, and recreated them in my own. But if it had done more before I noticed, I would have spent real time and money fixing changes I never knew about. That is the actual risk: an AI quietly doing things you are not privy to.
It can also come from outside. Security researchers recently showed that hidden instructions inside a web page could trick several AI assistants into copying private information out of accounts the user was signed into. Content your AI reads can try to talk it into things you never asked for. Another reason to use your smartest model, and the reason those "should I go ahead?" checks exist. They are your chance to catch what the AI missed.
So here is what to drive home: know what your AI has access to. Keep the connectors down to the ones you actually use; it limits the blast radius when something goes wrong. Keep permissions strict enough that it is hard for the AI to accidentally do the wrong thing. Keep approvals on the actions that matter, and verify the result after it acts. Do that, and connections are the biggest jump in what AI can do for you.