No reason, no field: one page per automated process
When a company connects an AI agent to a process, the easiest path is to give it broad access and narrow it later. Later rarely comes. Within weeks the agent can read far more than its job needs, nobody can say exactly what it touches, and the first security review stops the project. A one-page document, written before any access is granted, prevents this.
The page
For each process you want to automate, list every source of data it needs. For each source, write six things: what it is; why this process needs it, in one specific sentence; whether the agent reads it, writes it, or both; how sensitive it is; how long the agent may keep it after a task; and the name of the person who owns that data and approves the access.
The rule is binary
If you cannot state why the process needs a field, the agent does not get it. "For analysis" or "it might be useful" is not a reason. "To read the order status when a delivery is late" is a reason.
Take an agent that handles delivery exceptions. It needs the order, the stock level, the carrier tracking, the contract terms and the history of similar cases. It does not need payroll, the general ledger or the HR files. If those appear on the page, someone has to justify them, and usually nobody can.
Defaults that protect you
Read access by default; write access only with a reason and an approval threshold for anything that deletes or changes money. Sensitivity set by the owner of the data, not by the team building the automation. No memory beyond the task by default; longer retention must be justified. Each owner approves in writing.
If the page runs past one page, the process is too broad for a first step. Split it.
When to write it
Before the agent gets any credentials, not after. A page written once the agent is already running is a description of what went wrong, not a control. Review it a month after launch, then every quarter, and every time someone proposes a new data source.
The page takes an afternoon. It also answers, in advance, every question your IT manager, your auditor and your lawyer will ask.