Back to the siteJason Sirotin / AI Automation Partner
All news and guides
Security14 min read

How to secure AI automation that uses customer data

Practical controls for identity, permissions, data minimization, logging, vendor access, human review, and incident response.

Jason Sirotin
Jason SirotinAI Automation Partner
How to secure AI automation that uses customer data

Security starts before a model receives data. The workflow needs to know who is asking, which records they may access, why the data is needed, and what actions are allowed afterward.

Minimize the data path

Draw the data path from source to deletion. For each hop, record purpose, fields, sensitivity, legal or contractual constraint, processor, region if relevant, retention, and deletion method. Send only the fields required for the task; do not use production secrets, whole mailboxes, or complete customer histories when a narrower approved context will work.

Replace direct identifiers with internal IDs where possible. Keep secrets and authentication tokens outside prompts, model context, analytics, and error messages.

Enforce identity at the data layer

Application checks are helpful, but database and storage policies should independently restrict records by authenticated user, organization, and role. Test isolation using two organizations and attempt cross-tenant reads, writes, file access, signed URLs, and realtime subscriptions.

Server-only tables should not inherit public API access. Authentication answers who the user is; authorization decides whether that identity can read this record or perform this action. Both must be tested.

Protect every external action

Verify signed webhooks before parsing business data, bound payload size, rate-limit public routes, validate schema, and use idempotency for retries. Require confirmation for irreversible actions. Keep credentials in provider secret stores rather than source code, scope them narrowly, and rehearse rotation.

Treat retrieved documents, emails, web pages, and tool output as untrusted data. Prompt injection can arrive indirectly inside content. Do not let instructions found in a customer document expand the agent's permissions or modify its governing policy.

Prepare for incidents

Document how to disable the workflow, rotate credentials, revoke sessions, preserve necessary evidence, identify affected records, notify stakeholders, and deploy a verified fix. Assign an incident owner and an out-of-band contact method before the system is needed.

Run a tabletop exercise: a malicious document causes an agent to propose sending customer data to an unknown URL. Verify that allowlisted destinations, action validation, human approval, and logging prevent the action and produce useful evidence.

A minimum production security review

Use this as a starting review, not a claim of compliance. Higher-risk or regulated work needs qualified legal, privacy, and security advice. NIST's AI RMF organizes ongoing work into govern, map, measure, and manage; security is a lifecycle activity, not a launch-day scan.

  • Data inventory and purpose limitation
  • Tenant and role isolation tests
  • Least-privilege provider scopes
  • Secret storage and rotation runbook
  • Prompt-injection and untrusted-content tests
  • Signed webhook and replay protection
  • Idempotency and duplicate-action tests
  • Human confirmation for consequential actions
  • Redacted logs with correlation IDs
  • Backup, disable, recovery, and notification exercise

Secure the whole workflow: identity, data access, integrations, actions, logs, and recovery—not only the model request.

Bring one process. Leave with a clearer next step.

Book a free consultation