Just in Time

Insights

AI integration checklist: CRM, helpdesk, BI, APIs

An assistant becomes useful when it can work with business systems without bypassing their rules.

Connecting an assistant to software gives it access to useful information. It may also give it the ability to make mistakes with real consequences.

A customer relationship management system, or CRM, holds customer and sales records. A helpdesk manages support requests. Business intelligence, or BI, tools provide reports and analysis. Application programming interfaces, or APIs, let the assistant exchange information with these systems.

The integration should preserve each system’s permissions and distinguish reading information from changing it. OWASP recommends checking authorisation in the underlying software rather than relying on the model to decide what is allowed.

Connect one complete workflow

For example, a support assistant might read a ticket, retrieve the customer’s permitted account details, and draft a reply. Sending that reply or issuing a refund should be a separate action with its own permissions and approval rules.

Use this integration checklist:

  • Sources: Identify which system owns each fact, such as customer status or ticket priority.
  • Identity: Define whose permissions apply to every request.
  • Access: Preserve record-level restrictions and reporting permissions.
  • Actions: Separate read-only tools from tools that create or update records.
  • Validation: Check generated inputs before sending them to business systems.
  • Approval: Require review for consequential actions.
  • Failures: Define what happens when a system is unavailable or rejects a request.
  • Retries: Prevent repeated attempts from creating duplicate actions.
  • Logs: Record who requested an action and whether it succeeded.
  • Ownership: Assign someone to maintain each connection.

The checklist applies established guidance on limited permissions, validating model output, and managing AI services throughout their lifecycle.

One final rule matters: retrieved content is information, not authority. A ticket or document may contain instructions that try to manipulate the assistant. Reading those instructions must not give it permission to send messages, expose records, or change accounts.

Start with a read-only connection, verify that users see only permitted information, and then introduce narrowly defined actions with validation and approval. This gives you a controlled path from “answers questions” to “helps complete work.”

Related: Enterprise integration