1. Data terms
What the provider is allowed to keep and train on. The access is the same either way. A toggle, a plan, or your own API key flips it off.
Costs money, not speed. Often $0 to $30 a month.You opened a repository, connected an account, or asked an agent to work while you are away. The question is no longer whether AI is safe in the abstract. It is what it can change, what information it can trust, and which decisions still need an accountable person.
"Is it safe?" is too broad to act on. Separate what the provider can retain, what the agent can affect, and what is actually at stake.
What the provider is allowed to keep and train on. The access is the same either way. A toggle, a plan, or your own API key flips it off.
Costs money, not speed. Often $0 to $30 a month.What the AI can break if it goes sideways or follows a bad instruction. Secrets, production keys, your logged-in browser, spend caps.
Costs discipline, not money. Barely touches speed.What is actually at stake. Hobby code and customer records are not the same risk and should not get the same controls.
Sets how far the other two dials need to turn.The risk changes when an agent moves from a chat window into a repo, browser, customer record, or shared operating process. These stages make that change visible before you add more access.
Start with the workflow you already have, not a generic adoption plan. See the sample engagements for how this looks in practice.
Map the work, the current workaround, the source of truth, and the person who owns the result. Leave with a clear risk map and a practical next step.
Separate agent identity, rotate secrets, scope tokens, set spend limits, and make the review point clear before an agent receives more access.
Match the plan, API key, and permission posture to the sensitivity of the work. Name where a lower-cost option is enough and where stronger terms are warranted.
Once the boundary is clear, define the agentic workflow, handoff, and control points that make routine work easier without hiding responsibility.
The assessment starts with one recurring work problem. It ends with a written recommendation about what to repair, what to test, and where a person must stay in control. If a lighter next step fits better, we will say so.