# How do we safely connect an AI assistant to our CRM?

Give the model its own scoped service identity — a licensed integration user with explicit object and field permissions — rather than letting it inherit a person's access. That way permissions are auditable and revocable in one place, which is the specific control the mature implementations have.

About 40% of the panel now has a model connected directly to a CRM or warehouse through a tool-calling protocol, and the constraint that bites is governance, not capability: 30% show shadow assistants bought by individual reps or projects blocked for weeks on admin rights. Decide the identity model before the pilot, not after.

## Sources

- **Measurement** — [AI Workflows study — governance is the bottleneck](https://www.leanscale.team/knowledge/research/ai-workflows-study/)

---
Cluster: Ai_gtm · https://www.leanscale.team/knowledge/answers/connect-ai-to-crm-mcp/
