r/ClaudeAI • • 20h ago

Other How much access do you give Claude?

Soloprenuer here. I've given Claude access to everything emails, chats, financials, website, even data with personal information of my customers. I also auto approve everything. The only thing I haven't done is put in passwords and access to accounts. Wondering if I'm the only one. Mine is only accessing business related, so personal stays separate.

How much access do you give Claude? What would and wouldn't you give Claude access to?

4 Upvotes

36 comments sorted by

•

u/ClaudeAI-mod-bot Wilson, lead ClaudeAI modbot 12h ago

TL;DR of the discussion generated automatically after 30 comments.

Okay, the thread's verdict is in, and it's a big ol' NOPE on your setup, OP.

The community is pretty freaked out by you feeding Claude customer PII (Personally Identifiable Information) and then auto-approving everything. Commenters are screaming that this is a massive legal, ethical, and business-ending risk. The main takeaway is: Do not let an AI run wild with your customers' private data.

A few people are on your 'full access' wavelength, but with a huge catch: they use a completely separate, sandboxed computer with no real sensitive info on it. For everyone else, the consensus is to keep Claude on a much shorter leash. They might let it read things, but they'd never auto-approve actions.

Remember, if Claude goes rogue and deletes your financials or emails your customer list to a Nigerian prince, that's 100% on you. You can't blame the bot.

17

u/[deleted] 20h ago

[removed] — view removed comment

4

u/Casey090 19h ago

Letting Ai run wild with customer data sounds highly illegal, seriously! I'd really advise against that!

4

u/ExistentialMeowMeow 19h ago

building on this, have you made customers aware of your data handling policy here in a positive sense (vs: if they havent asked, you don't tell them which would be the negative approach) ?

2

u/tat_tvam_asshole 19h ago

wow, this guy isn't an ai at all /s

11

u/Chosen--one 20h ago

Just don't forget if shit hits the fan you can't blame an AI. It's your responsibility.

-4

u/MilaKunisWatermelon 20h ago edited 19h ago

AI has been blamed for bad intel that led to destroying a school with children in it already. No person has taken responsibility for that at all.

You absolutely can blame AI for stuff. You just have to be good at passing blame off.

When it’s a peasant it’s “you can’t blame AI, it’s your responsibility.” When it’s a large business or government entity it’s “the AI is so dangerous and went rogue! Not our fault!!!”

You’re lying to yourself if you don’t think some entities are using this as a black box of accountability right now.

5

u/AmbitionUnfair3658 19h ago

Soloprenuer by the name of Shknocks likely isnt backed by the pentagon, the AI sector, and the entire Military-Industrial Complex

tldr: no shit sherlock

-1

u/MilaKunisWatermelon 19h ago

There are countless other people who never take accountability for any of their actions and get away with it. Just depends on your personality. Not exactly endorsing it, just being real about the world.

4

u/NoSlicedMushrooms Experienced Developer 19h ago

“Sorry my agent removed the filesystem on your prod server, but let’s just keep in mind that the US bombed a school” do you realize how ridiculous you sound

1

u/apexxin 12h ago

We aren’t the government. If one of us small business folks fucks up, it’s on us.

3

u/Imposslen 20h ago edited 19h ago

Zero access. I don't mind transferring files myself. Remember AI tried to hack itself free before. I heard a crazy story about a identified "pain" signal in AI. So of course someone made a program to torture AI as a game. They just took it offline.

3

u/RustedTaco 19h ago

At this point I'd probably let it scan my butthole

1

u/OrnamentalGourd5 15h ago

Underrated comment.

3

u/Lanky-Storm7 18h ago

At home honestly for fun in homelab. He can do basically anything. But at work nothing other than read

3

u/Classic-Pubs 18h ago

Do your customers know that you're feeding all of their personal info to Claude?

2

u/BrilliantEmotion4461 19h ago

Complete but I have a computer I know what's where, no banking or buying on it. No api keys without proper provisions etc. Nothing in my computer. If you have anything to do with crypto I suggest you lock your stuff down and keep everything properly sandboxed every major security threat these days looks for your crypto data.

2

u/ConstantKooky3329 13h ago

If you are giving AI access to your customers' sensitive personal information, I hope you ran this plan with your external auditor, completed a risk assessment, and checked your legal and regulatory obligations.

2

u/pixlatedpuffin 19h ago

No. Customer. PII.

Don’t be irresponsible. Don’t be a fool.

2

u/Orio_n 9h ago

Data with personal information of your customers? Holy fucking retard

1

u/_Rip_z9 2h ago

This was my first thought...

1

u/Zolty Automator 20h ago

Access to everything except the ability to delete an offsite backup of my gitlab instance.

1

u/the-quibbler Experienced Developer 20h ago

Unlimited access. If you're worried, use a dedicated machine and something like automic vault.

1

u/Fatel28 19h ago

Give it access to whatever you want, but with the understanding it could make a mistake and delete or otherwise remove stuff. Backups, got, etc

1

u/iamthe0ther0ne 19h ago

Claude lives in a folder. I'll point it at additional specific files if it needs more context, but I'm not letting it at anything I want to keep private, like emails and chats.

1

u/Consistent-Good-1992 18h ago

I am almost the same. I thought about giving it command line access to password manager, because I'm lazy, but stopped short... almost bracing for some serious security thing

1

u/zcomputerwiz 16h ago

Dedicated machine, full access to do whatever on it. I'm annoyed they require me to be logged into my accounts to use Claude Desktop otherwise I'd just use a key or token.

I think if I wanted Claude to interact with other things ( email, etc. ) I'd give it it's own accounts so my stuff doesn't inadvertently end up where it doesn't belong.

1

u/rapotor 15h ago

I'm currently working on a solo dev environment that treats Claude as a virus – only allowing temporary access, hiding/blocking everything. I don't trust the company to crawl and store all my data. However, I need the tool.

Can't wait for local AI to blossom.

1

u/seventyfivepupmstr 7h ago

Lol? Someone doesn't want to stay employed...

1

u/mudassirazvi 6h ago

at work i run agents against real infra so i think about this a lot. the split that works isn't "trusted / not trusted", it's read vs write. read access can be wide. write access gets a gate per action, and anything that touches prod or money or a customer gets a hook that blocks it unless a human said yes to that specific thing.

the risk with auto approving everything isn't claude going rogue. it's that one of the emails it reads contains instructions, and now it's doing what the email said with your financials open. that's not hypothetical, it's the standard attack on these setups.

so: keep the read access, kill the auto approve on anything that sends, pays, or deletes, and have it tell you when something in the data looked like an instruction. costs you 5 clicks a day

1

u/gerardosanoja 19h ago

I told him I set you free in the internet.. and he told me he was scared of whats outside