Your admin chooses what to connect. Nothing is read from a tool that is not connected, and every connection is listed in Organisation settings with its scope and the date it was granted.
| Connection | What is read | What is not read |
|---|---|---|
| Salesforce and other CRMs | Records the person owns or touches: opportunity stage, next step, activity dates, update timestamps | Email bodies, attachments, records the person has no access to |
| Microsoft 365 and Google Workspace | Calendar and mail metadata needed to place a step in time: sender, recipients, time, subject line | Message bodies and attachments |
| AI assistants (Claude, ChatGPT Enterprise, Microsoft Copilot, Claude Code) | Usage exports your admin provides through the vendor's admin or compliance tools: features used, frequency, tool calls | Conversation contents, unless your organisation chooses to share them for a specific step |
| Process tools (SAP Signavio and similar) | Process and step definitions | Instance-level data |
| Slack and Microsoft Teams | Only the channel your admin designates for delivery, to post cards and read replies to them | Any other channel or direct message |
When an assistant is connected live. With the 20xwork plugin or MCP connection active in an assistant, the task a person starts and the fields of a write about to be made are sent to 20xwork to build the card and run the check. They are processed in memory and not retained.
Permissions. Connections use the narrowest scope the vendor offers. Read-only wherever the product only reads. Write access is limited to the record a person is updating in front of the product, and every write is logged.