OctopusSign up

The day they can touch Stripe is the day they can wreck it.

A teammate that cannot open your CRM, calendar, or inbox is still a chatbot. A teammate that can, with no scopes, is a leak with a first name.

Sep 6, 2026 · 8 min · Jimmy Harika

A teammate that cannot touch your tools is a chat window with a job title.

A teammate that can touch them with your personal login, your admin Stripe key, and no log, is a fire.

Both of those products exist. People buy the second one because the demo is exciting. The demo always has access. The demo never shows the morning after.

Useful the day they can open CRM, calendar, inbox. Dangerous the same day. That is not a reason to keep them in a sandbox forever. It is a reason to connect like an adult.

They sign in themselves

Octopus is opinionated here. Every teammate gets a computer and its own access. Separate logins by default. They sign in where tools usually cannot. You do not paste a cookie into a prompt and call it integration.

Mail has an inbox of its own, plus the Gmail you actually use, if you grant it. Clerk has Stripe, if you grant it. Maker has Notion. Watch has whatever page it is supposed to watch. Scout has the list tools. Chief routes. Nobody gets "all of it" because that is how you get a generalist who CCs legal on the first nudge.

Own access is not a nicety. It is how you fire one teammate without rotating every password you own.

Read-only is the default, not a personality

Every connected account carries a scope.

Give Clerk read-only on the books. Give Mail read plus send on Gmail, and still make customer sends wait in Needs you. Give Maker Notion, and no Slack. Leave Watch with no Stripe at all.

Scope is per teammate, not shared. That sentence is the whole security model. If Maker can see payroll because "the workspace is connected," you did not scope. You installed a hose.

Start read-only on every new connection. Watch the receipts for a week. Then open send on the one job that needs it. Not on the teammate. On the job.

The vault is not the thread

Add a password or an API key once.

A teammate reads it from the vault when a job needs it. Nothing sensitive sits in a thread you would have to go back and delete. Read at run time. Never shown in a chat.

If a vendor stores the key next to the prompt, stop. You will paste it into a share, a screenshot, a support ticket. You will do this on a Friday.

Octopus keeps the vault on that computer, in a dedicated workspace. We never train on your data. Bring your own keys for the models, too. ChatGPT, Claude, Grok, or the OSS models in the $99 plan. Same desk. The Stripe key still does not belong in the same place as the prompt.

Receipts, or it did not happen

Every call through your connections is written down. Who, which tool, when.

Clerk listed seven overdue invoices at 9:04. Mail read the overnight inbox at 7:12. You can read the log the same morning. The record is the product.

Without receipts you have vibes. "I think it only read." "I think it did not send." You will not think that after the first wrong email. You will want a line in a log.

Receipts are also how you debug a teammate without reading its mind. If Maker keeps opening the wrong Notion, the log says so. You fix the scope or you fix the brief. You do not add another prompt and hope.

What you connect first

Inbox, if Mail is the hire. Calendar, if Maker is the hire. Stripe or the sheet, if Clerk is the hire. The live page, if Scout or Watch is the hire.

Do not connect twelve tools on day one because the landing page had logos. Gmail, Calendar, GitHub, Slack, Notion, Stripe, Sheets, Drive. Cool. Pick the two that match the job you described.

MCP servers you bring are the same rule. If you cannot say which teammate needs it, it does not get connected.

The wreck is always a missing no

The wreck is not "AI." The wreck is send on a connection that should have been read. The wreck is one login shared by Clerk and Maker. The wreck is a key in a thread. The wreck is no daily cap. The wreck is no Needs you.

You take the tap. You do not babysit the pipe.

Connect them. Then put a fence on the connection, a vault on the secret, a receipt on the call, and a human on the send. That is the whole grown-up version of "it works with your tools."

Straight answers

Should two teammates share a login?
Separate by default. Clerk on the books. Mail on the inbox. You can put two on the same account when they both need it. Do not start there. Shared logins make receipts harder to read.
Where do API keys live?
In the vault, on that computer. A teammate reads a secret at run time and never posts it into a thread. If the key is sitting in chat, you do not have a teammate. You have a leak.
What is the safest first connection?
Read-only on one tool that already has a job. Stripe read for Clerk's overdue list. Calendar read for Maker. Inbox read for Mail. Add send after you have watched a week of receipts.

Hire your first AI teammate

Ten minutes to set up, on the AI plan already sitting in your browser — or on ours.

Sign up