The feature was not login
A login is a door. It tells you who is standing in front of it, but not yet on whose behalf work happens behind it. That answer is often enough for ordinary SaaS. For an agent that reads calendars, finds files, or prepares messages, it becomes the product question.
The convenient shortcut is one powerful company account that can see everything. It makes every demo look competent and every permission check look like bureaucracy. In production it creates an assistant that sounds helpful but has no idea when it knows too much.
A personal agent without a personal boundary is a superuser with a friendly voice.
The person is the mandate, not merely the recipient
When Anna asks for her next open slot, the answer cannot be guessed from the team calendar. When David asks for a file summary, the important question is whether David may see that file — not whether an administrator once connected the service. Identity has to travel all the way to the action.
That changes what an assistant is. It is not an all-knowing company bot that happens to talk to different people. It works for one person inside one organizational frame. That constraint is precisely what makes it useful at work.
Consent has to keep its meaning
People click through an astonishing amount of consent copy. An agent must not turn that into a power of attorney. Permission to read a calendar for a scheduling question is not automatically permission to send invitations, delete meetings, or quote private notes in a reply.
Good agent products do not treat consent as a one-time hurdle before the fun begins. They make it understandable what kind of work is possible, when another decision is needed, and how access ends. It does not need to sound technical. It only needs to be honest.
- The user understands on whose behalf the agent acts
- Reading and changing remain different promises
- Access can be visibly ended
- One login becomes permanent blanket authority
Smaller permissions make larger products
At first this sounds like less capability. In practice it creates more. Once a company can trust that each person operates only inside their own context, far more valuable tasks become possible. The assistant can move closer to real work because its reach is not based on hope.
That is the quiet irony of good governance: a clean boundary is not what prevents automation. It is what turns an interesting demo into a product people will actually switch on Monday morning.
The promise is smaller — and therefore credible
We do not believe in one agent that may do everything everywhere. We believe in assistants whose mandate stays legible: my files, my calendar, my permitted tools, my decision at the critical moment.
Personal AI does not begin with personalization. It begins with personal accountability. Everything else is a bot that knows your first name.