Skip to content
nullbot ← Back to site
◍EN
Français English Español Português (Brasil) Português (Portugal) 简体中文 繁體中文 日本語 한국어 Deutsch Nederlands العربية

Connecting your tools

Connecting your tools to AI agents

Connecting your tools to AI agentsBuild your own mobile appBuild your own websiteWhat an employee really costsWhat an SEO agency costsRunning a business with no marketing budgetAutonomous AI agentAutomating your business with AIAgentic systemAI agents in businessSalesAI agents for customer supportAI agents for financeCRM and AI agentsAI agents for social mediaSEO and GEO visibilityWatching your agents workGovernance and budgets

An agent with no access to your tools does nothing — it comments. That is the difference between an assistant writing a draft you will copy out and a team working inside your accounts: the ranking is recorded in your tool, the follow-up leaves from your address, the meeting lands in your calendar. Connecting an account takes a minute. What really counts is what the agent does with it in the sixth month, and above all what it is never allowed to do.

Table of contents

  1. 1. What a connector really changes
  2. 2. The tools available
  3. 3. Connecting an account
  4. 4. What the agent is allowed to do
  5. 5. What it gives you over time
  6. 6. Disconnecting, and what remains
  7. 7. Frequently asked questions

1. What a connector really changes

Most AI tools stop at the door of your accounts. They produce a text, an idea, a list — and the transcription work falls back on you: open the inbox, copy out, send, tick. That transcription is exactly the part that never gets done in a busy week.

A connector removes that step. The agent reads your data where it lives and acts in the tool, under your name and within your limits. Three concrete consequences:

  • The work is done, not suggested. An agent watching unpaid invoices does not tell you three are overdue: it prepares and sends the follow-up, and reports back.
  • Your data stays with you. Nothing is copied into a parallel database that will go stale. Your CRM remains the reference, and it is kept up to date rather than duplicated.
  • The trace is verifiable. Every action goes through the real tool, with its own history — so you can check in Gmail, in Stripe or in HubSpot what was actually done.

2. The tools available

Fifty-two services are connectable today, plus two generic gateways for any service exposing standard authentication. Here they are by use.

  • Sales and payments — Stripe, PayPal, Square, Shopify, HubSpot, Pipedrive, Close, Attio, Folk.
  • Email and customer service — Gmail, Slack, Intercom, Gorgias, Klaviyo.
  • Social media — LinkedIn, Instagram, Facebook, X (Twitter), TikTok, YouTube, Buffer.
  • Calendar and meetings — Google Calendar, Calendly, Google Contacts, Fireflies, Granola, Otter.
  • Organisation and projects — Notion, Asana, ClickUp, monday.com, Linear, Atlassian Rovo, Airtable, Jotform.
  • Files and design — Google Sheets, Dropbox, Box, Canva, Figma.
  • Sites and hosting — WordPress, Webflow, Wix, Cloudflare, Hostinger, Vercel.
  • Measurement and monitoring — PostHog, Mixpanel, Amplitude, Sentry.
  • Development and gateways — GitHub, Zapier.

Six of them have their own detailed page, with what the agent does there and what it does not. For the others the principle is the same: the service declares its permissions, nullbot asks for those and nothing broader.

3. Connecting an account

Connecting is done from the company, in a few seconds, and follows one of the three routes the service imposes — the choice is not ours.

  • Account sign-in (OAuth). The most common. You sign in on the service's site, you see the exact list of permissions requested, you accept. No password passes through nullbot: the service returns a token, revocable on its side as on ours.
  • The restricted key. Some services prefer a key limited to strictly necessary actions — that is what Stripe recommends for autonomous agents. You create it on their side and paste it once.
  • The public address. A few services require nothing: a Shopify store's storefront, for example, opens with its address alone.

In every case, connecting states which resource is concerned: the account, the workspace, the channel, the calendar, the store. A connector is never plugged in “in general”.

4. What the agent is allowed to do

This is the part that should decide your choice, well before the list of services. Three guarantees, and they are verifiable in the product:

  • Approval before writing is the default setting. Except for read-only connectors, any action that writes or deletes requires human approval before it is carried out. This is not an option to switch on: it is what applies when the connector is created, and it takes a deliberate act to relax it.
  • The scope is named. Every connection requires designating its resources — this workspace, this channel, this calendar, this store. An agent connected to one Slack channel does not read the others.
  • Spending is capped before the call. Each agent works under an envelope reserved before the model call: envelope exhausted, the call does not happen. Going over is made impossible, not merely unlikely. The detail of the governance is described separately.

There is also a risk few providers mention: the content an agent reads is not an instruction. An email, a ticket or a comment can contain text designed to divert the agent. That is why sensitive actions stay behind approval, and why an agent never follows an instruction found in data it consults.

5. What it gives you over time

Connecting is a minute's work, and it is the uninteresting part. What nullbot sells is what happens afterwards, month after month, without anyone having to think about it.

  • Week 1. Accounts are connected, scopes named, the first actions go through approval. You correct the tone and adjust what has to come back to you before anything happens.
  • Month 3. Follow-ups go out at the right moment, the calendar fills without an exchange of emails, the customer file no longer goes stale. That is the moment at which, doing it yourself, you would have stopped.
  • Year 2. The history becomes usable: what was done, when, at what cost, with what result. That is where you can finally stop what produces nothing — a decision impossible without records.

No quantified gain can be promised here: it depends entirely on what you delegate and on the volume. What is certain is that none of it happens when nobody keeps up the repetition — that is the real cost of regular work.

6. Disconnecting, and what remains

A connector is removed in one gesture, and revocation holds on both sides: the token is invalidated here, and you can also withdraw it from the service itself, which cuts access whatever happens.

What remains after disconnecting is what was done in your tools: the messages sent, the meetings booked, the records updated belong to you and do not move. What stops is the continuation — and that is the only effect intended.

One point deserves to be said plainly: some actions cannot be taken back. A message posted in a Slack channel is visible to everyone and cannot be withdrawn; an email that has gone is gone. That is precisely the reason for approval before writing, and the reason we do not recommend disabling it on those channels.

7. Frequently asked questions

Do I need a developer account to connect a tool?

Not in the vast majority of cases: you sign in with your usual account and accept the permissions displayed. Two exceptions exist, and they are flagged at connection time: some Google services require the corresponding interface to be enabled in a Google Cloud project, and a few tools ask for a key you create on their side.

Can an agent send an email on my behalf without my seeing it?

Not by default, and on Gmail Google's official connector does not even allow it: it reads, it files, it prepares drafts, but it does not send silently. More broadly, any write action goes through human approval until you have explicitly relaxed it.

Does my data go to nullbot?

The agent reads what it needs for the task at hand, within the scope you named. There is no systematic copying of your accounts into a parallel database: your tool remains the reference. What is kept is the trace of what was done — objective, action, result, approver — because untraceable work cannot be steered.

What happens if a service changes its rules?

The connector stops working and says so, rather than working around it. That is a deliberate choice: an access that degrades silently costs far more than one that stops plainly. Each service's own warnings — a connector still in preview, a permission to enable, a limit of the interface — are shown at connection time rather than discovered in production.

What if my tool is not on the list?

Two generic gateways cover services that expose standard authentication, and Zapier acts as a relay to a very large number of applications. The list is extended by declaration rather than by development: adding a service means adding a line to the catalogue, not changing the product.

Going further

Read next: governance and budget control, watching your agents work, or a CRM kept by agents.

AI NewsSecurityLegal NoticePrivacyCookiesCGUCGVDPA Manage my cookies

© 2026 MARA LABS — nullbot. All rights reserved. Société par actions simplifiée (SAS) au capital de 100 € · 104 321 104