Journal · The AI Architect · 2026-07-18

One job, one folder. Give your AI the drawer the task needs, not the keys to the whole cabinet.

One job, one folder. Give your AI the drawer the task needs, not the keys to the whole cabinet.

The tension is not really about security, though that is where most people’s minds go first. It is about trust that has not been earned yet. We hand a new hire a badge before we know how they work. We hand an AI system full access before we have watched it make a single decision. The discomfort you feel when an assistant asks for broad permissions is not paranoia. It is your instincts correctly noticing that convenience and judgment are two different things, and only one of them has been tested.

Scope is a form of respect

When you give a task-specific tool access to everything, you are not being generous. You are being vague. You have not done the work of deciding what the task actually requires, so you default to “all of it” and hope nothing goes wrong. That is not trust. That is avoidance dressed up as efficiency.

Narrow scope forces a useful discipline. Before you connect anything, you have to answer a real question: what does this specific job need to see, touch, or change? Usually the honest answer is smaller than what you were about to grant. A tool that summarizes your email does not need to send email. A script that reads your calendar does not need to delete events. Naming the actual boundary is where the thinking happens.

Try this: before your next integration or permission prompt, write one sentence describing the task in plain language. Then list only the folders, files, or actions that sentence requires. If the access request in front of you asks for more than your sentence justifies, that gap is your answer.

Mistakes should be small by design

The real argument for one folder, one job is not about distrust of AI specifically. It is about how you want any system, human or otherwise, to fail. Everything fails eventually — a bad prompt, a misread instruction, a tool that does something technically correct but contextually wrong. The question worth asking is not “will this ever go wrong” but “when it does, how far does the damage travel.”

A mistake contained to one drawer is an afternoon of annoyance. A mistake with access to the whole cabinet is a much longer conversation, possibly with people who are not going to be sympathetic about how convenient the broad access was supposed to be. Scoping access is how you decide, in advance and while calm, what the worst case looks like. You are not preventing every error. You are choosing which errors are survivable without drama.

Try this: pick one AI tool or automation you already use regularly. Ask what the single worst action it could take with its current access would be. If that answer makes you uneasy, that unease is information, not overreaction. Narrow the access until the worst case is something you could shrug off.

Undoing access is harder than granting it

There is a quieter reason to start narrow: permissions have a way of becoming permanent by default. Broad access, once granted, rarely gets revisited. It sits there, unnoticed, until something forces a review — usually an incident, which is the most expensive way to discover you were overexposed. Narrow access, on the other hand, invites expansion when it is actually earned. You add a folder when the task grows. You do not start with the whole cabinet and hope to remember to lock most of it later.

This is less about the AI and more about you. Systems that start minimal tend to stay legible — you can look at what a tool can access and understand why, in one glance. Systems that start maximal tend to accumulate justification after the fact, which is a nice way of saying nobody really knows why the access is that broad, only that it has always been that way.

Try this: once a quarter, or whenever you set up something new, do a five-minute audit of what your AI tools can currently reach. Not a deep security review — just a plain look. Ask, for each one, “does this still match the job it’s doing.” Adjust downward wherever the answer is unclear.

None of this requires becoming suspicious of the tools you use, or slowing down every task with elaborate permission ceremonies. It requires one habit: naming the job before you open the drawer. That habit is small enough to build in an afternoon and useful enough to keep for years. The book goes further into how this plays out across different kinds of tools and workflows, with more examples of what narrow scope looks like in practice — but the instinct itself, once you notice it, is something you can start using today.


Go deeper. The full method is in The AI Architect. New here? Start with the free companion pack, or explore the series.

The The AI Architect newsletter

One calm email now and then — new books, the occasional essay, and companion pack updates. No spam. Unsubscribe anytime.