Skip to content

Reviewing and revoking AI app connections to your mailbox

A runbook for the life of an AI app connected to your email: how OAuth grants work, a quarterly review, when to revoke, what revoking does, admin off switches.

Koltrix Team5 min read
Red padlock resting on a black keyboard
Photo by FlyD on Unsplash
On this page(8 sections)
  1. What you granted when you clicked Approve
  2. The quarterly review
  3. 1. Find the list of connected apps
  4. 2. For each connection, answer four questions
  5. 3. Check the AI app's side too
  6. 4. Note what you changed
  7. When to revoke immediately
  8. What revoking does, and doesn't do
  9. Reconnecting after a revoke
  10. Admin controls
  11. A runbook you can copy
  12. Key takeaways

Connecting an AI assistant to your inbox takes a minute. Forgetting about it takes even less. Months later, the connection is still live, still holding a token that can read your mail, long after you stopped using it.

This runbook covers the full life of an AI app connection: what you're granting, how to review connections regularly, when to revoke, and what revoking actually does.

What you granted when you clicked Approve

Most AI connections to email use OAuth. When you approved the connection, the email service issued the AI app tokens:

  • An access token, short-lived, used for actual requests.
  • A refresh token, longer-lived, used to get new access tokens without asking you again.

The refresh token is the important one. It's why the connection keeps working for weeks or months without you signing in again. As long as it's valid, the app can keep requesting access within the permissions you approved.

Those permissions, often called scopes, define what the app can do: read mail, apply labels, create drafts, or more. They were shown on the consent screen, but it's easy to forget what you agreed to.

Two practical consequences:

  1. The connection lives on the email service's side. Deleting the AI app, or removing a connector from its settings, doesn't necessarily revoke the token on the email side.
  2. Changing your password may not revoke OAuth tokens, depending on the service. Explicit revocation is the reliable way.

The quarterly review

Put a recurring 10-minute calendar reminder on the first week of each quarter. Then:

1. Find the list of connected apps

Look in your email service's settings for something like "Connected apps", "Third-party access", "Authorized applications", or "AI assistants". Check each email account you use, personal and work.

2. For each connection, answer four questions

Question If the answer is no or unclear
Do I recognize this app? Revoke immediately and investigate
Have I used it in the last month or so? Revoke; reconnect later if needed
Do its permissions match what I use it for? Revoke and reconnect with narrower permissions
Is it connected to the right account and workspace? Revoke and reconnect correctly

A useful connections page shows when each app was connected and when it was last used. "Last used" is the fastest way to spot stale connections.

3. Check the AI app's side too

In the AI app itself (Claude, ChatGPT, or others), review which connectors are enabled. Remove ones you don't use. This doesn't replace revoking on the email side, but it keeps the assistant from trying to use them.

4. Note what you changed

A one-line note ("Revoked old summarizer app, kept assistant connection, Q3") helps when you or your admin later wonders why something stopped working.

When to revoke immediately

Don't wait for the quarterly review when:

  • You change jobs or roles. Revoke connections to the old work account before you lose access to its settings.
  • You lose a device that was signed in to an AI app with a connection.
  • You see actions you didn't ask for: unexpected labels, archived threads, drafts you don't recognize.
  • The AI provider has a security incident or changes its data terms in a way you don't accept.
  • You stop using the app. An unused connection has no benefit and still carries risk.
  • Your admin asks you to, for policy or security reasons.

What revoking does, and doesn't do

Revoking a connection on the email service side:

  • Invalidates the tokens. The AI app can no longer make requests. With well-built services this takes effect immediately; with some, an already-issued access token may keep working until it expires.
  • Stops future access. The app must go through the consent flow again to reconnect.

It doesn't:

  • Delete data the AI app already received. Summaries, chat history, or copies the AI provider retained are governed by the provider's policies. Check its data settings if that matters.
  • Undo actions already taken. Labels applied or drafts created remain. Review recent changes if you're revoking because of unexpected behavior.
  • Remove forwarding rules or filters the app may have created, if it had that permission. Check your settings.

Reconnecting after a revoke

Sometimes you revoke a connection you still want, for example because you're rotating access after a laptop was lost. Reconnecting is the moment to tighten things. When the consent screen appears again, read it instead of clicking through. Check that the account and workspace are the ones you expect, and that the permissions requested still match how you use the assistant. If you only ever ask it to summarize and search, a connection that can also organize and draft is more than you need, if the service lets you choose. Then run one low-stakes request, such as listing your labels, to confirm the new connection works before you rely on it.

Admin controls

If you administer a team workspace, individual reviews aren't enough. Look for:

  • A workspace-level switch that disables AI assistant connections for everyone. When turned off, existing connections should stop working at once, not at the next sign-in.
  • A view of all connections across the workspace, showing which user connected which app.
  • Automatic revocation when a user is removed or suspended.
  • Logs of connection events and actions taken through them.

Whatever you connect, capability limits make this lifecycle less stressful. Koltrix's MCP server, for example, lets Claude, ChatGPT and other assistants read, organize and draft, but never send, so a connection you forgot about can't email anyone on your behalf.

A runbook you can copy

Quarterly AI connection review
[ ] Open connected-apps settings for each email account
[ ] Revoke anything unrecognized, unused, or over-permissioned
[ ] Confirm each remaining app is on the right account/workspace
[ ] Remove unused connectors inside each AI app
[ ] Note changes in one line

Revoke immediately when
[ ] Changing jobs or roles
[ ] Losing a signed-in device
[ ] Seeing actions you didn't ask for
[ ] Provider incident or unacceptable terms change
[ ] No longer using the app

After revoking because of a problem
[ ] Review recent labels, archives and drafts
[ ] Check forwarding rules and filters
[ ] Check the provider's data retention settings

Key takeaways

  • An OAuth connection keeps working through refresh tokens until you revoke it, often for months.
  • Revoke on the email service's side; removing a connector in the AI app may not be enough.
  • Review connections quarterly using the last-used date, and revoke anything you don't recognize or use.
  • Revoke right away when you change jobs, lose a device, or see actions you didn't request.
  • Revoking stops future access but doesn't erase data already shared or undo past actions.

Start with Koltrix

Your domain, one inbox, and an API that sends.

A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

SharePost on XLinkedIn