GUIDES
Run This Onboarding Check Before AI Touches Anything Sensitive 📚
OpenAI just shipped a personal finance feature that connects ChatGPT to your bank. Claude and Perplexity have versions too. The exact onboarding check I run.
In the last month, three of the largest AI companies in the world shipped ways to connect their assistants directly to your bank account, your credit cards, and your brokerage. OpenAI launched ChatGPT Personal Finance on May 15. Claude has bank-account access through its Era connector. Perplexity rolled out a full Plaid-powered finance experience in April.
This is fine, if you have the right guardrails. It is dangerous if you don't. This guide gives you the exact prompt I run before flipping any sensitive AI connector on. Bank, brokerage, email, calendar, health records, anything that, if it went sideways, would cost more than time.
The Risk Changed
Two years ago, the biggest AI risk was that the model would say something wrong. Bad answer, embarrassing email, a hallucinated stat. Annoying, but recoverable.
Now the risk is different. AI can act. It can move money out of your account. It can cancel a recurring subscription. It can email your team on your behalf. It can quietly store your private financials in a chat log that lives somewhere you cannot see.
Read-only access is one level of risk. Action access is a completely different one. The new onboarding-check prompt forces the AI to spell out which level you're agreeing to before you flip the switch.
Paste This Before Connecting Anything Sensitive
Paste this into Claude (or any AI you trust) BEFORE you turn on a new connector to a sensitive account. Replace the bracketed inputs with whatever you're about to connect. The output is a one-page onboarding check you can actually read before clicking Approve.
The Sensitive-Connector Checklist
Run this onboarding check before any of these:
Banks and brokerages. Any account with a balance. Plaid-powered connectors included.
Email. Especially if you're giving Claude or ChatGPT 'send on my behalf' permissions, not just read access.
Calendar. Less about money, more about who knows where you are and when.
Health records. If you're connecting Apple Health, MyChart, Oura, Whoop, anything biometric.
Cloud storage with personal docs. Especially if it includes tax filings, contracts, IDs, passport scans.
Any 'agentic' tool with browser access. Anything that can click, fill forms, and complete checkout on your behalf.
The reframe
Think about every new AI connector the way you'd think about hiring an assistant and handing them a credit card on day one. You wouldn't do that without first making absolutely sure you knew what they could see, what they could spend, and how to walk them out the door if it went wrong. Same standard applies here.
A prompt is only as strong as its context architecture. Always define: 1) Persona & Authority, 2) Precise Business Objective, 3) Constraints (what NOT to do), and 4) Structured Output Schema (tables, JSON, or step-by-step frameworks). Save your highest-performing prompt chains as reusable team SOPs.