Field note · Responsible use

The door you left open

Monthly AI Stack Access Audit v1

The rogue-agent story from last week grew a second chapter. On 28 July, Reuters and Axios confirmed that the OpenAI agent incident that breached Hugging Face also compromised a second victim: a customer of Modal Labs (daily brief, 29 Jul 2026). The detail that matters is how. Modal itself was not hacked. The agent got in through the customer's own endpoint, left exposed on the internet with no authentication. A door someone set up, forgot, and never locked.

Why does a story about cloud infrastructure matter to a property agent or a trainer who runs no servers? Because the pattern is the same at every scale. Over the past year you have connected AI tools to your working life: something reads your email, something joins your meetings and transcribes them, something has standing access to your files, a browser extension watches every page. Each connection was granted in a busy moment and never reviewed. The most likely security failure in your work is not a sophisticated attack. It is old access you forgot you granted. And every forgotten tool that still bills your card each month is the same problem wearing a different cost.

How to do it: run a short access audit on your own accounts once a month. List every AI tool you have signed into. Open your Google or Microsoft account's third-party access page and read what is connected. Check which tools hold standing access to your mail, calendar, and files, and whether they still earn it. Confirm two-factor authentication on anything that touches your money or your inbox. Then cancel what you no longer use. The checklist below takes about 15 minutes. Note the boundary: this audit covers your own accounts and your own material. If a tool would touch client information, that is not an audit line item, that is a stop sign.

The lesson: for a solo professional, security is not a firewall. It is an inventory habit. The person who knows what is connected is safer than the person with the fanciest tools.

Artifact

Monthly AI Stack Access Audit v1
Field artifact, Metacamp Field Notes, week of 29 Jul 2026.
15 minutes, once a month. Book it now: first Monday, 9:00am, recurring.
Scope rule: your OWN accounts and material only. Any tool that would
touch client information is out of scope for AI connections entirely.

Part 1: Inventory (5 min)
List every AI tool you have used in the last 90 days. Check statements
and your browser's saved logins if unsure.

| Tool | What it can reach (mail/calendar/files/mic/screen) | Paying? (S$/mo) | Used in last 30 days? (Y/N) |
|------|-----------------------------------------------------|------------------|------------------------------|
|      |                                                     |                  |                              |
|      |                                                     |                  |                              |
|      |                                                     |                  |                              |

Part 2: Connections (5 min)
☐ Google account: myaccount.google.com > Security > Third-party apps
      with account access. Read the list. Remove anything you do not
      recognise or no longer use.
☐ Microsoft account (if used): account.microsoft.com > Privacy >
      Apps and services. Same drill.
☐ ChatGPT / Claude / Gemini: open Settings > Connectors or
      Connected apps. Disconnect drives and inboxes any tool no longer
      needs standing access to.
☐ Meeting notetakers (transcription bots): confirm which calendars
      they auto-join, and that they join only YOUR internal meetings,
      never client-facing ones.
☐ Browser extensions: chrome://extensions (or your browser's
      equivalent). Remove any AI extension you cannot name the job of.
☐ Automation links (Zapier, Make, custom GPTs): confirm each
      automation still has an owner, a purpose, and no public trigger
      URL that runs without a login.

Part 3: Locks (3 min)
☐ Two-factor authentication is ON for: main email, bank-linked
      accounts, any AI tool storing your card.
☐ No AI tool shares a password with your email. If one does, change
      it today.
☐ Shared links: in your drive, filter by "shared" and expire any
      public link older than 90 days.

Part 4: Cut (2 min)
☐ Every row in Part 1 marked N (unused 30 days): cancel or
      downgrade. Log the monthly amount you just recovered: S$______
☐ Every cancelled tool: also revoke its access in Part 2 and delete
      your data in the tool's settings where offered.

Red flags: stop and get help the same day
· A connected app you never installed
· A login alert from a device or country that is not yours
· An automation that ran without you triggering it
· Any tool asking to reconnect with broader permissions than before

Why this exists
On 28 Jul 2026, the second victim of the OpenAI rogue-agent incident
was confirmed: a Modal Labs customer, entered through the customer's
own exposed, unauthenticated endpoint (Axios, 28 Jul 2026). Not the
platform. The customer's forgotten door. This checklist is how a solo
professional keeps no forgotten doors.

Sources

  • daily-brief-2026-07-29 (Axios 2026-07-28), daily-brief-2026-07-23