Revoke it: the most important button your child will ever press
Granting an AI access to an app is not the important skill. Taking it back is. Here is why teaching a child to disconnect matters more than teaching them to connect.
We connected an AI to a child's photo folder for exactly one task - finding every picture with a bicycle in it - and then, as the next step in the same exercise, disconnected it immediately afterward. Every child in that session remembered the disconnect step a week later. Almost none of them remembered the exact wording they'd used to connect it in the first place. The revoke was the part that stuck.
That is not an accident of memory. Granting access is a small, forgettable decision. Taking it back is the decision that actually determines how much risk a connection carried in total, which is why it deserves to be the headline skill of this whole level, not an afterthought at the end of it.
How do I disconnect an app from an AI?
Every connector worth using has a visible off switch - in the assistant's settings, in the connected app's own permissions list, or both. The habit worth teaching is not just knowing where that switch lives, but using it as a matter of course once a task is done, rather than leaving connections active "just in case" they're needed again.
A photo folder stays connected for months after the one task it was needed for. Nobody remembers granting it. Nobody is checking what it can still see.
The folder is disconnected the moment the bicycle search is done. Reconnecting later, if ever needed, takes ten seconds.
Why revoking matters more than granting
Permission you can take back is the only permission worth giving in the first place. An access grant with no realistic path to revoking it - buried three menus deep, or simply never checked again - is not really a controlled decision. It is a decision made once and then quietly permanent, which defeats the entire point of scoped, reversible access from the first article in this level.
The honest limit
Revoking access stops future reading. It does not erase what an AI already saw or said while it was connected - a fact it learned from a calendar last week does not un-learn itself the moment access ends. That is a genuine limit, not a reason to skip revoking, but it is why the strongest habit is scoping narrowly from the start rather than relying on disconnect alone to undo an overly broad grant. That closes out connectors; the next level, agents, is where an AI stops waiting to be asked and starts acting on a trigger - which makes every permission decision from this level matter even more.
Questions we get asked
How do I disconnect an app from an AI assistant?
Every well-built connector has a visible off switch, either in the AI assistant's own settings or in the connected app's permissions list. The important habit is using it as soon as a task is finished, rather than leaving a connection active indefinitely because it might be needed again someday.
Why is revoking AI permissions more important than granting them?
Because a permission with no realistic path back to off is not really a controlled decision - it becomes permanent by default. Access that can be taken back easily is what makes granting it in the first place a reasonable risk; access nobody ever revisits quietly turns into standing exposure nobody chose on purpose.
Does revoking access delete what an AI already learned?
No - disconnecting a source stops future reading, but it does not erase facts the AI already picked up while it was connected. This is a real limit, which is why scoping a connection narrowly from the start matters as much as remembering to revoke it afterward.
