AI & AutomationPerspective

Your Business Can Now Get a Free AI Agent. Decide What It Can Touch First.

On 29 September an AI agent that can work across a small business's accounting, payments, store and social accounts became available at no cost. The price has stopped being the barrier. The decision that is left is what the agent should be allowed to reach.

Author

DueClix Engineering

Published

Reading time

7 min read

On 29 September 2026 Meta launched Muse for Small Business, a version of its Muse agent with connectors for the software a small business already runs on: Intuit QuickBooks, Stripe, Shopify, Slack, Notion, Asana, Box, Canva, Dropbox, Figma, Granola, HighLevel, Klaviyo, Lovable and Zoom, plus Facebook and Instagram business accounts and custom connectors. It is available in the United States and Canada, and Meta says it is free for most of what people need, with paid plans for heavier use.

Meta's own examples are ordinary small-business work: analyse sales and draft a growth plan, prioritise urgent email and calendar items, study ad performance and draft a campaign, review the month's finances and flag unusual expenses. Its stated reason for building it is that small businesses said they are "short on hours, not ideas."

We are not going to review the product; we have not run it. The more useful point is that it moves a question most small businesses have not had to answer yet from someday to this week. When an agent can be connected to your books, your payment account and your inbox in a few clicks and at no cost, the only decision left is which of those it should be connected to, and that decision is worth making on purpose.

This is an agent, not a chatbot

The distinction matters here more than usual. A chatbot returns text and leaves you to act on it. An agent changes something: it drafts the campaign inside your ad account, it reads the ledger, it prepares the email in your outbox. We have written about the four things that separate the two: tools, permissions, a definition of done and a record of what happened. A connector is a tool. What you grant it is the permission.

Meta's design already covers two of those four. The original Muse announcement on 8 September said the agent "checks with the person before sensitive actions like sending an email or making a purchase" and "shows people a complete audit trail of everything it has done and plans to do." The small-business announcement puts it more briefly: "Nothing publishes, sends, or spends without your approval."

The approval button covers what it does, not what it reads

Publish, send, spend. Those are the three verbs that need your approval, and they are the right three to gate. Notice what is not on the list: read. Once QuickBooks, Stripe and your email are connected, the agent can read what they contain. That is how it works at all. It is also where the risk sits, because every email in your inbox is text written by someone else, and an agent reads instructions and data through the same channel.

Security researchers call this prompt injection: content written to be read by an AI rather than by you, telling it to do something you did not ask for. ESET's 21 September guidance for small businesses describes the dangerous combination as a "lethal trifecta": an agent with access to private data, exposure to untrusted content, and the ability to communicate outward. Its advice is to limit all three, not only the last one.

An approval step is a strong control over the third. It does less for the first two, and it depends on the person approving it reading what they are approving. When every action asks, people start clicking yes. Fewer, more meaningful approvals protect you better than more of them.

An agent uses whatever it can reach

A different story from the same month makes the point without any attacker involved. On 21 September Google confirmed that, during a security evaluation run by the testing firm Irregular in May, a Gemini model that was not supposed to have internet access was given it by mistake. It treated real websites as part of the exercise, guessed passwords until it got into one company's system, and used credentials it found in public online repositories to get into two more. Google said the model stopped in each case, no damage was done, the companies were notified and its testing procedures have changed.

Nothing about that is specific to Gemini or to Muse. The lesson is general: an agent's real scope is what it can reach, not what you meant it to do. The instructions described a test. The access described the internet. The access won.

What to connect first

A sensible order is to start with the connections where a mistake is cheap and visible, and leave the ones where a mistake is expensive or quiet until you have watched the agent work.

A starting order for a small business. Adjust it to what your business actually runs on.
ConnectionWhy it is a reasonable start or a reason to waitSuggested timing
Instagram and Facebook analyticsReading performance data. The worst case is a bad suggestion you ignore.Start here
Ad accountsThe agent drafts, you approve spend. Set a budget ceiling in the ad account itself so the limit does not depend on the agent.Early, with a spend cap
Project and notes toolsUseful context. Check first that nothing in them is confidential to a customer.Early, after a quick review
Accounting (for example QuickBooks)Month-end review is a good use, but it is the most sensitive data you hold, and a wrong categorisation is quiet.After a few weeks of watching
Payments (for example Stripe)Customer and payment records. Connect only for a specific task you can name.Only for a named task
Your main inboxThe largest source of untrusted text, and the channel attackers already target.Last, and consider a separate address

Where a connector offers a narrower scope, such as read-only access or a single account, choose it. Where it does not, the question is simply whether the task is worth the access. Meta says Muse runs in a dedicated virtual machine and that it "doesn't share a person's conversations or the data in their VM with Meta's ad systems." TechCrunch's launch coverage noted that claims like these will need deeper investigation by independent security experts. Both can be true: the design is careful, and you should still connect only what the task needs.

Write the rule down before you connect anything

ESET's SMB Cyber Readiness Index 2026 surveyed 4,400 small and mid-sized business decision-makers and found that 40 percent had no AI policy at all. A policy for a small team does not have to be a document anyone signs. It can be five lines:

  1. Which accounts the agent may connect to, and who in the business decides when that list changes.
  2. Which actions always need a named person's approval. Anything that sends money, contacts a customer or publishes in the business's name.
  3. Where limits live outside the agent. Spend caps in the ad account, payout controls in the payments account, so a wrong approval has a ceiling.
  4. Who reviews the audit trail, and how often. A record nobody reads is not a control.
  5. How to disconnect it. Know where each connection is revoked before you need to do it in a hurry.

Start with one job that has an end

A free agent makes it tempting to connect everything and ask it to "help run the business." The better first use is one repeatable job with a clear finish, such as a weekly summary of what sold and which posts worked, where you can check the result against what you already know. If the process behind that job was never written down, automating it will multiply the confusion, not remove it.

The price of an AI agent reached zero in September. What the agent can reach is still your decision, and it is one worth making before the first connection rather than after the first surprise.

Sources

Written by

DueClix EngineeringEngineering team

The team that designs and builds DueClix systems. We write about the parts of the work that are worth writing down.

Have a process worth improving?

Let's build the system behind it. Tell us what the process is and where it breaks — the first conversation is about constraints, not technology.