Back up everything the AI tool will be able to change, plus what you'd need to put things back: the folders and spreadsheets it can edit, the CRM and accounting records it can write to, mailbox rules, automation settings, and a snapshot of who has access to what. Keep one copy outside the connected system, and test one restore before you grant write access.
The question that decides how much work this is: will the tool read your data or write to it? A chat where you upload a copy of a file changes nothing at source. An add-in that edits your live workbook, or an automation that updates CRM records, can change hundreds of things in a minute, and those changes look like ordinary edits. Recycle bins catch deletions. They do very little about a column of prices quietly rounded, or 300 contacts given the wrong owner.
Read access, write access and why the difference matters
Start by listing every AI connection you plan to switch on and sorting it by what it can do. The examples below are typical of what small firms connect first; the options themselves are explained in connecting ChatGPT or Claude to your business apps.
| Type of connection | Example | What it can change | Backup needed first |
|---|---|---|---|
| Uploading a copy into a chat | Attaching a spreadsheet to ChatGPT or Claude | Nothing at source; new files it makes are separate | None beyond normal backups; think about what you upload |
| Connector that reads (and sometimes creates) | Claude's Google Drive connector, which can search and read Drive and create new files | Usually no edits to existing files, but new files and wide visibility | Permissions snapshot so you know what it could see |
| Add-in that edits the open file | Claude for Excel, Copilot in Excel | Cells, formulas, formatting and sheets in the live workbook | Dated copy of each workbook, version history on, control totals |
| Automation with an AI step | Zapier or Make classifying emails and creating CRM records | Records at volume, every time it runs | Full CRM export, automation settings exported |
| Agent acting across apps or in a browser | ChatGPT Work, Claude in Chrome | Anything the signed-in account can edit | Backup of every system the account can reach, and a narrower account |
Vendors build in some protection. Anthropic's Excel add-in warns before it overwrites existing data and asks you to confirm risky operations, and Claude in Chrome is blocked from permanent deletions and purchases whatever permission mode you choose. Those guard rails reduce accidents. They don't stop a correct-looking edit made on a bad instruction, which is why the checklist below assumes the worst sensible case.
The checklist, grouped by where your data lives
Work through only the groups that match the systems the AI will touch. Each item says why it matters and how to confirm it's done.
Files and shared folders
- List the folders the AI account can reach. Connectors see whatever the signed-in account sees, which is often far more than the job needs. Verify by opening the connector's file picker as that user and noting the top-level folders it shows.
- Copy those folders somewhere the sync can't reach. A backup inside the same OneDrive or Google Drive that's being edited is not a backup, because a sync can carry a mass deletion or overwrite straight into it. Verify by opening three random files from the copy on a different device.
- Check version history is on for any library the AI will edit. Version history lets you roll back one file without a full restore. Verify by opening one file's version history and seeing earlier versions listed.
- Remove "anyone with the link" sharing on sensitive folders. An AI connector won't use those links, but a clean-up now makes the permissions snapshot below accurate. Verify with your suite's sharing report.
Spreadsheets that other things depend on
- Save a dated copy of each workbook the AI will edit, named plainly, such as "Fee tracker 2026-09-27 pre-AI.xlsx". Verify it opens and the formulas still calculate.
- Record control totals. Write down the row count, the sum of two or three key columns, and the number of formula cells in any calculated column. These three numbers catch most silent damage. Verify by entering them in the backup register at the end of this tutorial.
- Note every link in and out. Power Query connections, IMPORTRANGE formulas, and other files that read this one will break if the AI renames a sheet or a header. Verify by listing them in the register.
CRM and customer records
- Export every object the AI can write to (contacts, companies, deals, tickets) with all properties, not the default columns. Verify the export's row count matches the count shown in the CRM.
- Export or screenshot your custom fields and pipeline stages. If an automation creates a field or renames a stage, you need the original definitions to rebuild. Verify by comparing the list to the CRM settings page.
- Switch off automatic duplicate merging during the first weeks. A merged record is much harder to undo than an edited one. Verify in the CRM's data-quality or duplicates settings.
Email, calendars and mailbox rules
- Screenshot or export mailbox rules for any mailbox an AI tool will triage. Tools that sort or label mail can conflict with existing rules, and rebuilding rules from memory is slow. Verify the list against the rules screen.
- Save your email templates and signatures if the AI will draft or send on your behalf. Verify they're in the backup folder.
- Know your deleted-items window. Find out how long deleted mail stays recoverable on your plan before you let anything file or delete messages. Verify in your admin settings.
Accounting and finance data
- Run and save your standard reports (trial balance, aged debtors, aged creditors, and your tax summary) as PDF and CSV on the day you connect. If figures later look wrong, you can prove what they were. Verify the files open.
- Set a lock date or close the books to the last month-end, if your accounting software offers it, so nothing can post into finished periods. Verify by trying to edit a transaction dated before the lock.
- Export bank rules and the chart of accounts. AI categorisation tools sometimes create rules of their own, and the originals are your reference. Verify the export against the settings screen.
Automation and integration settings
- Export the list of Zaps or scenarios with their owners. Make lets you export a scenario blueprint; in Zapier, record each Zap's trigger, steps and folder. Verify every active automation is listed.
- Export Zap history before changes. Zapier keeps a maximum of 60 days of run data and shows up to 10,000 runs, so anything you need as evidence has to be exported. Verify the export covers the last 60 days.
- List every API key and where it is used. If you have to cut off a misbehaving tool, you need to know which key to revoke without breaking three other things. Verify each key has a named owner.
Access and permissions snapshot
- Record who and what has access to each system the AI will reach, including the AI's own account or app connection and its role. After an incident, this tells you whether the AI could have seen or changed something. The process is covered in more depth in checking which apps can access your business accounts. Verify by saving the admin page exports with the date.
What your platforms already keep, and what they don't
Most small firms assume their cloud provider "has a backup". It does, within limits worth knowing precisely.
| Platform | What it keeps | What it won't save you from |
|---|---|---|
| SharePoint and OneDrive | Deleted items stay in the two-stage recycle bin for 93 days in total; an admin can ask Microsoft Support to restore within a further 14 days | Hundreds of edits that look legitimate; there's no bulk "undo what the AI did" |
| Google Drive (Workspace) | Trash keeps files for 30 days; an admin can restore items within 25 days after a user empties the trash | Overwritten content in many files at once, unless you restore each version by hand |
| Airtable | Revision and snapshot history: 2 weeks on Free, 1 year on Team and Business | Nothing on Free after two weeks; snapshots restore a whole base, not one change |
| Zapier | Up to 60 days of Zap history | The data the Zap changed in other apps |
If you'd rather pay than manage copies yourself, Microsoft 365 Backup is a pay-as-you-go add-on with a list price of $0.15 per GB per month of protected content. For a firm with 40 GB in SharePoint, that works out at $6 a month. Third-party backup services for Microsoft 365 and Google Workspace also exist; whichever you use, the restore test below still applies.
A surveying firm's pre-connection backup, start to finish
An eleven-person surveying firm is about to do two things: let staff use an AI assistant that can read the SharePoint jobs library, and add an AI step to Zapier that reads enquiry emails and creates contacts and deals in the CRM. Before switching either on, the office manager works through the checklist in one afternoon.
- Scope (20 minutes). The AI assistant will read the Jobs library (38 GB) and the Fee tracker workbook. The Zap will write to CRM contacts (2,650 records) and deals (410 open).
- Files (40 minutes, mostly waiting). The Jobs library is copied to a separate encrypted drive kept in the office safe, and version history is confirmed on.
- Spreadsheets (25 minutes). The Fee tracker is saved as a dated copy. Control totals: 1,184 rows, fees column sums to 1,962,340, and column H holds 1,184 formula cells.
- CRM (35 minutes). Contacts and deals exported with all properties; row counts match (2,650 and 410). Custom fields screenshotted. Auto-merge switched off.
- Automation (30 minutes). Nine existing Zaps listed with owners; 60 days of Zap history exported.
- Permissions (20 minutes). SharePoint site membership exported; the Zapier connection's CRM role noted as "can create and edit contacts and deals, cannot delete".
- Restore test (30 minutes). Described in the next section.
Total: about three and a half hours of one person's time. The firm also turns on Microsoft 365 Backup for the Jobs library at roughly $5.70 a month (38 GB at $0.15), so it has a second, automatic copy for the weeks when nobody remembers to update the drive.
The restore test that most firms skip
A backup you have never restored is a guess. Pick one item from each group and actually put it back, into a test location, not over the live data. The surveying firm's log looked like this:
| Item | Backup source | Restored to | Time | Result |
|---|---|---|---|---|
| Fee tracker workbook | Dated copy on the external drive | Test folder | 4 min | Opened; control totals matched |
| One job folder (620 files) | External drive | Test SharePoint library | 18 min | All files opened; folder structure intact |
| 25 CRM contacts | CSV export | CRM import into a test list | 9 min | Failed first time: created 25 duplicates |
The CRM failure is the useful part. The import matched records on name rather than email address, so it created new contacts instead of updating the existing ones. The fix was to include the CRM's record ID column in the export and match on that. Finding this during a calm afternoon is far better than finding it the morning after an automation has overwritten 300 records. Write the corrected steps into the register so whoever does the restore next time doesn't repeat the mistake.
Problems that show up after the AI goes live
These are the kinds of damage the checklist is designed to catch, with how each one tends to surface.
- Formulas turned into fixed numbers. Someone asks an AI add-in to "clean up" a fee column. The values look right, but the formula count in column H drops from 1,184 to zero, so next month's figures won't update. The control total spots it; the dated copy fixes it. Working safely with spreadsheet add-ins is covered in using Claude with Excel and Google Sheets safely.
- "Tidied" prices. A request to "make the price list consistent" rounds 1,247.50 to 1,250 across 80 rows. Nobody notices until a client queries a quote. The sum of the price column, recorded beforehand, shows a difference of a few hundred and points straight at it.
- Two sites merged into one client. An automation decides two records for the same landlord at different addresses are duplicates and merges them, losing one address's job history. With auto-merge off and a full export, the second record can be recreated.
- A loop that runs overnight. An AI step that creates a task whenever a deal changes, plus another automation that changes the deal when a task is created, produces 900 tasks by morning. The exported Zap list shows which two automations to switch off, and adding a human approval step stops it recurring.
- A deletion that followed the sync. A folder "archived" by an assistant disappears from every synced laptop. The copy on the separate drive is untouched because it was never part of the sync.
Keeping the backup current once the AI is connected
The one-off backup protects the first day. After that, a light routine keeps you covered:
- Weekly: an automatic backup of the systems the AI can write to, whether that's a paid backup service or a scheduled export.
- Before any new permission: rerun the relevant checklist group. Granting a connector access to a new folder or a new CRM object counts.
- Monthly: restore one item into a test location and record the time.
- After 30 days: review whether the AI still needs write access everywhere you gave it. Narrowing it often costs nothing and shrinks what a mistake can reach.
A one-page register keeps this in one place. The surveying firm's reads, in part:
AI BACKUP REGISTER (updated 27 Sep)
System | AI access | Backup copy | Control totals | Last restore test
SharePoint | Read (assistant) | External drive + M365 | 38 GB, 14,210 files | 27 Sep, 18 min, OK
| | Backup | |
Fee tracker | Read (assistant) | Dated copy, weekly | 1,184 rows; fees | 27 Sep, 4 min, OK
| | | 1,962,340; 1,184 formulas|
CRM contacts | Create/edit (Zap) | Weekly CSV with IDs | 2,650 records | 27 Sep, 9 min, FAILED
| | | | then OK matching on ID
Zapier | n/a | Zap list + 60-day | 9 active Zaps | n/a
| | history export | |
Owner: office manager. Next review: 27 Oct.
That register is also what you'd hand to anyone helping you set up AI tools, because it shows at a glance what can be changed, what protects it and when the protection was last proved to work.
Further reads
- AI Vendor Lock-In: How to Keep Your Data and Prompts Portable — Keep your data and prompts portable if you change AI tools.
- What Can Go Wrong When AI Agents Take Actions for You? — What else goes wrong once AI can take actions for you.
- Where Is Your Data Stored When You Use AI Tools? — Where copies of your data end up once a tool reads it.
- What Is Prompt Injection and Should a Small Business Worry? — How hidden instructions in files can trigger unwanted edits.
- How to Clean Up SharePoint Permissions Before Turning On Copilot — Tighten who can see what before Copilot reads it.
- How to Stop Zapier and Make Automations Breaking Silently — Catch failed or runaway automations before they do damage.
- How to Prepare Your Business Data for AI, Step by Step — Eight steps from scattered spreadsheets to data an AI tool reads correctly, with a photography studio's 1,400 client records as the example.
- How to Clean Up Customer Records Before You Add AI — Four clean-up passes that stop AI emailing people twice, or at all when they said no, with matching rules and a merge log.
- How to Organise Shared Files So AI Tools Can Use Them — Three afternoons to get a shared drive ready for Copilot, Gemini or ChatGPT, with a wedding planner's folder tree and a ten-question test.
- How to Clean Up a Messy CRM With AI — A four-day CRM clean-up: audit the mess, merge duplicates safely, let AI standardise fields and rescue facts from notes, and set rules so it stays clean.
- n8n Self-Hosted vs Cloud: Real Costs for a Small Business — Both price lists side by side, the upkeep hours self-hosting really takes, and a roofing contractor's year costed both ways.
- Is Your Business Data Ready for AI? A Clean-Up Checklist — A 50-record sample test and a five-part clean-up checklist, each item with why it matters and how to check it, plus a record cleaned before and after.
- Business Continuity Planning With AI: A Template for Small Firms — A ten-section continuity plan template with the checks for each item, plus prompts that let AI interview you and run a tabletop test.
- What Connecting Two Business Apps Really Costs: Four Options — Price the whole app connection with four routes, a worked annual budget and tests for duplicates, delays and failures.
- AI Security Checklist Before Connecting Tools to Email and Files — Twenty checks to run before an AI tool touches your inbox or shared drive, from reading the permission screen to rehearsing how to disconnect it.
- How to Turn On Two-Factor Authentication for Every AI Account — Setting paths checked on each vendor's help pages, the order to work in, which second step suits whom, and a recovery-code register filled in.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: Microsoft Learn and Microsoft Support pages on SharePoint and OneDrive retention and recycle bins, Microsoft 365 Backup pricing; Google Workspace Admin Help on restoring deleted Drive files; Airtable plans overview; Zapier help centre on Zap history; Anthropic documentation for Claude for Excel, the Google Drive connector and Claude in Chrome permissions.