Business Data Backup Checklist Before You Connect AI Tools

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Business Data Backup Checklist Before You Connect AI Tools.
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Business Data Backup Checklist Before You Connect AI Tools.

Back up everything the AI tool will be able to change, plus what you'd need to put things back: the folders and spreadsheets it can edit, the CRM and accounting records it can write to, mailbox rules, automation settings, and a snapshot of who has access to what. Keep one copy outside the connected system, and test one restore before you grant write access.

The question that decides how much work this is: will the tool read your data or write to it? A chat where you upload a copy of a file changes nothing at source. An add-in that edits your live workbook, or an automation that updates CRM records, can change hundreds of things in a minute, and those changes look like ordinary edits. Recycle bins catch deletions. They do very little about a column of prices quietly rounded, or 300 contacts given the wrong owner.

Follow me on Instagram@sagnikteaches

Read access, write access and why the difference matters

Start by listing every AI connection you plan to switch on and sorting it by what it can do. The examples below are typical of what small firms connect first; the options themselves are explained in connecting ChatGPT or Claude to your business apps.

Connect on LinkedInSagnik Bhattacharya
Type of connectionExampleWhat it can changeBackup needed first
Uploading a copy into a chatAttaching a spreadsheet to ChatGPT or ClaudeNothing at source; new files it makes are separateNone beyond normal backups; think about what you upload
Connector that reads (and sometimes creates)Claude's Google Drive connector, which can search and read Drive and create new filesUsually no edits to existing files, but new files and wide visibilityPermissions snapshot so you know what it could see
Add-in that edits the open fileClaude for Excel, Copilot in ExcelCells, formulas, formatting and sheets in the live workbookDated copy of each workbook, version history on, control totals
Automation with an AI stepZapier or Make classifying emails and creating CRM recordsRecords at volume, every time it runsFull CRM export, automation settings exported
Agent acting across apps or in a browserChatGPT Work, Claude in ChromeAnything the signed-in account can editBackup of every system the account can reach, and a narrower account

Vendors build in some protection. Anthropic's Excel add-in warns before it overwrites existing data and asks you to confirm risky operations, and Claude in Chrome is blocked from permanent deletions and purchases whatever permission mode you choose. Those guard rails reduce accidents. They don't stop a correct-looking edit made on a bad instruction, which is why the checklist below assumes the worst sensible case.

Subscribe on YouTube@codingliquids

The checklist, grouped by where your data lives

Work through only the groups that match the systems the AI will touch. Each item says why it matters and how to confirm it's done.

Files and shared folders

  • List the folders the AI account can reach. Connectors see whatever the signed-in account sees, which is often far more than the job needs. Verify by opening the connector's file picker as that user and noting the top-level folders it shows.
  • Copy those folders somewhere the sync can't reach. A backup inside the same OneDrive or Google Drive that's being edited is not a backup, because a sync can carry a mass deletion or overwrite straight into it. Verify by opening three random files from the copy on a different device.
  • Check version history is on for any library the AI will edit. Version history lets you roll back one file without a full restore. Verify by opening one file's version history and seeing earlier versions listed.
  • Remove "anyone with the link" sharing on sensitive folders. An AI connector won't use those links, but a clean-up now makes the permissions snapshot below accurate. Verify with your suite's sharing report.

Spreadsheets that other things depend on

  • Save a dated copy of each workbook the AI will edit, named plainly, such as "Fee tracker 2026-09-27 pre-AI.xlsx". Verify it opens and the formulas still calculate.
  • Record control totals. Write down the row count, the sum of two or three key columns, and the number of formula cells in any calculated column. These three numbers catch most silent damage. Verify by entering them in the backup register at the end of this tutorial.
  • Note every link in and out. Power Query connections, IMPORTRANGE formulas, and other files that read this one will break if the AI renames a sheet or a header. Verify by listing them in the register.

CRM and customer records

  • Export every object the AI can write to (contacts, companies, deals, tickets) with all properties, not the default columns. Verify the export's row count matches the count shown in the CRM.
  • Export or screenshot your custom fields and pipeline stages. If an automation creates a field or renames a stage, you need the original definitions to rebuild. Verify by comparing the list to the CRM settings page.
  • Switch off automatic duplicate merging during the first weeks. A merged record is much harder to undo than an edited one. Verify in the CRM's data-quality or duplicates settings.

Email, calendars and mailbox rules

  • Screenshot or export mailbox rules for any mailbox an AI tool will triage. Tools that sort or label mail can conflict with existing rules, and rebuilding rules from memory is slow. Verify the list against the rules screen.
  • Save your email templates and signatures if the AI will draft or send on your behalf. Verify they're in the backup folder.
  • Know your deleted-items window. Find out how long deleted mail stays recoverable on your plan before you let anything file or delete messages. Verify in your admin settings.

Accounting and finance data

  • Run and save your standard reports (trial balance, aged debtors, aged creditors, and your tax summary) as PDF and CSV on the day you connect. If figures later look wrong, you can prove what they were. Verify the files open.
  • Set a lock date or close the books to the last month-end, if your accounting software offers it, so nothing can post into finished periods. Verify by trying to edit a transaction dated before the lock.
  • Export bank rules and the chart of accounts. AI categorisation tools sometimes create rules of their own, and the originals are your reference. Verify the export against the settings screen.

Automation and integration settings

  • Export the list of Zaps or scenarios with their owners. Make lets you export a scenario blueprint; in Zapier, record each Zap's trigger, steps and folder. Verify every active automation is listed.
  • Export Zap history before changes. Zapier keeps a maximum of 60 days of run data and shows up to 10,000 runs, so anything you need as evidence has to be exported. Verify the export covers the last 60 days.
  • List every API key and where it is used. If you have to cut off a misbehaving tool, you need to know which key to revoke without breaking three other things. Verify each key has a named owner.

Access and permissions snapshot

  • Record who and what has access to each system the AI will reach, including the AI's own account or app connection and its role. After an incident, this tells you whether the AI could have seen or changed something. The process is covered in more depth in checking which apps can access your business accounts. Verify by saving the admin page exports with the date.

What your platforms already keep, and what they don't

Most small firms assume their cloud provider "has a backup". It does, within limits worth knowing precisely.

PlatformWhat it keepsWhat it won't save you from
SharePoint and OneDriveDeleted items stay in the two-stage recycle bin for 93 days in total; an admin can ask Microsoft Support to restore within a further 14 daysHundreds of edits that look legitimate; there's no bulk "undo what the AI did"
Google Drive (Workspace)Trash keeps files for 30 days; an admin can restore items within 25 days after a user empties the trashOverwritten content in many files at once, unless you restore each version by hand
AirtableRevision and snapshot history: 2 weeks on Free, 1 year on Team and BusinessNothing on Free after two weeks; snapshots restore a whole base, not one change
ZapierUp to 60 days of Zap historyThe data the Zap changed in other apps

If you'd rather pay than manage copies yourself, Microsoft 365 Backup is a pay-as-you-go add-on with a list price of $0.15 per GB per month of protected content. For a firm with 40 GB in SharePoint, that works out at $6 a month. Third-party backup services for Microsoft 365 and Google Workspace also exist; whichever you use, the restore test below still applies.

A surveying firm's pre-connection backup, start to finish

An eleven-person surveying firm is about to do two things: let staff use an AI assistant that can read the SharePoint jobs library, and add an AI step to Zapier that reads enquiry emails and creates contacts and deals in the CRM. Before switching either on, the office manager works through the checklist in one afternoon.

  1. Scope (20 minutes). The AI assistant will read the Jobs library (38 GB) and the Fee tracker workbook. The Zap will write to CRM contacts (2,650 records) and deals (410 open).
  2. Files (40 minutes, mostly waiting). The Jobs library is copied to a separate encrypted drive kept in the office safe, and version history is confirmed on.
  3. Spreadsheets (25 minutes). The Fee tracker is saved as a dated copy. Control totals: 1,184 rows, fees column sums to 1,962,340, and column H holds 1,184 formula cells.
  4. CRM (35 minutes). Contacts and deals exported with all properties; row counts match (2,650 and 410). Custom fields screenshotted. Auto-merge switched off.
  5. Automation (30 minutes). Nine existing Zaps listed with owners; 60 days of Zap history exported.
  6. Permissions (20 minutes). SharePoint site membership exported; the Zapier connection's CRM role noted as "can create and edit contacts and deals, cannot delete".
  7. Restore test (30 minutes). Described in the next section.

Total: about three and a half hours of one person's time. The firm also turns on Microsoft 365 Backup for the Jobs library at roughly $5.70 a month (38 GB at $0.15), so it has a second, automatic copy for the weeks when nobody remembers to update the drive.

The restore test that most firms skip

A backup you have never restored is a guess. Pick one item from each group and actually put it back, into a test location, not over the live data. The surveying firm's log looked like this:

ItemBackup sourceRestored toTimeResult
Fee tracker workbookDated copy on the external driveTest folder4 minOpened; control totals matched
One job folder (620 files)External driveTest SharePoint library18 minAll files opened; folder structure intact
25 CRM contactsCSV exportCRM import into a test list9 minFailed first time: created 25 duplicates

The CRM failure is the useful part. The import matched records on name rather than email address, so it created new contacts instead of updating the existing ones. The fix was to include the CRM's record ID column in the export and match on that. Finding this during a calm afternoon is far better than finding it the morning after an automation has overwritten 300 records. Write the corrected steps into the register so whoever does the restore next time doesn't repeat the mistake.

Problems that show up after the AI goes live

These are the kinds of damage the checklist is designed to catch, with how each one tends to surface.

  • Formulas turned into fixed numbers. Someone asks an AI add-in to "clean up" a fee column. The values look right, but the formula count in column H drops from 1,184 to zero, so next month's figures won't update. The control total spots it; the dated copy fixes it. Working safely with spreadsheet add-ins is covered in using Claude with Excel and Google Sheets safely.
  • "Tidied" prices. A request to "make the price list consistent" rounds 1,247.50 to 1,250 across 80 rows. Nobody notices until a client queries a quote. The sum of the price column, recorded beforehand, shows a difference of a few hundred and points straight at it.
  • Two sites merged into one client. An automation decides two records for the same landlord at different addresses are duplicates and merges them, losing one address's job history. With auto-merge off and a full export, the second record can be recreated.
  • A loop that runs overnight. An AI step that creates a task whenever a deal changes, plus another automation that changes the deal when a task is created, produces 900 tasks by morning. The exported Zap list shows which two automations to switch off, and adding a human approval step stops it recurring.
  • A deletion that followed the sync. A folder "archived" by an assistant disappears from every synced laptop. The copy on the separate drive is untouched because it was never part of the sync.

Keeping the backup current once the AI is connected

The one-off backup protects the first day. After that, a light routine keeps you covered:

  • Weekly: an automatic backup of the systems the AI can write to, whether that's a paid backup service or a scheduled export.
  • Before any new permission: rerun the relevant checklist group. Granting a connector access to a new folder or a new CRM object counts.
  • Monthly: restore one item into a test location and record the time.
  • After 30 days: review whether the AI still needs write access everywhere you gave it. Narrowing it often costs nothing and shrinks what a mistake can reach.

A one-page register keeps this in one place. The surveying firm's reads, in part:

AI BACKUP REGISTER (updated 27 Sep)
System        | AI access          | Backup copy            | Control totals          | Last restore test
SharePoint    | Read (assistant)   | External drive + M365  | 38 GB, 14,210 files     | 27 Sep, 18 min, OK
              |                    | Backup                 |                         |
Fee tracker   | Read (assistant)   | Dated copy, weekly     | 1,184 rows; fees        | 27 Sep, 4 min, OK
              |                    |                        | 1,962,340; 1,184 formulas|
CRM contacts  | Create/edit (Zap)  | Weekly CSV with IDs    | 2,650 records           | 27 Sep, 9 min, FAILED
              |                    |                        |                         | then OK matching on ID
Zapier        | n/a                | Zap list + 60-day      | 9 active Zaps           | n/a
              |                    | history export         |                         |
Owner: office manager. Next review: 27 Oct.

That register is also what you'd hand to anyone helping you set up AI tools, because it shows at a glance what can be changed, what protects it and when the protection was last proved to work.

Further reads

Sources: Microsoft Learn and Microsoft Support pages on SharePoint and OneDrive retention and recycle bins, Microsoft 365 Backup pricing; Google Workspace Admin Help on restoring deleted Drive files; Airtable plans overview; Zapier help centre on Zap history; Anthropic documentation for Claude for Excel, the Google Drive connector and Claude in Chrome permissions.

Want a second pair of eyes before AI gets write access?

On a 1:1 call we'll list what each AI tool will be able to change in your systems, decide what needs backing up first, and narrow its access so a mistake stays small and easy to undo.

Book a 1:1 call with me