A few weeks ago, two people on our team each tried a buzzy new personal AI assistant (names undisclosed, for reasons our legal team would call “sensible”); the kind that promises to read your email, your calendar, your messages, and finally get you.
One person lasted about five minutes before disconnecting it. The other gave it a full day before deciding it wasn’t worth it either.
Neither account was about the tool being broken. It worked fine. It’s that having access to everything about someone didn’t make the output any better — it just made the risk bigger for no real payoff. More access, but not more value, which is basically the whole privacy conversation happening around AI right now.
Enterprises ask about it in every connector conversation we have. So we got specific with the two people who built the approach to data and access within Optimizely’s AI, Mark: Imran Yousuf, VP of Software Engineering, and Alex Whitney, Principal Product Manager.
Here’s what actually happens when you connect a system to Mark.
What a connector actually is
Connector is one of those words that means something different depending on who’s using it, and in AI, that ambiguity causes real confusion.
It’s a tool, and a tool is a wrapper around an API you were already using. When Mark connects to Salesforce, Gmail, or Teams, it authenticates with the same credentials and hits the same endpoints a person would use logging in directly. Nothing new gets exposed; the interface is just conversational instead of a UI you click through.
That distinction gets missed constantly, because people trust “API” (something they’ve used for twenty years) and are wary of “AI tool” (something that feels new). It’s the same risk surface, wearing a different name.
How access gets scoped
Access in Mark is scoped to you. Connect your own Teams account and you see the chats you’re already in — not every conversation at the company. Connect Gmail and you’re scoped to the inbox you authenticated with, exactly as if you’d logged into gmail.com yourself. No new data gets created by the act of connecting; if you couldn’t see something before, connecting a tool doesn’t change that.
There’s a less obvious effect too: connecting a tool actually reduces the amount of data moving around, compared to the alternative. If you were already planning to paste an email thread into a chat window for help with it, that data was leaving its original system either way — you were just moving it manually, with no record of who else might see the copy-paste. A connector replaces that with a scoped, auditable action.
Not a new door. The same door, with a record of who walked through it.
What gets logged, and who can see it
Most AI products can’t tell you what they did with your data during a session. Mark keeps an execution log of every tool call — across agents and regular chat — and makes it inspectable. That’s not an agent-only feature bolted on for enterprise; it’s logged the same way no matter how you’re using Mark.
For a buyer evaluating the platform, that’s the difference between being told to trust the system and being able to verify it themselves.
Why Mark won’t let agents drive your browser
One deliberate architecture choice: Mark doesn’t let agents control a live, stateful browser session. Some AI tools let an agent log into a site and operate inside that session directly, which means once you’ve logged in, what happens next is out of your hands. The session exists outside any single, auditable action.
Mark keeps everything inside the path of a tool call instead: authenticated through OAuth, scoped to a specific action, logged, and revocable at any time. Disconnect a tool and the access ends immediately — there’s no lingering session to account for.
Admins decide what’s available before anyone touches it
Control starts further upstream than the individual connection. Admins can enable or disable specific tools within a connector at the instance level, before anyone on the team can connect to anything — unlike most platforms, which ship an integration with every tool switched on by default.
An admin can keep Google Calendar available while switching Gmail off entirely, so it’s not even an option on the list. For teams working under strict data-handling rules, that’s often what makes adoption possible at all.
What happens to your data after the call ends
Mark only works with LLM providers running on Optimizely’s own cloud infrastructure, under a zero-data-retention agreement — the providers don’t store or train on anything that flows through them. Delete an execution log or a file, and it’s gone. Not hidden. Gone.
Bring your own MCP
Mark ships with a growing, curated set of built-in connectors for enterprise marketing workflows, but it’s not a closed list. Customers can connect their own MCP servers and get the same OAuth-based, per-user access model applied to systems Mark didn’t build a dedicated integration for.
Security isn’t a special case reserved for Optimizely-built connectors. It’s the standard every connection runs through.
The takeaway
Enterprises don’t ask about data privacy because they distrust AI as a category. They ask because they’ve seen what happens when a system accumulates access faster than anyone tracks it.
Mark’s answer isn’t “trust us”; it’s a specific, inspectable set of guarantees: access scoped to what you already have, every call logged, admin control over what’s even available, and a flat no on training. Not the flashiest story to tell about AI. It’s the one enterprise teams need answered before they’ll connect anything at all.
Want to find out more about Mark and Optimizely Agent Platform? Head to optimizely.com/ai.