Insights

AI strategy in CRE

·

8 min read

·

AI Email Inbox Security Is a Scope Problem, Not a Trust Problem

Ask an acquisitions principal why the firm has not connected an AI tool to the deal inbox and the answer lands on trust. That answer is wrong about itself. AI email inbox security in commercial real estate is not a question of whether the model reads a rent roll correctly. It is a question of what the model is permitted to see. The standard integration asks for one grant covering every message in the account, and in a CRE firm that account holds the capital call, the employment dispute, the wire instruction, and the offering memorandum the firm signed an NDA to receive. The firm is not refusing AI. It is refusing an undifferentiated grant, and it is right to.

Key Takeaways

  • A mailbox is not a document store that happens to receive mail. It is the unclassified sum of everything the firm has ever been told, and it has no access tier below all of it.

  • Google classifies Gmail read access as a restricted scope, requiring an independent security assessment renewed at least every 12 months for any app handling that data off-device.

  • Microsoft Graph application permissions reach every mailbox in the tenant by default. Exchange Online RBAC for Applications narrows that, and almost no CRE procurement asks about it.

  • The FBI recorded $3.05 billion in verified business email compromise losses in 2025. The inbox was the firm's softest surface long before any AI touched it.

  • Routing deal mail to a dedicated intake address cuts the messages inside the permission boundary by roughly 98 percent, with no loss of screening capability.

Why is the inbox the broadest permission a CRE firm can grant?

Because the inbox is the firm's only unclassified record of itself. Deal documents, wire instructions, legal correspondence, personnel matters, and investor communications all land in the same store with no labeling layer between them. A single read grant over that store is broader than the access most firms give a partner.

Every other system has a natural boundary. Accounting holds accounting. The data room holds one deal. The mailbox holds all of it, plus what never reached a system: the side conversation about a tenant's credit, the counsel email about a boundary dispute, the LP who wants out. Deloitte's 2026 commercial real estate outlook, surveying more than 850 C-level executives at owners and investors with at least $250 million under management, notes that real estate data routinely carries bank account and Social Security numbers, tenant names, and mortgage payment status.

What sits in an acquisitions mailbox

Sensitivity

Where else it lives

Offering memorandums and broker packages

Confidential under an executed NDA

Data room, for a limited window

Rent rolls, T-12s, tenant correspondence

Tenant-identifying, sometimes payment data

Deal folder, if someone filed it

Wire instructions and closing statements

Direct fraud target

Title company, escrow

LP communications, capital calls, side letters

Investor-confidential

Investor portal

Counsel correspondence

Privileged

Nowhere else

Personnel and compensation threads

Employment-sensitive

HR, sometimes

Six categories, six different rules about who may see them, and one permission model that does not distinguish between any of them. That is the objection, stated properly.

What does an AI tool get when you connect it to email?

In the default implementation, every message in the mailbox and every message that arrives after, until someone revokes the token. Google classifies Gmail read access as a restricted scope covering all mail. Microsoft Graph application permissions apply to every mailbox in the tenant unless an administrator narrows them deliberately.

Both platforms publish this plainly. Google's restricted scope verification policy places Gmail read and modify scopes in the restricted tier, and an app moving that data through a third-party server must complete an independent security assessment and be reassessed at least every 12 months to keep access. Microsoft's RBAC for Applications in Exchange Online documentation states that permissions granted in Entra apply to all mailboxes in the tenant, and that limiting an app to specific mailboxes requires a management scope configured by an administrator.

Permission

Default reach

Can it be narrowed

Who narrows it

Gmail gmail.readonly

All mail and settings in the account

Not below the account

Nobody. The account is the unit

Graph Mail.ReadBasic

All mailboxes, bodies excluded

By management scope

Exchange administrator

Graph Mail.Read

All mailboxes in the tenant

By management scope via RBAC for Applications

Exchange administrator

Forwarding rule to a dedicated address

Only what is forwarded

By construction

Anyone who writes the rule

Read the last column. Two of these controls sit with the firm's own administrator and one sits with whoever writes a mail rule. None require the vendor to build anything. Most firms waiting on vendor security have not exercised the controls they already hold.

Does letting an AI read an offering memorandum breach the NDA?

It depends on terms most buyers never check. A standard CRE confidentiality agreement permits disclosure to the recipient's representatives who need the information and who are bound by the same obligations. A vendor that retains the document, trains on it, or routes it to a subprocessor is not covered by that language.

The confidentiality legend on a broker package is conventional: the information is furnished solely for the recipient's evaluation and may not be made available to any other person without written consent. The representatives carve-out is what permits third-party processing at all, and it carries two conditions. The representative must need the information for the permitted purpose, and must be bound to the same terms.

That turns a vague worry into four contract questions with yes or no answers. Does the vendor train models on customer content, in the contract rather than the marketing page? What is the retention window, and does deletion include backups? Which subprocessors touch the data, and are they bound downstream? Is the firm's data isolated from other tenants, or pooled?

A vendor answering all four in writing is a representative under the agreement. One that will not is a disclosure the seller never consented to. That is a contracting exercise rather than a technical one, and it is the diligence any CRE technology purchase deserves, covered in choosing AI tools for CRE workflows.

How should a CRE firm scope AI access to email?

Narrow the mailbox, narrow the permission, narrow the retention, and log every read. Four controls carry most of the risk reduction: a dedicated intake address instead of a personal account, an administratively scoped application permission, a contractual no-training and deletion term, and a per-message record of what the system read.

Work the exposure math from stated inputs. Take a firm with 12 mailboxes across acquisitions and asset management, each receiving 120 messages per business day, and 18 months of retained mail in scope, or 375 business days. A tenant-wide grant puts 12 × 120 × 375 = 540,000 messages inside the permission boundary. Now route broker distributions to a dedicated intake address. The firm receives 1,400 offering memorandums a year, or 2,100 over the same 18 months, and each deal thread runs roughly four messages. That is 8,400 messages in scope.

Configuration

Messages in scope

Share of the tenant-wide grant

Screening capability

Tenant-wide Mail.Read

540,000

100 percent

Full

Twelve personal mailboxes, scoped

540,000

100 percent

Full

Dedicated intake address

8,400

1.6 percent

Full

The third row does the same job as the first. Every offering memorandum still gets read, extracted, and scored. What changes is that counsel correspondence, wire instructions, and personnel threads were never inside the boundary, so no revocation, no deletion request, and no vendor incident can reach them. Risk never accepted does not need to be managed.

The intake address is the better workflow independent of security, because it gives inbound deal flow a queue instead of twelve private piles, an argument made in the OM inbox problem and in the intake workflow that closes the loop. Security and throughput point at the same design, which is rare enough to notice.

What does refusing to connect the inbox cost?

It costs the screening capacity the firm already pays for. Deal flow arrives as email attachments, and a firm that will not automate the reading of them processes inbound at the speed of whoever opens the message. The refusal is defensible. Leaving it unresolved for two years is not.

Deloitte's 2026 outlook found 19 percent of CRE respondents still in the early stages of their AI journey and 27 percent reporting implementation difficulty from technical issues, missing expertise, or internal resistance. Inbox access is where much of that stall sits, because it is the one integration nobody can pilot quietly in a corner. It needs an administrator, a contract review, and a signature.

The threat environment is not an argument against connecting. It is an argument for connecting carefully. The FBI's Internet Crime Complaint Center reported $3.05 billion in verified business email compromise losses in 2025 across 24,768 complaints, inside $20.9 billion of total reported cybercrime losses. None of that happened in a mailbox an AI had touched. A scoping exercise that finally produces an intake address, a logged read trail, and a written no-training term leaves the firm safer than it was before the question came up. Whether that trail survives scrutiny is a separate discipline, covered in chain of custody for AI-extracted CRE data.

Frequently Asked Questions

Is it safe to give an AI tool access to a company email account?

Access to a full account is rarely the right grant. The safer pattern is a dedicated intake address receiving only the mail the tool needs, plus an administratively scoped permission and a contractual retention limit. The question is not whether AI is safe but how much mail sits inside the boundary.

Does connecting AI to email violate an offering memorandum NDA?

Not automatically. Most CRE confidentiality agreements permit disclosure to representatives who need the information and are bound by the same terms. A vendor that contractually agrees not to train on the content, deletes on a defined schedule, and binds its subprocessors generally fits. One that will not commit in writing does not.

What is the difference between a sensitive and a restricted OAuth scope?

Google requires app verification for sensitive scopes, and both verification and an independent third-party security assessment for restricted scopes. Gmail read, modify, and metadata scopes fall in the restricted tier, and apps handling that data off-device must be reassessed at least every 12 months.

Can an administrator limit which mailboxes an application can read?

Yes, in Microsoft 365. RBAC for Applications in Exchange Online pairs an application permission with a management scope listing the mailboxes it may reach, replacing the older Application Access Policies. Google Workspace has no equivalent sub-account scope, which is why the dedicated address pattern matters more on Gmail.

Conclusion

The inbox objection gets dismissed as conservatism, and the dismissal is lazy. A firm that hesitates to hand over its mailbox has correctly identified that the mailbox is the firm: every document, every negotiation, every confidence, in one store with one permission tier. Refusing a grant that broad is judgment. Treating the refusal as final is not.

The resolution is not more trust in the model. It is less surface for the model to stand on. Move deal mail to an address that exists for that purpose, scope the permission at the administrator level, put the no-training and retention terms in the contract, and keep a record of every message the system read. Do that and the question changes from whether the firm trusts AI with its email to whether the firm has ever defined what its email is for. Most have not, and that gap costs more than the integration ever will.