Muse for Small Business: What to Connect, What to Skip
Meta's Muse for Small Business plugs into QuickBooks, Stripe, Shopify and Slack. Its own security post explains why you should scope it first.

Meta just handed its Muse agent the keys to your books, your store, and your ad account. Then, in a separate post, Meta explained exactly how an attacker could talk it into misusing them. That is the honest version of the Muse for Small Bus
Meta just handed its Muse agent the keys to your books, your store, and your ad account. Then, in a separate post, Meta explained exactly how an attacker could talk it into misusing them.
That is the honest version of the Muse for Small Business launch. It is a genuinely useful product with a genuinely candid safety document, and the gap between the two is your setup work.
Muse for Small Business connects your whole back office
On September 29, 2026, Meta announced Muse for Small Business: new skills and connectors inside the Muse personal agent it launched on September 8. You give Muse a goal, like "run my business" or "find me new customers," and it works in the background across the tools you link.
The named connectors are Asana, Box, Canva, Dropbox, Figma, Granola, HighLevel, Intuit QuickBooks, Klaviyo, Lovable, Notion, Shopify, Slack, Stripe, and Zoom. Facebook Pages, Instagram professional accounts, and Meta ad accounts connect too. Muse also supports custom connectors, so it can talk to services Meta hasn't built yet.
Meta's pitch is time. The launch post quotes Tom Mulholland, who runs Mulholland Grocery in Malvern, Iowa, saying he works about 65 hours a week and needs to spend them cutting steaks and making sausages, not doing every other job a business owner inherits. Fair. That is exactly the itch this scratches.
Pricing is simple on paper. Meta says Muse is free for most of what people need, with subscription plans for those who want more. Availability is the US and Canada only, adults 18 and over.
Meta's own security post describes the recipe for a hijack
The interesting document is not the launch post. It is Meta's How We Built Safety Into Muse, published September 8 and linked from the small-business page.
In it, Meta cites Simon Willison's "lethal trifecta": an agent that has access to your private data, is exposed to untrusted content, and can communicate externally can be tricked by an attacker into sending that data out. Meta says the problem has been an obsession for its team, and it built layers against it.
Now count what a normal small business gives Muse.
Private data: QuickBooks, Stripe, customer records. Untrusted content: every inbound customer email, contact-form message, and review is text written by a stranger. External communication: Slack, Klaviyo, email, your ad account, and a browser that can visit sites.
You do not need to be unlucky to hit all three. You just need to connect the tools on the launch list.
— Meta, How We Built Safety Into Muse, September 8, 2026No matter how strong the model is at the core, any agent like this will still make mistakes, and it will sometimes be attacked via the data it reads.
Credit where it is due. Meta's design assumes that attack will happen. The agent runs in an isolated cell and never sees your real credentials, and a separate component called Sentinel is the only thing that can approve a connector action or outbound network request. Meta is also paying up to $300,000 through an open bug bounty. That is a serious effort, and better than most vendors publish.
It is still an effort, not a guarantee. Meta's own conclusion says prompt injection remains an open problem in the industry. Our earlier piece on why prompt injection is still the number one AI risk explains why: the risk moved from tricking a chatbot to hijacking an agent that has tools.
Approvals come in five sizes and one never expires
Meta's headline promise is that nothing publishes, sends, or spends without your approval. The Muse for Small Business page adds an audit trail of what the agent has done and plans to do, and says you can undo actions.
The security post is more precise, and the precision matters. Approvals are bound to a specific connector, destination, and use case. Muse can ask for permission that is one-time, session-scoped, task-scoped, time-bounded, or perpetual. Sentinel decides which options to show you.
Two details deserve a second read.
First, Meta says the goal is not to ask about everything. Read-only, previously allowed, or demonstrably low-risk actions can proceed without interruption. So reading your QuickBooks does not trigger a prompt. Anything you approved before does not either.
Second, "perpetual" exists. Tick it once for "reply to customers" and the gate you were told about becomes a gate you opened permanently on a busy Tuesday.
Purchases get tighter treatment. Per the security post, Muse asks for approval on every purchase, and its wallet uses a single-use card number via Stripe Link, tied to one merchant, one amount, and a short window. Sensible. That covers what Muse buys, not what it says to your customers.
Where your customer data goes
A connector is a data decision, not just a convenience. Here is what Meta says, in its own words, about where things land:
Your Muse lives in a dedicated cloud VM that holds your files, memory, and connector credentials. You can inspect, edit, and download those files. Meta says it does not share your conversations or VM data with its ad systems, with one caveat: when Muse browses, it looks like your activity, so a purchase on a designer's site can influence the ads you see on Instagram.
Training is the part to read carefully. Meta says sanitized conversation trajectories can be used to train the model, and you can opt out with a switch in Muse settings. If you connect customer records, that switch is worth flipping before the first task, not after.
Access is the last one. Meta restricts its staff's access to your data through operational policies but says that does not prevent access when necessary to support, secure, or operate the service. A Confidential VM mode that would cryptographically block Meta is promised for later this year. It is not here yet.
If your business handles client files or regulated data, put that against the habit we flagged in your team pasting client data into ChatGPT. The tool is different and the exposure question is identical.
What we'd connect first and what we'd keep apart
This is our opinion, not Meta's. When we scope agent access for clients, the rule is to break the trifecta on purpose instead of hoping the guardrails hold.
Start read-only, one system at a time. Connect analytics and ad accounts first. Ask Muse for the growth plan, the ad audit, the "what needs my attention" summary. All of it is drafting and analysis, which is where these agents earn their keep.
Keep the untrusted inbox away from the money tools. The account that reads inbound customer messages should not also be the account with QuickBooks and Stripe. Separate contexts mean a poisoned email has nothing valuable in reach.
Refuse perpetual grants on anything customer-facing. One-time and task-scoped approvals cost you a tap. That tap is the whole safety system.
Read the audit trail weekly for the first month. If you would not have approved something in the log, tighten the scope before you widen it.
Check the cross-vendor overlap. Shopify is on Muse's connector list, and stores were already auto-enrolled into Muse's agentic checkout earlier this month. Muse buying from stores and Muse connected to your store are two different exposures. Audit both.
The same pattern is everywhere now. When Google turned on third-party connectors in Gemini, the useful move was a permission audit before anyone touched a prompt. Muse is the same lesson with a bigger surface.
When a scoped build beats a free agent
Muse is free for most of what people need, and for one person with a light stack it is a fine experiment. Run it on analytics and ad reporting for a month and see what you learn.
It gets harder when the work touches money and customers on a schedule. A free agent waits for you to open the app and hand it a goal. A wired workflow runs when the trigger fires, with approvals designed around your business instead of a general-purpose default.
That is the build we do: workflow automation where the invoice reminder, the review request, or the lead follow-up runs on rails, drafts land in front of a person before anything goes out, and every action leaves a log. You can use Muse for thinking and let us wire the parts that must not improvise.
Three more from the log.

Connecticut AI Law: What Starts Oct 1 for Small Business
Headlines say Connecticut's AI law hits chatbots on October 1. The text says January 2027. Here's what actually starts, and what your business owes.
Sep 21, 2026 · 7 min
Does TRAIGA (Texas's AI Law) Cover Your Business?
Texas's AG just switched on the AI complaint portal. Here's what TRAIGA requires from a small business, and the two places most coverage gets it wrong.
Sep 16, 2026 · 6 min
California Just Redrew the Rules for AI at Work
Newsom signed the first state AI audit law on Sept 9. Two more bills, including a ban on robot firings, sit on his desk. Here's what changes.
Sep 11, 2026 · 6 min