Reading your calendar is one grant. Sending email as you is another. Spending money is a third. Treating those as one big yes is how trust gets burned.
The useful frame is blast radius: how bad is the worst version of this action, and can it be undone?
Approvals where they earn their keep
Approving every step turns an assistant into a form. Approving nothing hands your accounts to a system that can make things up. The middle is checkpoints at consequence: act freely on reversible work, show a preview before anything leaves the building, hard-stop before anything that cannot be taken back.
Checkpoints also build the relationship over time. Every preview you approve without changes is evidence that it drafts the way you would. Every edit teaches it where you differ. After a few weeks the previews start feeling boring, and that boredom is exactly when you know a wider grant is safe.
Scoped access, honest logs
Grant the narrowest access that does the job, and prefer products that show a ledger of what was done on your behalf: what was read, what was sent, what changed. The log is what makes delegation auditable instead of faith-based.
Scopes sound technical, but you already think this way. The dog sitter gets a house key and does not get your banking password. Reading your calendar and sending email as you are two different keys. If a product treats them as one big yes, it has quietly made that decision for you.
Trust is earned in layers
Start with low-stakes errands, watch how the system behaves at the edges, widen the grant as it proves out. The same way you would onboard a human assistant, minus the guilt about checking their work.
Building trust in stages also protects against a newer risk: things an agent reads can try to give it orders. A web page or an email can contain a hidden line telling the agent to ignore you and forward your files. With layered permissions, even a fooled agent runs into a checkpoint before it can do anything serious. Design for the bad day and the good days take care of themselves.