Skip to content
§AI

Copilot will find everything your permissions allow

AI assistants do not create new access to your data. They make existing access easy to use. Why an AI rollout is a permissions project first, and the order of work that makes it safe.

Published 15 September 2026

The first surprise in most AI rollouts is not a hallucination. It is an employee asking an assistant a harmless question and getting back a salary spreadsheet, a board paper or a client contract they were never meant to see. Nothing was hacked. The file was already shared with them. They simply never knew it existed.

Microsoft 365 Copilot works inside the permissions a user already has. Gemini in Google Workspace does the same with Drive sharing, and the connectors that let ChatGPT or Claude search company files act with the access of the person asking. That is the correct design. It also means an AI assistant is the most efficient search tool ever pointed at your oversharing.

Where oversharing hides

  • Sharing links set to anyone in the organisation, created years ago for a single meeting and never removed.
  • Teams and Microsoft 365 groups created as public by default, with document libraries everyone can read.
  • SharePoint sites where permission inheritance was broken once for a folder and nobody remembers why.
  • Former project members, contractors and shared mailboxes that still hold access.
  • HR, finance and legal files saved into general team spaces because that was where the person was working.

None of this is new. What changes is discoverability. A file buried four folders deep was protected by obscurity. An assistant that reads everything a user can read removes the obscurity.

The order to work in

  1. 01Inventory the sensitive content. Decide which libraries, sites and drives hold HR, finance, legal and client data, and who should genuinely see each one.
  2. 02Run the sharing reports. Microsoft 365 and Google Workspace both report on broadly shared sites and files. Start with organisation-wide links and public groups.
  3. 03Fix access at the site or library level. Remove broad links, close public groups that should be private, and restore inheritance where it was broken without a reason.
  4. 04Label what matters. Sensitivity labels in Microsoft Purview, or the Workspace equivalent, let you restrict how the most sensitive content is used, including by AI.
  5. 05Pilot with a small group whose access you have reviewed, and ask them to look for things they should not find.
  6. 06Roll out in waves, with a usage policy, training and a named owner for access reviews.

Choosing the right plan matters as much

Staff using personal accounts on consumer AI tools are the other half of the risk. The business and enterprise plans of ChatGPT, Claude, Gemini and Copilot add single sign-on, admin controls, retention settings and contractual data terms, and by default they do not train models on your content. Moving people onto a managed plan, and making it the easy option, removes most of the reason to use a personal one.

Making it stick

Permissions drift back the moment the project ends unless someone owns them. Three habits keep an AI rollout safe after launch: quarterly access reviews for sensitive sites, a default of private for new teams and groups, and a simple route for staff to report anything an assistant showed them that it should not have.

AI does not change who can see your data. It changes how quickly they find it.

This is why we treat every AI rollout as an infrastructure project first: identity, permissions and data governance are fixed before the assistant is switched on.

Talk to an Engineer

Tell us what you run today and what needs to happen next. A senior engineer reviews it and comes back with a clear recommendation.

Keep reading