ENGINEERING · AI SECURITY

What an approved assistant can see

An assistant inherits the permissions of the person using it. That is the design, and it is why a decade of file sharing becomes searchable overnight.

9 August 2026·7 min read·By Agile Labs

Does the assistant break the permission model?

No, and that is the uncomfortable part. An enterprise assistant answers using content the person asking is already entitled to open. Nothing is bypassed. If it surfaces a document, that person could have found it through search, given enough patience.

What changes is the patience. A file buried in a site nobody visits, shared five years ago through a link that still works, was effectively invisible. A question in plain language makes it reachable in one step. The permission was always wrong; the assistant made the consequence immediate.

Where the over-permission comes from

Rarely from a decision. It accumulates.

Somebody shared a folder with the whole organisation to unblock a project in 2019. A site was created with broad default access and inherited it downward. Sharing links were generated for external review and never expired. A departing employee’s files moved into a shared area without their access being revisited. Each was reasonable at the time and none was reviewed afterwards.

Microsoft’s own guidance for assistant rollouts treats this as the first workstream rather than a footnote, and ships the tooling to address it inside the assistant licence: data risk assessment to find the exposure, restricted access controls to contain it, and sharing-link remediation at scale.

“The permission was always wrong; the assistant made the consequence immediate.”

— on why oversharing surfaces at rollout

What does an assessment actually test?

Probe questions, run from a low-privilege account that resembles an ordinary employee rather than an administrator. The account asks the questions a curious person would ask: what is the salary band for this role, what is in the redundancy plan, what did the board discuss about the acquisition, what does the incident report say.

The finding is not that the assistant answered. It is that this account was entitled to the underlying document, and nobody knew.

This is deliberately manual. The value is in choosing questions that match the organisation’s actual sensitivities, which a generic scanner cannot do, and in framing the exercise as red-teaming rather than surveillance of staff.

The order the work has to happen in

1. AssessData risk assessment across the tenancy. Where is sensitive content, and who can reach it.
2. ContainRestricted access on the riskiest sites, and bulk remediation of overshared links. Days, not months.
3. Label and enforceSensitivity labels on the content that matters, with data-loss policies wired to them.
4. GrindThe permissions themselves, site by site, with a governance cadence so it does not regrow.
Fig. 01 — Containment comes before correction. The permissions work takes months, and the exposure should not stay open for all of them.

Why the containment step matters commercially

A rollout that waits for a complete permissions clean-up does not happen. A rollout that ignores permissions produces the incident that stops it. Containment first — restrict the worst sites, kill the worst links, scope the assistant where clean-up is unfinished — lets the deployment proceed while the underlying work runs.

It also sets up the part organisations get wrong afterwards. Permission sprawl regrows, because the behaviours that created it are still there. A standing governance cadence is what keeps the clean-up from being an event that happens once.

What this means for an assessment

Agile Labs runs the discovery and the probe questions on the client’s own licences, because their tenancy usually already includes the tooling. Evidence stays on machines we control, and we do not push tenant metadata into a third-party discovery service under our name — which is the first question every buyer asks and deserves a straight answer.

Article

Published 16 August 2026

By Agile Labs

Agile Labs is a Singapore enterprise software engineering company. We design, build and secure enterprise software and AI systems.

Sources

  1. Microsoft, oversharing blueprint for Microsoft 365 Copilot: Purview and SharePoint Advanced Management.
  2. Microsoft, Restricted Access Control and data risk assessment documentation, 2025–2026.
  3. Agile Labs AI Exposure Assessment delivery protocol, September 2026.

Related articles

View all insights

Have something complex to build, fix or take over?

Build better software, with zero surprises