Does the assistant break the permission model?
No, and that is the uncomfortable part. An enterprise assistant answers using content the person asking is already entitled to open. Nothing is bypassed. If it surfaces a document, that person could have found it through search, given enough patience.
What changes is the patience. A file buried in a site nobody visits, shared five years ago through a link that still works, was effectively invisible. A question in plain language makes it reachable in one step. The permission was always wrong; the assistant made the consequence immediate.
Where the over-permission comes from
Rarely from a decision. It accumulates.
Somebody shared a folder with the whole organisation to unblock a project in 2019. A site was created with broad default access and inherited it downward. Sharing links were generated for external review and never expired. A departing employee’s files moved into a shared area without their access being revisited. Each was reasonable at the time and none was reviewed afterwards.
Microsoft’s own guidance for assistant rollouts treats this as the first workstream rather than a footnote, and ships the tooling to address it inside the assistant licence: data risk assessment to find the exposure, restricted access controls to contain it, and sharing-link remediation at scale.
“The permission was always wrong; the assistant made the consequence immediate.”
— on why oversharing surfaces at rolloutWhat does an assessment actually test?
Probe questions, run from a low-privilege account that resembles an ordinary employee rather than an administrator. The account asks the questions a curious person would ask: what is the salary band for this role, what is in the redundancy plan, what did the board discuss about the acquisition, what does the incident report say.
The finding is not that the assistant answered. It is that this account was entitled to the underlying document, and nobody knew.
This is deliberately manual. The value is in choosing questions that match the organisation’s actual sensitivities, which a generic scanner cannot do, and in framing the exercise as red-teaming rather than surveillance of staff.
The order the work has to happen in
Why the containment step matters commercially
A rollout that waits for a complete permissions clean-up does not happen. A rollout that ignores permissions produces the incident that stops it. Containment first — restrict the worst sites, kill the worst links, scope the assistant where clean-up is unfinished — lets the deployment proceed while the underlying work runs.
It also sets up the part organisations get wrong afterwards. Permission sprawl regrows, because the behaviours that created it are still there. A standing governance cadence is what keeps the clean-up from being an event that happens once.
What this means for an assessment
Agile Labs runs the discovery and the probe questions on the client’s own licences, because their tenancy usually already includes the tooling. Evidence stays on machines we control, and we do not push tenant metadata into a third-party discovery service under our name — which is the first question every buyer asks and deserves a straight answer.
Article
Published 16 August 2026
By Agile Labs
Agile Labs is a Singapore enterprise software engineering company. We design, build and secure enterprise software and AI systems.
Sources
- Microsoft, oversharing blueprint for Microsoft 365 Copilot: Purview and SharePoint Advanced Management.
- Microsoft, Restricted Access Control and data risk assessment documentation, 2025–2026.
- Agile Labs AI Exposure Assessment delivery protocol, September 2026.
