Why does it come back?
Because a clean-up removes the accumulation and leaves the mechanism. The reasons people over-share are unchanged the day after the audit closes: a default that grants broadly, a sharing link with no expiry, a site created without an owner, a deadline that makes the wide permission the fast one.
Published guidance and field experience put the regrowth window at roughly six months in a typical tenancy. The organisation has spent months of effort and buys about two quarters of improvement.
What the clean-up is actually fighting
Three habits, none of which is unreasonable in the moment.
Broad grants to unblock work. Sharing with the whole organisation is one click; working out the right group is twenty minutes and a conversation.
Links that outlive their purpose. A link created for external review in March still resolves in November because nothing expires by default.
Sites without owners. Somebody creates a space for a project, the project ends, the space keeps its permissions and its content, and nobody is accountable for either.
“A clean-up removes the accumulation and leaves the mechanism.”
— on why permission sprawl regrowsWhat order should the work happen in?
Containment before correction, because the grind takes months and the exposure should not stay open for all of them.
Run the data risk assessment first, so the work is directed at where sensitive content actually sits rather than at whatever is alphabetically first. Then restrict access on the worst sites and remediate overshared links in bulk. Those steps take days and remove most of the immediate exposure.
Only then does the permissions work proper begin, site by site, with sensitivity labels and data-loss policies wired to them so that new content is classified as it arrives rather than audited later.
What makes it hold afterwards
Why an assistant rollout is the moment this gets funded
The permissions have been wrong for years and nobody paid to fix them, because the consequence was theoretical. An assistant makes the consequence immediate and visible to executives, which is the first time the work has a sponsor.
That is worth using rather than resenting. The clean-up is not AI work; it is information governance that AI made urgent. Framing it that way also sets the right expectation about duration, because a sponsor who thinks they are buying an AI configuration will not fund six months of permissions work.
What we do and do not take on
We run the assessment, do the containment, and build the controls, using the tooling the client’s own licences already include rather than introducing another product. The standing governance cadence is theirs to own, and we say so at the start — a supplier who quietly becomes the permanent owner of a client’s permissions has created a dependency rather than a capability.
Article
Published 18 August 2026
By Agile Labs
Agile Labs is a Singapore enterprise software engineering company. We design, build and secure enterprise software and AI systems.
Sources
- Microsoft, oversharing blueprint and SharePoint Advanced Management guidance, 2025–2026.
- Microsoft, Restricted Access Control and data risk assessment documentation.
- Agile Labs Secure AI Engineering delivery protocol, September 2026.
