ENGINEERING · SECURITY

Why permission cleanups regress

Sprawl regrows within months because the behaviour that created it is still there. What makes a clean-up hold.

10 July 2026·6 min read·By Agile Labs

Why does it come back?

Because a clean-up removes the accumulation and leaves the mechanism. The reasons people over-share are unchanged the day after the audit closes: a default that grants broadly, a sharing link with no expiry, a site created without an owner, a deadline that makes the wide permission the fast one.

Published guidance and field experience put the regrowth window at roughly six months in a typical tenancy. The organisation has spent months of effort and buys about two quarters of improvement.

What the clean-up is actually fighting

Three habits, none of which is unreasonable in the moment.

Broad grants to unblock work. Sharing with the whole organisation is one click; working out the right group is twenty minutes and a conversation.

Links that outlive their purpose. A link created for external review in March still resolves in November because nothing expires by default.

Sites without owners. Somebody creates a space for a project, the project ends, the space keeps its permissions and its content, and nobody is accountable for either.

“A clean-up removes the accumulation and leaves the mechanism.”

— on why permission sprawl regrows

What order should the work happen in?

Containment before correction, because the grind takes months and the exposure should not stay open for all of them.

Run the data risk assessment first, so the work is directed at where sensitive content actually sits rather than at whatever is alphabetically first. Then restrict access on the worst sites and remediate overshared links in bulk. Those steps take days and remove most of the immediate exposure.

Only then does the permissions work proper begin, site by site, with sensitivity labels and data-loss policies wired to them so that new content is classified as it arrives rather than audited later.

What makes it hold afterwards

DefaultsNew sites and links start narrow. The wide option requires a decision.
ExpirySharing links expire. Renewal is deliberate rather than automatic.
OwnershipEvery site has a named owner who attests to its access on a cadence.
ReviewA standing monthly pass on the highest-risk content, not an annual audit.
Fig. 01 — None of these is technically difficult. All of them are organisational commitments, which is why they are the part that gets dropped.

Why an assistant rollout is the moment this gets funded

The permissions have been wrong for years and nobody paid to fix them, because the consequence was theoretical. An assistant makes the consequence immediate and visible to executives, which is the first time the work has a sponsor.

That is worth using rather than resenting. The clean-up is not AI work; it is information governance that AI made urgent. Framing it that way also sets the right expectation about duration, because a sponsor who thinks they are buying an AI configuration will not fund six months of permissions work.

What we do and do not take on

We run the assessment, do the containment, and build the controls, using the tooling the client’s own licences already include rather than introducing another product. The standing governance cadence is theirs to own, and we say so at the start — a supplier who quietly becomes the permanent owner of a client’s permissions has created a dependency rather than a capability.

Article

Published 18 August 2026

By Agile Labs

Agile Labs is a Singapore enterprise software engineering company. We design, build and secure enterprise software and AI systems.

Sources

  1. Microsoft, oversharing blueprint and SharePoint Advanced Management guidance, 2025–2026.
  2. Microsoft, Restricted Access Control and data risk assessment documentation.
  3. Agile Labs Secure AI Engineering delivery protocol, September 2026.

Related articles

View all insights

Have something complex to build, fix or take over?

Build better software, with zero surprises