Control over AI
Blog
AI data leakage 8 min read

What happens when Copilot can reach SharePoint?

Over-broad permissions were harmless for years because nobody could find anything. An assistant that searches well changes that in a single query.

Admin reviewing permissions across SharePoint sites
Quick answer

Copilot does not break permissions. It searches with exactly the permissions the user already held, and that is the problem. Most tenants contain sites and folders open to everyone in the organisation, usually by accident and usually years ago. While searching took effort, those documents were protected by being unfindable. An assistant that searches the whole workspace semantically and summarises makes them reachable in one sentence. Microsoft places remediating oversharing first in its own deployment guidance, ahead of handing out licences.

01

Copilot inherits user permissions and violates none of them

02

Unfindability was the real control, and it disappears

03

Pay data, restructuring papers and board minutes surface most often

04

Microsoft puts permission remediation before rollout in its own guidance

05

This is an authorisation project wearing an AI badge

Someone asks Copilot to summarise what is known about last year's restructuring. The answer is tidy, properly cited, and includes a passage from a set of minutes naming them and three colleagues alongside figures.

Nothing was breached. The site holding those minutes was opened to everyone in the organisation once, because something needed sharing quickly. That was in 2023 and nobody reversed it.

Copilot breaks no permissions

Establish this first, because everything else follows from it. Copilot searches with the permissions of the user asking. What you cannot open does not appear in your answer.

That sounds reassuring and it is the core of the problem. The question shifts from "can the assistant see too much" to "should this person have been able to see this already". And in most organisations that second question has been answered for years with "probably not, but it never mattered".

Unfindability was the control

This is the mechanism, and it is worth stating precisely.

A large SharePoint tenant holds tens of thousands of documents. Some fraction sits too open: a site set to "everyone in the organisation" once, a folder that came across in a migration, a sharing link that never expired.

While you had to know where something was to find it, nothing happened. Search worked on keywords and rarely returned anything useful. In practice that was a security layer: never designed, entirely effective.

An assistant works differently. It searches by meaning, so you do not need the right words. It searches everywhere at once. And it summarises, so you do not even have to open the document to learn what is in it.

What changes is not access. What changes is effort. And if effort was your only control, you did not have one.

What surfaces

The categories are strikingly consistent across organisations:

  • Pay and performance documents, often as an HR system export parked somewhere "for now"
  • Restructuring and redundancy material, usually in a project site nobody cleaned up
  • Board and leadership team minutes
  • Contracts with unusual terms the rest of the business is not meant to know about
  • Personal data in attachments to old tickets and requests

What they share: they are sensitive for good reasons, and nobody deliberately opened any of them up.

What Microsoft says about it

None of this surprises the vendor. Microsoft describes remediating oversharing as the first of three pillars in its own deployment guidance, ahead of setting up guardrails and ahead of meeting AI regulatory requirements.

The recommended sequence amounts to: identify the most-used sites, run a permission state report, start access reviews on the sites that are overshared, and apply restricted access control to business-critical sites. Licences after that.

In practice it usually runs the other way round, because the licences arrived first and the cleanup is a project measured in months.

Why this is not an AI project

Perhaps the most useful conclusion is that none of this work is about AI. Permission cleanup was always necessary. It was simply never urgent.

What the assistant does is present the bill. That is unwelcome and it is also useful: there has rarely been a better week to get an access review funded than the one in which somebody stumbled into their manager's compensation letter.

The same pattern applies to any assistant searching your own sources, see what is RAG and how AI tools reach files you never uploaded.

And a second track runs alongside this project. Cleaning up permissions governs what the assistant can find inside your tenant. It says nothing about what someone pastes into a chat window from an email, a PDF, or a system that was never in SharePoint at all. Those two run in parallel, and only the first one can ever be finished.

FAQ

Common questions

Can Copilot reach documents I have no permission for?

No. Copilot searches with your permissions and surfaces nothing you could not have opened yourself. That is precisely where the exposure comes from: the question is not whether it breaks permissions, but whether your permissions were ever right.

Why is this a problem now?

Because findability used to be the brake. A document in a forgotten site with loose permissions was effectively unreachable because nobody would search for it. An assistant that searches by meaning and summarises does reach it.

What actually surfaces in practice?

The same categories across organisations: pay and performance documents, restructuring and redundancy papers, board and leadership minutes, contracts with unusual terms, and old exports from HR or finance systems parked somewhere temporarily.

What should we do before rolling out Copilot?

Remediate permissions. Microsoft describes this as the first step: map the most-used sites, run a permission state report, run access reviews on oversharing sites, and apply restricted access control to business-critical sites before licences go out.

Is this only a Microsoft problem?

No. Every assistant that searches your own sources has this pattern: Google Workspace, Slack, Notion, or an in-house search product. Microsoft is the clearest example because so many documents live in SharePoint and the integration runs deep by default.