Microsoft has confirmed that its enterprise assistant becomes generally available on 1 November, at thirty dollars per user per month with a minimum commitment of three hundred seats. Google's equivalent for its workspace suite reached general availability at the end of August at a similar price. The pilots are over; the purchase orders are being drafted. And in almost every organisation now running a pilot, the finding is the same, and it has nothing to do with the quality of the model. The assistant works. It is the file estate underneath it that does not.
For twenty years, bad search was a security control. Nobody planned it that way, and nobody budgeted for its replacement
The vendors are accurate when they say the assistant respects existing permissions. It does. It will not show a user anything they could not already open. That is precisely the problem, because what a user could already open and what a user could realistically find have never been the same thing. Enterprise search was bad enough that over-permissioned content stayed effectively private. Nobody stumbled onto the redundancy planning spreadsheet in a subsite of a subsite, because finding it required knowing it existed and guessing what it was called. Retrieval that understands intent removes that gap in a single step. The question "what are we paying the regional directors" now gets answered from wherever the answer happens to sit, provided the asker has technical access. Obscurity was doing real work, and it has stopped.
Where the over-permissioning came from
None of this was carelessness, exactly. It accumulated. Link sharing defaults. A decade of people clicking share and accepting whatever scope was preselected, frequently anyone in the organisation, occasionally anyone with the link. Convenience groups. A broad organisation-wide group added to a site once, for a genuine reason, in 2019, and never removed. The migration. Flat network shares lifted into a collaboration platform with permissions approximated rather than rebuilt, because rebuilding them would have delayed the project by two quarters. Departures. Personal drives and individually shared items belonging to people who left, still accessible, still indexed, still containing the last thing they were working on. Self-service sprawl. Anyone can create a team, so thousands exist, most without an owner who understands what was granted.
The numbers to put in front of a steering committee
This is measurable, which makes it fundable. Before deployment, count: items accessible to organisation-wide groups; sites with broken permission inheritance; active external sharing links with no expiry; guest accounts that have not been used in ninety days; and files containing payroll data, identity documents or bank details sitting outside their proper location. Every one of those has a number today and a target for the deployment date. That converts an open-ended governance ambition into an eight to twelve week programme with a finish line, which is the only form in which this work ever gets done.
Design the pilot to find the problem, not to prove the value
Most pilots are staffed with enthusiastic volunteers asked to report productivity gains. That answers a question you already know the answer to. The useful pilot is twenty people drawn from human resources, finance, legal and the executive office, given the tool and asked to spend an afternoon trying to surface things they should not see. Two hours of that will produce a remediation backlog and a board-ready business case, and it costs nothing. Run it before the licences are counted, not after.
Sequence the remediation by yield
Sensitivity labelling and automated classification are the right long-term answer and the wrong place to start, because they require a taxonomy, an application campaign and a tolerance for false positives. The fast wins are duller. Expire existing sharing links and set a default expiry for new ones. Remove organisation-wide groups from sites holding regulated or personal data. Run an access review on the fifty most sensitive sites with named owners signing off. Disable or reassign departed users' storage. Sweep for identity documents and payroll workbooks outside approved locations and move them. That sequence delivers most of the risk reduction in the first month, and it does not depend on anyone agreeing a classification scheme.
Expire sharing links
Expire existing links and set a default expiry for new ones.
Remove broad access
Remove organisation-wide groups from sites holding regulated or personal data.
Review sensitive sites
Have named owners sign off on access to the most sensitive sites.
Resolve departed-user storage
Disable or reassign storage belonging to departed users.
Relocate exposed records
Find identity documents and payroll workbooks outside approved locations and move them.
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
Scope the rollout by population
The most common mistake is treating this as all-or-nothing. It is not. Deploy first to populations whose content is low-sensitivity — operations, engineering, sales — and hold human resources, finance, legal and the executive office until their areas are remediated. You get the productivity benefit on schedule and you keep the exposure away from the content that would generate an incident.
Practical Guidance for AI Permissions Readiness Review
- Baseline five oversharing metrics before signing the licence agreement.
- Run an adversarial pilot with HR, finance, legal and the executive office.
- Expire existing share links and default new ones to expire.
- Strip organisation-wide groups from sensitive sites.
- Review and expire dormant guest accounts.
- Sweep for identity documents and payroll files outside approved locations.
- Name an accountable owner for every site holding regulated data.
- Stage the rollout by population, not by department enthusiasm.
The Regional Angle
Three categories of content make this materially riskier for organisations here than the international guidance suggests. The first is people data, which in this region is both unusually sensitive and unusually badly stored. Compensation is individually negotiated, varies widely between people doing similar jobs, and correlates with nationality in ways that are commonplace in practice and explosive in disclosure. Alongside the salary workbooks sit passport scans, visa pages, identity card copies, medical insurance schedules, offer letters and end-of-service calculations — material that accumulates in email attachments, in a public relations officer's shared folder, and in whatever site the human resources coordinator created in 2021. A single assistant query about pay bands, answered from a stray workbook, is an internal crisis that no communications plan recovers from quickly. Run the sweep for identity documents and payroll files first, before anything else on the list, because in most regional organisations it returns results immediately and it makes the business case without further argument. The second is the family and shareholder layer that sits inside the same tenant as the operating business. In owner-led and family-owned groups, the chairman's office, the board secretariat and the family's private affairs frequently share infrastructure with the trading companies: shareholding structures, succession documents, related-party arrangements, personal investments and board papers, often in sites created informally by an executive assistant. Standard access reviews never reach these because nobody wants to ask the question. An assistant deployed tenant-wide does not share that reticence. Isolate this content before deployment, with its own access model and ideally its own boundary, and treat it as a separate decision taken by the principal rather than as part of an IT programme. The third is the guest population, which in regional structures is larger and older than anyone expects. Outsourced accounting firms, external auditors, corporate service providers, free zone agents, public relations officers, legal advisers and joint venture partners routinely hold guest accounts in the tenant, created for a specific engagement years ago and never revoked because nobody owns the list. Each one is an external party with standing access to whatever was shared with them and whatever inherited from it. Before enabling an assistant, establish who those guests are, whether their engagement is still live, and critically whether any of them are licensed for the assistant themselves — an external accountant with a licensed account and semantic retrieval over your finance site is a scenario worth thinking about carefully before it exists.
The objection worth taking seriously
The strongest objection is that this is opportunism. Security teams have wanted a permissions cleanup for a decade, could never get it funded, and have now found a launch to attach it to. The technical argument is also weaker than it sounds: the assistant genuinely cannot show anyone anything they were not already entitled to open, so nothing has actually been made less secure. Meanwhile, holding the deployment while a governance programme runs costs measurable productivity and hands the advantage to competitors who simply switched it on. The funding-grab observation is fair, and worth conceding plainly. This work should have been done years ago and the launch is being used as leverage. That does not make it the wrong work. The technical argument is where the objection fails, because confidentiality in practice has always been the product of permission and discoverability together. A document that fifteen thousand people can technically open but nobody can locate is functionally confidential; the same document surfaced on request is not. Nothing about the permission model changed, and everything about the outcome did. The right conclusion is not to delay the deployment but to stage it: the populations whose content is already appropriate can start in November, and the ones holding payroll, board papers and legal files can start when their five numbers look different. That gets you the productivity and avoids the incident, which is the only version of this argument that both sides can sign.
Common Questions
Can we restrict which sites the assistant can see?
Controls of that kind are limited today and vary by platform. Plan on the assumption that the assistant sees what the user sees, and fix the permissions rather than waiting for a scoping feature.
How long does remediation take?
Eight to twelve weeks for the high-yield items in a mid-sized estate. A full classification and labelling programme takes far longer and is not a prerequisite for deployment.
Do sensitivity labels solve this?
Only where they have been applied, which in most organisations is a small fraction of content. They are the destination, not the first step.
What should we expect over the next twelve months?
Expect the platform vendors to ship tenant-level controls that restrict which content an assistant can index, because every large customer is currently asking for exactly that. Expect oversharing assessment to become a distinct product category and a lucrative consulting line, with tooling that mostly reports numbers you could count yourself. Expect at least one prominent incident in which an assistant surfaces a compensation list or a restructuring plan to the wrong audience, and expect it to do more for access governance than a decade of audit findings. And expect the seat minimums and pricing to loosen during the year as competition arrives, which is an argument for spending this quarter on remediation rather than on procurement.
AI Permissions Readiness Review — we baseline the five numbers that decide whether your assistant is a productivity tool or a disclosure engine, and we run the pilot designed to find what it should not.
