Key takeaways
- Connected AI does not break your permissions. It reveals that they were already broken.
- Run a sharing and permissions review before you connect anything to a shared document store.
- Connect in order of blast radius: calendar, then personal mailbox, then team sites, then the whole store.
- The built-in versus standalone question is a real decision, not a formality, and most firms end up with both.
There is a specific incident that happens in organisations shortly after connecting an AI assistant to their document store, and it is worth describing because it is entirely predictable and entirely preventable. An employee asks a reasonable question. The assistant answers it accurately, using a document that employee should never have been able to open. Nobody did anything wrong. The file had been shared broadly three years earlier by someone who has since left, and until now nothing was good enough at searching to find it.
That is the whole problem in one paragraph, and it is a permissions problem wearing an AI costume.
What connecting actually does
When you connect an assistant to Microsoft 365 or Google Workspace, you are granting it the ability to retrieve content on behalf of a user, within that user's existing access rights. It does not get privileged access. It does not read things the person could not read. It cannot see a file that is properly restricted.
What it does is remove the friction that was doing your security work for you. In most organisations, over-shared content has been safe in practice because finding it required knowing it existed, knowing roughly where it was, and being motivated enough to look. A good retrieval system removes all three requirements. Someone asks a plain question and gets the answer, drawn from wherever the answer happens to live.
So the honest framing for a leadership conversation is not that AI creates a new risk. It is that AI ends a period during which poor search was concealing an old one.
The sentences that surface the problem in a meeting: ask what would happen if every employee could instantly search every file they technically have access to. If the room gets uncomfortable, you have found the work that needs doing before connection, and you have found it for free.
The permissions review, scoped so it actually happens
A full permissions remediation across a mature tenant is a project nobody has budget for, and proposing one is the fastest way to stall the whole initiative. The version that works is narrow and targeted at the categories that actually matter.
Four things to look for, in order:
- Anything shared with everyone in the organisation. Most tenants have accumulated these. Review the list, not the whole store. This is where the compensation spreadsheet and the board pack usually turn up.
- Anonymous or link-based sharing that has no expiry. These are external exposure as well as internal, and they long predate any AI decision.
- The four categories that cause actual incidents. Payroll and compensation, human resources case files, merger and transaction material, and legal advice. Confirm these are properly restricted before anything is connected, even if you do nothing else.
- Orphaned sites and drives from departed staff. Frequently over-permissive and entirely forgotten.
Both major platforms have administrative reporting that will produce these lists. This is days of work rather than months, and it is worth doing regardless of whether you ever connect an AI tool, which is a useful thing to say to whoever has to approve the time.
Connect in order of blast radius
| Connector | Value | Risk | Prerequisite |
|---|---|---|---|
| Calendar | Meeting prep, scheduling context | Very low, scoped to the user | None |
| The user's own mailbox | High, thread summarisation and drafting | Low, they already have it | Retention position agreed |
| The user's own drive | Moderate | Low | None |
| A single team site or shared drive | High for that team | Moderate | Permissions checked for that site |
| Whole document store | Highest | High | Full sharing review completed |
| Chat and messaging history | Moderate | Moderate, informal candour | Employee communication first |
| Line of business systems | Varies | Depends entirely on the system | Own review each time |
The sequence matters more than the destination. Starting with calendar and personal mailbox gives people a genuinely useful experience within a day, generates the adoption you need, and carries almost no cross-user exposure. It also buys time to do the permissions work properly rather than under pressure.
Organisations that begin by connecting everything get one impressive demonstration and then a difficult month.
The messaging connector deserves a separate conversation. People write things in internal chat that they would never put in a document, on the reasonable assumption that it is ephemeral and unsearched. Making that corpus retrievable changes the social contract of the tool, and it is worth telling employees before rather than after.
Built-in or standalone
The other decision in this area is whether to use the assistant built into your productivity suite or a separate tool connected to it. Both are defensible and the trade-off is stable enough to state plainly.
The built-in option requires no connector work, respects your existing permissions and security model by construction, keeps data within a tenant you already have agreements for, and appears inside the applications people already use, which matters enormously for adoption. It is typically priced per seat on top of your existing licences and its general capability may lag the frontier.
The standalone option often has stronger general reasoning and writing, a lower cost of entry, and no dependency on your suite vendor's roadmap. It requires deliberate connector configuration, adds a vendor relationship, and lives outside the applications where work happens, which costs some adoption.
A large number of mid-size organisations end up running both, with the suite assistant embedded in day-to-day document and email work and a standalone tool used for heavier drafting and analysis. That is a reasonable outcome. It is only a problem when it happens by accumulation rather than by decision, because then nobody owns the total cost, the overlapping capability or the two separate retention configurations.
What to do about sensitivity labelling
If your organisation already applies sensitivity or classification labels, connected AI generally respects them and this is one of the stronger arguments for the built-in option. If you do not label, do not start a labelling programme as a prerequisite. It is a large undertaking with a poor completion rate, and the targeted permissions review described above delivers most of the protection for a fraction of the effort.
Labelling is worth doing eventually. It is not worth blocking on.
Frequently asked questions
Can AI see files our staff should not have access to?
No. It works within each user's existing rights. The issue is that in most organisations people already have access to far more than intended, and poor search was hiding it. Connected AI does not create that exposure, it makes it findable, which is why the permissions review comes first.
What should we connect first?
Calendar, then the user's own mailbox and drive. These are scoped to one person, carry almost no cross-user risk, and deliver enough day-one value to drive adoption. Shared team sites come next, and the full document store comes last, after a sharing review.
Do we need to fix all our permissions first?
Not all of them. Target four things: content shared with the entire organisation, link sharing with no expiry, the four high-consequence categories of payroll, human resources, transactions and legal advice, and orphaned sites from departed staff. That is days of work, not months, and it is worth doing regardless.
Should we use our suite's assistant or a separate one?
Built-in wins on integration, permissions inheritance and adoption. Standalone often wins on capability and cost of entry. Many organisations run both deliberately, which is fine. The failure mode is ending up with both by accident, so that nobody owns the combined cost or the two retention configurations.
Get it connected in the right order
We run the sharing review, decide what should be connected and in what sequence, configure retention and access, cap the spend, and train your people on what the connected version is actually good for. Your own team runs it afterwards. Fixed price, live in 30 days or less.