For fifteen years, SharePoint oversharing had a strange property: it was mostly harmless in practice, because nobody could find anything. The permissions were too broad, but discovery was hard, so the finance folder shared with "Everyone" sat unread. Then organisations started rolling out AI assistants — and discovery stopped being hard.
The assistant is only as discreet as your ACLs
Microsoft 365 Copilot answers from whatever the signed-in user's permissions allow it to read. That is the correct security model — the AI respects the ACLs. But it means the question "what can this user access?" is no longer theoretical. Before AI, an over-broad grant required someone to go looking. Now a prompt as innocent as "summarise our salary bands" will cheerfully use the spreadsheet nobody remembered was shared org-wide.
Nothing leaked, in the breach sense. The permissions did exactly what they always said. What changed is that permissions became answers.
Microsoft's own prescription proves the point
Microsoft's Copilot-readiness guidance leans heavily on permission hygiene, and its tooling for it — the Data Access Governance reports in the SharePoint admin center — sits behind the SharePoint Advanced Management add-on (included with Copilot licences). The message underneath the licensing is worth taking seriously: fix who-can-access-what before you point an AI at it. We've written about what to do when you don't have that licence.
External sharing is the sharpest subset
Internal oversharing embarrasses you in a meeting. External oversharing is a different category: anonymous "Anyone" links, guest grants that outlived their project, folders whose guest access quietly extends to everything beneath them. AI rollouts have a way of forcing the whole permissions conversation at once — and the external slice is the part with regulatory weight behind it (GDPR Article 32 asks exactly this question).
A sane sequence
- Inventory external exposure first. It's the highest-risk slice and the most tractable one — see the complete how-to.
- Review causes, not rows. One folder grant explains hundreds of exposed files; work the grant.
- Make it a cadence, not a project. Sharing state drifts weekly; a one-time cleanup before the AI pilot is stale by the production rollout.
This is the job TRACER365 was built for: the external who-can-access-what, scanned read-only, de-duplicated to the findings that need a decision, on a schedule. It doesn't audit Copilot — it makes sure that what any assistant can reach is what you decided it should.