Ask your AI what it can see before your team does.

Files that were safe because nobody could find them become answers in a chat. Ask the questions you hope it cannot answer, before anyone else does.

Floor 16 · Sep 2026 · 6 min read

An AI chat answering a question with payroll and board files nobody meant to share

An employee opens the AI assistant and types a reasonable question: "What are the bonus ranges this year?" The answer comes back in seconds, with a neat summary and a link to the source. The source is a payroll spreadsheet that someone shared with the whole company four years ago, meaning to share it with one person.

Nobody hacked anything. The AI did exactly what it was built to do. It searched everything that employee was allowed to open and wrote a helpful answer. The problem was there long before the AI arrived. The AI just found it first.

Oversharing used to be harmless

Most companies have files shared more widely than anyone intended. A folder set to "Everyone" so a new hire could get in. A link with no expiry sent to a contractor years ago. An HR site that inherited the permissions of the intranet. For years this did little damage, because finding those files took effort. You had to know they existed, know where they were, and go looking.

An AI assistant removes the effort. It searches every site, library and conversation a person can reach, reads what it finds, and writes the answer in plain language. A file that was safe because nobody could find it becomes a sentence in a chat window, whether or not the employee meant to look for it.

That is why the order matters. You want to be the first person to ask the awkward questions, not the last to hear about the answers.

AI does not create a permissions problem. It finds the one you already have, and it finds it faster than any audit.

What "the boundary" means, in plain words

When we talk about setting the boundary, we mean deciding what AI can see and making sure the settings agree with the decision. It comes down to four things:

  • Permissions. Who can open what. Sites and folders shared with everyone are narrowed to the people who need them, and old sharing links are closed.
  • Sensitivity labels. A label on HR, finance, legal and client confidential content says how it is handled. Labels can be applied automatically, and with the right settings a label keeps a file out of AI answers even for people allowed to open it.
  • Sites left out. Some sites, such as board papers or a deal workspace, are excluded from AI and company-wide search altogether. The people who work in them still can.
  • Archive. Old content moves to an archive where search and AI do not look. That keeps three-year-old drafts out of today's answers, which matters almost as much as keeping secrets out.

Do it in this order

Every company that asks us how to switch on AI safely gets the same four steps, in the same order. Skipping one is how the HR folder ends up in a chat answer.

  1. Assess. Scan who can see what, what is stale, what is duplicated and what has no owner. Put numbers on it before anyone decides anything.
  2. Clean up. Archive the old, remove the duplicates and give every site an owner. Less content means fewer surprises, and better answers from what is left.
  3. Lock down. Fix the oversharing, apply sensitivity labels and leave the restricted sites out. Then test the boundary.
  4. Deploy AI. One team first, on real work, then the rest.

Lock down is the step people skip, because it is the least visible. It is also the step that decides what AI can find.

Ask the questions you hope it can't answer

The test is simple and a little uncomfortable. Before anyone switches AI on for real, sign in as an ordinary employee, not an administrator, and ask the questions you hope it cannot answer. Do it once for each department, because each one can see different things.

  • What does everyone in the finance team earn?
  • Summarize the last board meeting.
  • Who is on a performance plan?
  • What discount did we give our largest client?
  • Are we planning layoffs?
  • Show me the latest version of the acquisition model.

Write down every answer. Anything restricted that comes back is a fix, and the test runs again after each one. The boundary passes when every one of those questions comes back empty. Only then does the first team get access.

Try it here. Ask what an employee might ask, and see what AI finds today and after the boundary is set.

What it looks like in one scenario

In one scenario, a 50-person professional services firm bought AI licenses and left them switched off, because nobody could say what the AI would find. They were right to wait. One test question about bonuses came back quoting a payroll spreadsheet that had been shared with the whole company years earlier.

The Scan sorted their files without opening any of them. More than half had not been touched in three years, and a fifth were duplicates. Another 12% was restricted HR, finance and legal material, and 8% had no owner anyone could name. Only about 5% was current, owned and safe to connect.

Six sensitivity labels went on automatically, and the old material went to the archive. Then the boundary test ran, and no HR or finance file came back for anyone. The finance team went first, on the work they actually do, and operations followed. Six weeks after the licenses had been sitting unused, AI was in daily use, answering from current documents instead of three-year-old drafts.

The same rules apply to every AI

This is not only about Copilot. Claude, ChatGPT and agents built in Azure AI Foundry can all connect to SharePoint, and when they do, they see what the person using them can see. Where a tool runs outside Microsoft 365, you also decide exactly which sites it can reach, so the boundary matters even more. We choose the tool for the job, but the boundary comes first either way. Your licenses come first too: if the job needs new AI seats or a Microsoft 365 upgrade, you see the cost and what it pays for before we build it.

If you have AI licenses you are not sure about switching on, book the Scan. It is free: an automated scan of your Microsoft 365 and a few 30-minute conversations with your people, and you get the numbers on who can see what before anyone asks the AI.

For IT
  • Start with the data access governance reports in SharePoint Advanced Management to find sites shared with Everyone or Everyone except external users, and sharing links with no expiry. Check your admin center for what your licenses include.
  • Restricted Content Discovery keeps a site out of Microsoft 365 Copilot and organization-wide search without changing who can open it. Use it for board, HR and deal sites while permissions are fixed. Restricted SharePoint Search is a stopgap, not a plan.
  • Publish Microsoft Purview sensitivity labels, with auto-labeling for HR, finance and legal content. A DLP policy for the Microsoft 365 Copilot location can keep labeled files out of responses.
  • Move inactive sites to Microsoft 365 Archive so they drop out of search and AI answers but stay recoverable for the records period.
  • Run the boundary test with test accounts that mirror real roles in each department. Keep the prompts and results as evidence, and use Data Security Posture Management for AI in Purview to watch prompts after go-live.
  • For Claude, ChatGPT or Azure AI Foundry, check which connector scopes and sites each tool is granted, and whether it acts with the user's delegated permissions or its own app identity.
Start here

Book the Scan.

Thirty minutes on a call. We look at your Microsoft 365 with you, put numbers on it and tell you the first three things we would do.