Your agent is not who you think it is.
You restricted those SharePoint folders for a reason. Then you connected an AI agent to them, and the question nobody asked is which identity that agent uses when it reads.
Most people cannot answer that. Three questions further down this page will tell you whether it is even your problem. Answering them takes about a minute.
The permissions did not fail. They were never consulted.
Same question, same person, two different builds. The only difference is which identity reaches Microsoft 365.
You are unusually exposed if all of these are true.
- You built your own connection to Microsoft 365, whether that is an MCP server, a Power Automate flow, or a Copilot Studio agent.
- Some SharePoint or OneDrive locations are deliberately restricted, because not everyone should see everything.
- You are on Claude Team, ChatGPT Team or Copilot Studio rather than a full Microsoft 365 Copilot rollout.
That last one matters more than it looks. Microsoft's own cleanup tooling for this problem, SharePoint Advanced Management, ships with a Microsoft 365 Copilot licence. If you are not on Copilot, the safety net that every enterprise guide assumes you have is simply not there.
One of these is what you are running.
The agent signs in as the person asking
Access is the overlap of what the app may do and what that person may already reach. Your existing permissions do the enforcing, for free. The trade is that nothing can run unattended, because no one is there to be signed in as.
The agent has its own identity, scoped to named locations
A grant of Sites.Selected starts at nothing and an administrator adds specific sites one at a time. Same unattended convenience, a fraction of the reach, and an access list you can audit.
The agent has its own identity and can reach everything
Sites.Read.All and Files.Read.All mean what they say: every site in the tenant, for every person who asks. This is the easier thing to build, which is why it is usually what got built.
A map of every connection, and a verdict on each one.
- Every route between your agents and Microsoft 365, and the identity each one runs as.
- A verdict per location: safe, over-permissioned, or unknown.
- The Graph permissions actually consented on your app registrations, and which are wider than your intent.
- A remediation plan ranked by exposure, separating a settings change from a rebuild.
- What is already fine and should be left alone.
- What to re-check the next time you add an integration.
Written, and yours. If the answer is that you are fine, the report says that, and it says it in the first paragraph.
Three questions, one minute, no email.
Answer them here and you will know whether this is your problem before anyone asks you for anything. If it is not, this page will say so and you can close the tab.
This is your pattern to check, and the audit is built for it.
An agent holding its own credential does not consult your SharePoint permissions at all. Nobody gets denied, nothing errors, and the only thing between a person and a restricted file is whatever the prompt says. A prompt is not an access control.
The audit maps every route between your agents and Microsoft 365, names the identity each one runs as, and hands you a written remediation plan ranked by exposure. One week, $2,500, async. If it turns into fix work, the $2,500 comes off that invoice, so the diagnosis never costs extra.
From October, Microsoft surfaces oversharing alerts directly in the Microsoft 365 admin centre. There is a difference between finding your number privately now and having it appear on a dashboard leadership can open.
Start the audit · $2,500Questions first? Email me. Written answers, usually same day. No calls to book.
You are probably already fine.
If the agent signs in as the person asking, your existing permissions do the enforcing for free, and they stay correct as staff join and leave. That is the right build for most teams.
The one thing worth confirming is that it is true of every route, not just the one you remember building. If you want that checked in writing, the audit covers it, but I would not call it urgent.
Have it checked anyway · $2,500Lower exposure than most, for now.
An agent with its own credential bypasses your permissions, but if nothing is deliberately restricted, there is not much for it to leak today.
The gap opens the day you first restrict a folder, because nothing in this build will tell you when that happens. The agent keeps reading everything, including the thing you just restricted. Worth fixing on your schedule, not urgently on mine.
Email me when that day comesThis one is not for you.
Without an agent reaching into Microsoft 365, there is no permission gap of this kind to find. I would rather say that now than sell you an audit that arrives at it.
Ask whoever builds it: does the agent sign in as the person asking, or as an app with its own credential? If it is the second one, your permissions are not protecting you. A prompt is.
Rather skip the questions and ask a person? Email me directly. Written answers, usually same day, and nobody's calendar is involved.
The three questions above are the qualifier. The audit runs on twenty.
If you want to run the check yourself first, the full question set unlocks right here. It is the same instrument the paid audit uses. Fair warning from experience: the questions are the easy half. Knowing which answers are fine and which are exposure is the half people pay for.
work email · single opt-in · the set opens on this page, nothing to download
If the audit turns into fix work, the $2,500 comes off the $7,500, so the diagnosis never costs extra. A comparable enterprise readiness assessment starts around fifteen thousand and produces a document. This one is scoped for teams who build their own things, and the build work behind the fix is the same practice as the install work.