logo Prometheon
Permission debt: what your AI is actually allowed to read
Mario Beck

Permission debt: what your AI is actually allowed to read

Mario Beck

2026-08-25


Somebody needed a file on a Friday afternoon. Sharing it properly meant finding the right group, or raising a ticket, and waiting until Monday. Sharing it with the whole company took one click. The deadline won.

That happened in 2019. It also happened last week, and it will happen again on Friday. Repeat it for years across a file server, a SharePoint migration, a CRM, and the shared drive that arrived with the company you acquired, and you end up with a quiet layer of access that nobody designed and nobody owns.

I have started calling it permission debt, because it behaves like debt. You take it on to move faster today, it accrues silently, and something eventually forces you to settle.

That something is usually an AI assistant.

The number that should stop the meeting

Varonis reports that on average 10 percent of a company's Microsoft 365 data is open to every employee. In their 2025 State of Data Security Report, built on nearly 10 billion files across a thousand real environments, 99 percent of organisations had sensitive data an AI tool could surface. The same study found 88 percent carrying stale but still-enabled accounts for people who had left, 66 percent with cloud data reachable by anonymous users, and only one company in ten that had labelled its files at all.

Read those numbers as a description of a category rather than a verdict on you. A figure that close to 100 percent tells you where the industry is, not where your tenant is. The useful version of that statistic is the one you measure yourself.

Why none of this hurt until now

Permission debt was survivable for a long time because search was bad.

To find a document a colleague should not have seen, a person had to know it existed, guess roughly what it was called, and care enough to keep digging. Almost nobody cleared all three hurdles. Bad search was quietly doing security work that nobody budgeted for, and nobody thanked it.

Then you connect an assistant that reads everything it is permitted to read, in about a second, and answers in a friendly sentence with a citation attached.

The assistant is following your access rules exactly. That is precisely what makes it uncomfortable. It is not creating exposure. It is reporting exposure you already had, out loud, to whoever asks a reasonable question.

You are not the first person to be told this

Two things make the permission argument hard to dismiss as vendor noise, because neither of them comes from a vendor selling you an alternative.

The first is Microsoft. Its foundational deployment guidance for Microsoft 365 Copilot puts oversharing remediation in the foundation phase, before rollout, using SharePoint Admin Center, SharePoint Advanced Management, and Microsoft Purview. The company selling the assistant documents the permission cleanup as a prerequisite rather than an optional hardening step.

The second is a regulator. In July 2026 the Dutch data protection authority answered a prior consultation from the municipality of Haarlemmermeer, which had run a data protection impact assessment on Copilot, found high risks it could not mitigate alone, and was therefore legally obliged to ask. The authority concluded that the use as described would breach the GDPR, and that measures had to come first.

Four risks stayed high in that assessment: whether citizens could still exercise their privacy rights, what happens when the AI produces incorrect personal data about someone, what data Microsoft actually processes during Copilot use, and how long it keeps it. Among the measures required before deployment: proper access controls and data classification, and information management that prevents inappropriate access to data.

Two things are worth holding at the same time here. Haarlemmermeer is a municipality, carrying public duties and public scrutiny that most companies do not. And the four risks are not municipal in the slightest. Any organisation putting personal data through a hosted assistant arrives at the same four questions, usually with less documentation and nobody obliging them to ask.

Seven questions, one morning

Most AI readiness checklists ask about models, budgets, and use cases. Very few ask who can open what. This is the audit we run before any pilot. If you cannot answer one of these, that is the finding.

  1. Which systems will the assistant read, and who owns permissions in each one?
  2. How many items are shared with everyone, or by an open link, right now?
  3. When did an account last get removed, rather than disabled?
  4. Which locations hold HR, legal, salary, or client data, and who can reach them today?
  5. If the assistant cites a document, will the person reading the answer be allowed to open it?
  6. Who reviews access when somebody changes role, and how quickly?
  7. If an answer surfaces something it should not have, what is the response, and who runs it?

Question five is where a real deployment separates from a demo. An assistant that cites sources the reader cannot open has already told them the document exists, roughly what it covers, and often who wrote it.

Paying it down without freezing the company

Most permission cleanups die in week two. Somebody runs a report, sees the exposure, and revokes broadly. Within days the service desk is buried, a project misses a deadline, and the cleanup gets quietly parked. The exposure returns within a quarter, because the behaviour that produced it was never touched.

Here is the sequence that survives contact with the business.

Measure, change nothing. Count open links, sites shared with everyone, enabled accounts for people who have left, and locations holding regulated data. One week, read only.

Fix the concentration first. Exposure is never spread evenly. A small number of containers usually holds most of it, so starting there buys most of the reduction with very little disruption.

Make the safe path faster than the unsafe one. If requesting access takes two days and sharing with everyone takes one click, people keep choosing the click. Answer requests in minutes and the behaviour changes without a policy.

Close the tap. Change tenant and provisioning defaults so new oversharing stops being created while you clean up the old.

Review on role change, not on the calendar. An annual review is stale within a month. The moment somebody moves team is the moment their access should be re-derived.

Step three is the one that gets skipped, and it is the only one that changes behaviour rather than state.

The procurement question is about timing

Every AI assistant claims it respects your permissions. The claim is easy to make and hard to verify, because the part that matters is timing rather than intent.

Ask a vendor whether the assistant checks permissions in the source system at query time, or against a copy taken when the content was indexed. Then ask the follow-up: somebody's access is revoked at nine in the morning, so at what time does the assistant stop returning that content. That second question produces the longest pause in most vendor calls.

Ask where the index lives and who can read it. Ask who can see the query logs and under which country's jurisdiction they sit. Ask whether an auditor receives a log of answers given or a log of what was retrieved to produce them. Ask what happens when a document has no owner and no classification, because plenty of them do not.

Sovereignty conversations usually open with where data is stored. This is where they get concrete. Storage location is a contract term you negotiate once. Access control is an engineering decision you can verify on a Tuesday afternoon, and it decides how much damage any single answer can do.

Start with the query, not the project

None of this needs a transformation programme. It needs one number to begin with: how many items in your environment are shared with everyone right now. You can have that answer this afternoon, without buying anything, and it will tell you more about your AI readiness than any vendor demo.

I turned the audit above into a short worksheet, with the seven questions, a red, amber and green table for classifying sharing scope, and the five-step cleanup sequence in a form you can hand to whoever owns the tenant. You can grab it through our newsletter here.

And if question five is the one that made you wince, that is worth a conversation. It usually is.

Keep me updated

One useful email a week on sovereign AI, governance, and enterprise AI that ships. Sign up and get the free Sovereign AI Playbook.

Subscribe on our newsletter page