AI Oversharing Report
Rolling out AI on Microsoft 365 - Copilot, ChatGPT, Claude, or an internal agent? Grant read access and we show you, site by site, exactly what it would surface to the wrong people the day you switch it on, before you switch it on.
Grant read access - the report comes back within a few working days. You keep it either way.
The promise
exposures you didn't know about, or it's free
- Site by site, before you switch anything on
- What AI would surface, and to whom
- Fee credited in full against the pack it leads to
The problem
Any AI you point at Microsoft 365 - Microsoft Copilot, an enterprise ChatGPT or Anthropic Claude deployment wired to your data, or an internal agent over SharePoint - grants no new access. It works with the permissions each user already has, and simply makes existing access instant and searchable. That is exactly the problem: most tenants have accumulated years of organisation-wide sharing links, stale permissions, and unlabelled sensitive content that nobody sees day to day - until a tool that searches everything at once surfaces it all at once. It is why so many teams licensed an AI assistant and never switched it on. This is the fast, low-cost way to see the exposure before you enable it: not a full remediation, but a clear reading of what the AI would reach on day one.
What's Included
- An oversharing sweep of your Microsoft 365 - organisation-wide links, 'Everyone except external users' access, and stale permissions from people who moved or left
- The sensitive content an AI assistant would surface that is unlabelled or misclassified, identified by site and library
- A red/amber/green exposure report, with the highest-risk sites ranked by how much they expose and to whom
- A short call to talk through the findings and what closing them before switch-on would involve
What This Assumes
- Read-only access to your Microsoft 365 - SharePoint, OneDrive, and Microsoft Graph, plus Microsoft Purview where in use
- One tenant - a very large SharePoint estate may be re-scoped at quoting
Not Included
- Any remediation - the report shows the exposure, it does not close it (that is the AI Readiness Pack)
- The AI assistant's own licensing, rollout, or configuration
Outcomes
- A clear-eyed view of what AI would expose on day one, before you enable it - Copilot, ChatGPT, Claude, or an internal agent
- The oversharing hotspots found and ranked, not discovered by an employee's prompt
- A costed shortlist of what to fix, and in what order, to switch on safely
Who It's For
- Teams that have licensed Microsoft Copilot, ChatGPT, Claude, or an internal AI agent and held back from rolling it out
- IT and security leads who need the data-exposure risk quantified before switch-on, not after
- Anyone weighing the full AI Readiness Pack who wants to see the size of the gap first
Engagement Model
A fixed-price, fast-turnaround report: grant read access and get the exposure report back within a few working days. Defined deliverables, a fixed price, no day rates. And it is guaranteed: if the report does not surface at least three exposures you did not already know about, it is free. The fee is credited in full against the AI Readiness Pack if you book within 30 days.
Pricing: from £2,500 / $3,200 - larger engagements are tailored to scope.
We govern the AI we deliver with
This work is delivered AI-accelerated, so AI tooling reads configuration and permission data from your estate along the way. It is fair to ask how that is governed - and the answer is published: which providers we use and on what commercial terms, what client data never reaches a model, that a named architect signs off every output, and that AI tooling holds no standing write access to client systems.
Read our AI policyRelated
The AI Readiness Pack
Found the exposure? The fixed-price, guaranteed sprint that closes oversharing and gets you to a verified, safe switch-on.
Before you switch on AI, fix oversharing
The thinking behind the report - why AI inherits every permission your users already have.
Microsoft 365 Security & Hardening
The ongoing identity, device, and data hardening behind a safe rollout. Start with a free posture audit.
AI Oversharing Self-Check
Prefer to gauge it yourself first? The free ten-question self-check is the fast read on whether AI would expose over-shared data.
Get started
Find out where you stand, free
Most engagements start with a no-cost posture audit against the baselines that matter to you. If a fixed-fee roadmap is the right next step, we'll say so - and if it isn't, we'll say that too.