Skip to content

Security1 publisher2 min readPublished

Syskit's 327-respondent survey puts Copilot rollouts 33 points ahead of permissions reviews

Syskit's September 10 governance report has 76% of UK and US organizations running or piloting Copilot on Microsoft 365 data and 43% reviewing permissions and oversharing before switching it on. The findings are self-reported.

The Watch · Security desk

Illustration accompanying Syskit's 327-respondent survey puts Copilot rollouts 33 points ahead of permissions reviews

What happened

  • Syskit surveyed 327 IT and security decision-makers responsible for Microsoft 365 governance at US and UK organizations with 500 or more employees, publishing the results on September 10.
  • Three-quarters of respondents, 76%, have deployed or piloted an enterprise AI tool such as Copilot on Microsoft 365 data, and 43% completed a thorough review of permissions and oversharing risk first.
  • While 91% say they are confident they can see which agents are active and what those agents can reach, 22% have a formal policy defining what an AI agent may access.
  • On the underlying permissions, 41% leave SharePoint sites accessible to all staff without restrictions, 35% say former employees' files are still available to active users, and 33% have files shared with "Everyone".
  • The governance problem named most often is content with no accountable owner, with 47% flagging orphaned teams, groups and sites that AI tools can read with the same authority as anything else.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Anyone inside the tenant with a prompt box inherits its oversharing without stealing a credential or touching a CVE, and the activity looks like ordinary search in the logs.
  • decision The permissions review becomes a gate on the rollout rather than housekeeping deferred behind it, and it is paid in staff hours reading SharePoint permissions.
  • constraint An organization that cannot enumerate access quickly cannot scope what an agent exposed, so response begins with building an inventory that should already exist.
  • contradiction Syskit sells Microsoft 365 governance tooling, so the survey measures appetite for its own product, and none of the findings are attacker telemetry.

Copilot answers with the permissions of the person who asked. A site opened to all staff in 2019 stayed quiet because nobody could find the file. Search over the tenant finds it. Toni Frankola, Syskit's CEO, said AI agents have removed the friction that once made accidental access to sensitive files less likely, and that Copilot surfaces content according to existing permissions, including files and sites shared broadly years ago and never reviewed since [8].

"What stands out in this data is that so few organizations can check what their AI can actually reach before switching it on, and fewer still plan to spend anything on finding out. Reviewing permissions is unglamorous work, but it has become the deciding factor in whether an AI rollout is safe," Frankola said [7].

The distance between deployment and review is 33 percentage points [1]. Reviewers are a subset of deployers, so at least a third of the sample turned on an AI tool over data it had not fully checked. Against 327 respondents, that is roughly 108 organizations [2].

Nine percent said an agent inherits the full permissions of whoever deployed it [6], about 29 organizations in this sample [4]. Where an administrator built the agent, its blast radius is the administrator's reach, and it is available to anyone who can prompt it.

The incident figure needs splitting. Syskit reports that 90% of organizations have experienced or suspect an incident linked to misconfiguration or over-permissioned access in the past two years, and that 39% confirmed one [16].

Self-reported confidence also runs ahead of the evidence. Eighty-three percent said they know exactly who can access sensitive data at any given moment [14]. Four percent could produce a complete access report for an external auditor within an hour, and 55% would need a day or longer [15].

What to watch

  • A confirmed case of Copilot surfacing overshared data to the wrong staff would move this from survey material to telemetry; the report carries none.
  • Whether the 22% with a written agent access policy moves in Syskit's next round, given its CEO says buyers do not plan to spend on finding out what AI can reach.
  • Whether external auditors start asking for the complete access report only 4% of respondents can produce inside an hour.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories