Nonprofits often need employees to find information quickly.
They also need to prevent the wrong people from seeing sensitive information.
Those goals are not in conflict, but they do require careful planning.
A secure AI knowledge hub should not make all organizational information available to everyone. It should respect the same access boundaries the nonprofit already uses across departments, programs and roles.
Example: A Domestic-Violence Nonprofit
Consider a domestic-violence organization operating emergency shelter, legal advocacy, counseling referrals, housing support and community outreach programs.
Its information may include:
- Shelter procedures
- Client-safety protocols
- Employee policies
- Volunteer training
- Grant requirements
- Incident procedures
- Financial records
- Legal documents
- Board materials
- Program manuals
- Internal contact lists
- Facilities information
Some of this information should be widely available to staff.
Other information must remain tightly restricted.
A volunteer may need the emergency-evacuation procedure but should not have access to employee records. A program employee may need approved shelter procedures but not confidential legal documents. A general staff member should not receive information about protected client locations.
Role-based permissions help maintain these boundaries.
What Role-Based Permissions Mean
Role-based permissions control access according to a person’s responsibilities.
Instead of deciding access one document at a time for every employee, the nonprofit defines groups or roles such as:
- General staff
- Program employees
- Supervisors
- Human resources
- Finance
- Executive leadership
- Board members
- Volunteers
- Contractors
Each role receives access to the information needed to perform its work.
Access should be based on legitimate operational need, not convenience.
AI Should Not Create New Access
An AI knowledge hub should only provide answers from information the user is already authorized to access.
If an employee cannot open a restricted HR document in SharePoint, the knowledge agent should not summarize it for them.
If a volunteer cannot access confidential shelter procedures, asking the question through chat should not bypass that restriction.
The AI interface changes how users find information.
It should not change who is allowed to see it.
Why This Matters More With Conversational Access
Traditional document systems create friction.
That friction is often frustrating, but it can also hide poor permission design because employees do not know what information exists.
Conversational AI makes information easier to request.
An employee can ask a direct question without knowing the file name or storage location.
That is useful, but it also means permission mistakes become easier to expose.
If SharePoint access is too broad, an AI agent may make restricted information easier to discover. The problem is not necessarily the AI. The problem is that the underlying permissions were already wrong.
Before introducing conversational access, the nonprofit should review who can access what.
Sensitive Information Takes Many Forms
Nonprofits may hold sensitive information involving:
- Clients
- Employees
- Donors
- Volunteers
- Financial records
- Legal matters
- Health information
- Youth
- Domestic-violence survivors
- Substance-use recovery participants
- Foster families
- Board decisions
- Internal investigations
Not all sensitive information belongs in the same category.
A domestic-violence organization may need especially strict controls around client identities, service locations, safety plans and confidential case information.
The knowledge hub should distinguish between general operational guidance and protected records.
Policies and Client Records Are Different
An employee may need access to a policy explaining how client information should be handled.
That does not mean the employee should receive access to every client record.
A knowledge hub may appropriately answer:
- What is the process for handling a confidentiality request?
- Who should be notified after a safety incident?
- What records-retention policy applies?
- How should confidential documents be stored?
- What training is required before accessing client information?
It should not automatically retrieve or reveal protected client details.
Policy access and record access must be treated separately.
Permissions Should Follow Existing Identity Systems
Organizations using Microsoft 365 can often manage access through existing identities, groups and SharePoint permissions.
For example, the domestic-violence nonprofit may have separate groups for:
- Shelter employees
- Legal advocates
- Housing staff
- Human resources
- Finance
- Executives
- Volunteers
Each SharePoint site, library or knowledge area can be configured according to those groups.
A Copilot Studio agent can then operate within that permission structure when designed and configured correctly.
This reduces the need to create a separate security model solely for the knowledge hub.
Good Permissions Begin With Information Classification
Before assigning access, the nonprofit should classify its information.
A practical structure may include:
- Public
- General internal
- Department-restricted
- Confidential
- Highly restricted
Public information may be available on the nonprofit’s website.
General internal information may include standard policies and routine procedures.
Department-restricted information may include program-specific manuals.
Confidential information may include HR, finance or legal records.
Highly restricted information may include protected client information, shelter locations or active investigations.
Classification makes permission decisions more consistent.
Too Much Access Creates Risk
Some organizations give broad access because restrictive permissions are difficult to manage.
This may feel efficient until sensitive information is exposed.
Broad access can create risks involving:
- Client safety
- Privacy
- Employment matters
- Legal exposure
- Grant compliance
- Donor trust
- Internal investigations
- Organizational reputation
An AI knowledge hub should not be built on the assumption that every employee can see everything.
Too Little Access Also Creates Problems
Overly restrictive permissions can prevent employees from finding information they legitimately need.
That leads to workarounds:
- Documents emailed as attachments
- Files copied into personal folders
- Screenshots shared through Teams
- Printed copies kept outside controlled systems
- Employees asking others to forward restricted documents
These workarounds often create more risk than properly designed access.
The objective is not maximum restriction.
It is appropriate access.
Database Access Requires Separate Controls
The domestic-violence nonprofit may use a case-management system, donor database, HR platform and accounting system.
These systems may contain information that should not be copied broadly into a knowledge hub.
Selected data may sometimes be accessed through approved connectors, APIs, indexed copies or scheduled exports.
However, each integration must define:
- Which fields are available
- Which records are included
- Which users can request them
- How current the data must be
- Whether responses are logged
- Whether sensitive details are excluded
- What happens when roles change
Database permissions should be evaluated independently from document permissions.
Access Must Change When Roles Change
Permissions are not permanent.
Employees transfer departments. Volunteers become staff members. Managers change responsibilities. Contractors finish their work. Employees leave.
The nonprofit needs a process for changing or removing access when roles change.
This should include:
- New-hire access
- Department transfers
- Temporary assignments
- Leave periods
- Contractor access
- Volunteer access
- Terminations
- Leadership transitions
An outdated account with unnecessary access can create the same risk as an incorrectly configured document.
The Agent Should Know When Not to Answer
Permissions alone do not address every sensitive situation.
Some questions should be escalated even when the employee has access to related information.
For example:
- Is this situation legally reportable?
- Should this client be relocated?
- Can this exception be approved?
- How should an active investigation be handled?
- Should this confidential information be disclosed?
The knowledge hub can provide approved policies and escalation contacts.
It should not replace legal, clinical, safety or leadership judgment.
Start With a Permissions Review
Before connecting organizational information to AI, nonprofit leaders should ask:
- Which information is currently available to everyone?
- Which content should be restricted?
- Are SharePoint permissions inherited too broadly?
- Do volunteers have access beyond their roles?
- Are former employees still included in groups?
- Which documents contain sensitive information?
- Who approves access changes?
- Which databases require separate controls?
- How are access decisions documented?
- How often are permissions reviewed?
This review often reveals issues that existed before the AI project began.
Security Is Part of Knowledge Management
A knowledge hub is not useful if employees cannot trust it.
They need confidence that the answers are correct and that sensitive information remains protected.
For a domestic-violence nonprofit, that trust is especially important. Poor access controls can create serious operational and safety consequences.
Pixeldust helps nonprofits organize information, classify sensitive content, review access requirements and build Microsoft-based knowledge hubs around existing roles and permissions.
The goal is not to make all information available.
The goal is to make the right information available to the right people.





