Nonprofits need employees to find information quickly, but not every employee should see every document.
Organizations may hold participant records, employee files, donor information, financial reports, legal documents and security procedures. Placing all of this content into one broadly accessible library would create unnecessary risk.
An AI Knowledge Hub can help a nonprofit retain institutional knowledge without removing the access controls that protect sensitive information.
Why Information Access Becomes Difficult
Sensitive information is often scattered across email, shared drives, personal folders and specialized software. Staff may not know which documents are confidential, who owns them or where approved guidance should be stored.
Common categories include:
- Public information
- General internal procedures
- Manager-only guidance
- HR and personnel information
- Financial records
- Donor information
- Confidential participant records
- Legal advice and signed agreements
- Security procedures
- Passwords and system credentials
The solution is not to place everything into Maisy. The organization must first classify its information and decide who needs access.
The NIST principle of least privilege states that users should receive only the access needed to complete their assigned tasks. This is a practical foundation for designing a nonprofit Knowledge Hub.
Organize Guidance Without Exposing Records
SharePoint should serve as the organized knowledge source. It can contain approved policies, blank forms, training materials, decision trees and instructions explaining how employees should handle restricted information.
Copilot Studio provides the conversational AI layer. Authorized employees may access Maisy through Microsoft Teams and ask questions such as:
- Who may access participant intake records?
- Where should a completed medical form be stored?
- Which blank consent form should staff use?
- Who approves access to financial reports?
- What should an employee do after sending information to the wrong person?
- Which records may be shared with a partner organization?
Maisy should only retrieve content the user already has permission to access. Microsoft supports managing SharePoint access through Microsoft 365 groups and security groups rather than granting broad access to individual files. (Microsoft Learn)
Keep Sensitive Records in Their Proper Systems
Blank forms and general instructions may belong in SharePoint. Completed forms containing personal, medical, financial or participant information should usually remain in the appropriate secured system.
The case-management system remains authoritative for participant records. The donor CRM remains authoritative for donor information. HR and payroll systems remain authoritative for employee records. Accounting software remains authoritative for financial transactions.
Maisy can explain procedures surrounding those systems and direct employees to the correct location, but it should not automatically copy every sensitive record into the Knowledge Hub.
Direct integration requires technical discovery, licensing review, permission mapping, data-quality review, security planning and testing. Read-only access should generally come before allowing AI to update another system.
Passwords, access keys and private credentials should never be exposed through the assistant. CISA recommends using access controls and data-classification practices so sensitive information remains available only to authorized users. (CISA)
How Maisy Helps
A practical starting point is a permissions and information-classification review. Pixeldust identifies repeated questions, locates authoritative guidance, separates general procedures from restricted records, assigns content owners and maps SharePoint permissions.
Pixeldust then organizes approved knowledge in SharePoint, configures the Copilot Studio layer and tests questions using employees with different access levels. This helps the nonprofit retain institutional knowledge while preventing the Knowledge Hub from becoming an unrestricted repository for confidential information.





