Sensitive Information Is Reaching the Wrong People—Maisy Follows Microsoft 365 Permissions

by | Jul 25, 2026 | AI consultant Texas, AI for nonprofits, AI Knowledge Hub, AI Knowledge Hub for Nonprofits, College Station AI consulting, nonprofit, nonprofit Copilot, Retain Institutional Knowledge

A nonprofit may organize its procedures successfully and still create a serious problem if employees can access information they do not need.

A volunteer finds a manager-only document. A program employee sees confidential HR guidance. A contractor gains access to financial procedures. A broadly shared SharePoint site contains participant information that should have remained restricted.

The issue is not always malicious behavior. In many cases, access was granted quickly for convenience, inherited through a group or never reviewed after someone changed roles.

A Knowledge Hub must make information easier to find without making sensitive information easier to expose.

Classify Information Before Connecting It

The nonprofit should decide who may access each type of information before adding it to an AI Knowledge Hub.

Useful classifications may include:

  • Public information
  • General internal guidance
  • Program-specific procedures
  • Manager-only instructions
  • Restricted financial information
  • Confidential HR material
  • Participant or client information
  • Legal and compliance records
  • Security-sensitive information

Each document should have an owner who approves its classification and access requirements.

The principle of least privilege means users should receive only the minimum access necessary to perform their assigned work. That principle helps reduce both accidental disclosure and unnecessary exposure.

Classifying information also helps the nonprofit retain institutional knowledge about access decisions instead of relying on administrators to remember why someone was granted permission years earlier.

Use Microsoft Groups Instead of Informal Sharing

SharePoint should serve as the organized knowledge source, but its permissions must reflect actual organizational roles.

Access may be assigned through Microsoft 365 groups or Microsoft Entra security groups for roles such as:

  • All employees
  • Program managers
  • Finance staff
  • HR personnel
  • Executives
  • Board members
  • Approved volunteers
  • External contractors

Microsoft recommends using the built-in SharePoint groups for communication sites and the associated Microsoft 365 group for team sites when practical. Its guidance on customizing SharePoint permissions explains how access can be assigned to appropriate groups and users.

The nonprofit should avoid sending anonymous or broadly accessible links to sensitive content. It should also review group membership when employees change roles, contractors finish projects or volunteers leave.

Microsoft’s restricted access control guidance explains how SharePoint site access can be limited through Microsoft 365 groups or Entra security groups, including in Microsoft search and Copilot experiences.

Let Maisy Enforce the Existing Access Model

Copilot Studio provides the conversational layer.

Through Maisy, employees could ask:

  • What is the current reimbursement procedure?
  • Where is the participant intake checklist?
  • Who approves this exception?
  • Which policy applies to managers?
  • Where are the security incident instructions?
  • Who can access this document?

Maisy should answer from approved SharePoint knowledge only when the signed-in user has permission to access the underlying source.

Microsoft explains that when SharePoint is used as a Copilot Studio knowledge source, users are authenticated with their Microsoft credentials and the agent does not give them additional SharePoint permissions.

This means a volunteer may receive general safety guidance while being unable to retrieve manager-only procedures. A program employee may access operational instructions without seeing restricted HR or finance material.

Keep Sensitive Records in Their Proper Systems

Not every record belongs in SharePoint.

The case-management system should remain authoritative for participant records. The CRM should remain authoritative for donor information. HR and payroll systems should remain authoritative for employee records. Accounting software should remain authoritative for transactions.

SharePoint may contain general procedures, blank forms and links explaining how employees use those systems. It should not become an uncontrolled copy of confidential records.

Passwords, private keys, recovery codes, banking details, completed background checks and unrestricted participant files should not be placed in a general Knowledge Hub.

Maisy should not decide who deserves access, override a permission restriction or reveal that restricted content exists. Access decisions remain with leadership, system owners, HR, IT and other authorized professionals.

How Maisy Helps

Pixeldust begins by identifying the information employees need, the systems where it currently resides and the people who should be allowed to access it. Discovery looks for broadly shared folders, inherited permissions, outdated group memberships and sensitive records stored in inappropriate locations.

Pixeldust then works with content owners to classify information, organize approved guidance in SharePoint and map permissions through Microsoft 365 and Entra groups. Maisy is configured through Copilot Studio only after the access model is reviewed.

Realistic questions are tested using different employee and volunteer roles to confirm that users receive appropriate answers without seeing restricted content.

This helps the nonprofit retain institutional knowledge while making approved information easier to retrieve without weakening the security controls that protect sensitive people, records and operations.

Pixeldust IT Contract Risk Review Icon

Free Assessment

Complete the form below, and let's talk about how we can help preserve your organizational knowledge and make it easier for your team to find the answers they need.

Name(Required)

Free Guide: The Knowledge Capture Playbook

A practical system for extracting critical knowledge from employees, documents, workflows and real operational cases. This white paper includes prioritization scoring, interview scripts, workshop agendas, capture templates, evidence standards, validation controls, performance metrics and a 30/60/90-day rollout plan.

Download The Free PDF Guide

The Intelligence Compound: A New Operating Model for AI in Small Business

The Intelligence Compound presents a practical framework for implementing AI in small business. Rather than treating AI as a collection of isolated productivity tools, the paper explains how businesses can use it to preserve knowledge, support decisions, reduce owner dependency, identify operational problems, and improve processes over time. It includes original use cases, governance principles, real-world examples, and a 90-day implementation roadmap.

Download Whitepaper PDF