Skip to content
CyberTECTDigital operations control
All resources

How to Know What Data Your AI Tools Can Access

To understand AI access, identify the product, account, plan, users, connected systems, permissions, files, groups, plugins, logs, retention settings and the owner responsible for review.

The short answer

To know what data an AI tool can access, identify the exact product, account, plan, administrator, users, connected systems, permission model, files, groups, plug-ins, agents, browser access, logs, retention settings, vendor terms and business workflows. Then test with representative users and document what is approved, restricted and unknown.

Start with the exact AI product

“We use AI” is not enough detail to understand access. A personal chatbot, ChatGPT Business, Microsoft 365 Copilot, Gemini for Google Workspace, a CRM assistant, a meeting-summary tool and a browser extension all have different access paths.

Record the product name, vendor, plan, account owner, administrator, user group, billing owner, sign-in method, MFA status, enabled features and whether the tool is approved for business use.

Map the data sources

List every source the AI tool can receive, search, summarize or act on. Include prompts, uploaded files, email, cloud storage, chat, meetings, calendars, CRM records, accounting data, websites, support tickets, browser pages, desktop files, mobile content, connectors, plug-ins and API integrations.

For each source, ask whether access is based on the user’s existing permissions, an application permission, a service account, an admin grant, a browser permission, a file upload or manual copy-and-paste.

Review Microsoft, Google and standalone AI separately

Environment Access review focus
Microsoft 365 Copilot SharePoint, OneDrive, Teams, Exchange, sensitivity labels, external sharing, groups, guests, connectors and user permissions.
Google Workspace and Gemini Google Drive, shared drives, Gmail, Meet, Groups, external sharing, third-party apps, DLP controls and Gemini service settings.
Standalone AI tools Prompt history, file uploads, data-use settings, retention, workspace administration, custom assistants, memory, plug-ins and export/deletion controls.
Vendor AI features Data already held by the vendor, new AI terms, subprocessors, support access, logs, outputs, human review and exit options.

Microsoft’s Copilot guidance explains that Copilot uses the permissions and policies in Microsoft 365. Google also publishes DLP for Gemini guidance for supported Workspace services. Those product controls are useful only when the business reviews its own permissions and use cases.

Use these discovery sources

  • Microsoft 365 enterprise apps, SharePoint/OneDrive sharing reports, Teams membership, guests and admin roles.
  • Google Workspace third-party app access, Drive sharing, shared drives, Groups, Gmail/Meet settings and Gemini admin controls.
  • Password manager records, credit-card subscriptions, browser extensions, endpoint software and mobile app lists.
  • Vendor contracts, invoices, support portals, API keys, service accounts, OAuth grants and integration settings.
  • Interviews with staff doing sales, finance, HR, marketing, client service, operations and administration.

Classify findings into four buckets

  1. Approved access. The access is intentional, proportionate, documented and reviewed.
  2. Excess access. The access exists but is broader than the business purpose requires.
  3. Unknown access. The business cannot explain what the tool or connected app can reach.
  4. Prohibited access. The tool or workflow receives information the business has decided should not be used that way.

Unknown access is not a reason to freeze every workflow forever. It is a reason to assign ownership, limit high-risk uses and complete the review before expanding AI.

Connect the access map to everyday rules

An access map should feed the AI adoption checklist, the safe AI use guide and the AI data exposure guide. It should also connect to the AI policy and the apps and vendors access register.

CyberTECT’s Digital Operations Checkup and AI & Digital Operations Review can document these relationships alongside accounts, files, vendors, backups and continuity.

Frequently asked questions

How do I know what data an AI tool can access?

Identify the exact product and account, then review connected systems, permissions, integrations, files, groups, plugins, logs, vendor settings and user workflows.

Can Copilot or Gemini see everything in the business?

They should operate within configured product controls and user permissions, but broad or outdated permissions can make information easier to find. Review permissions before broad rollout.

Do browser extensions count as AI tools?

Yes, if they use AI for work or can read business content. Review what pages, text, files and accounts the extension can access.

Who should maintain the AI access map?

Assign a business owner supported by the technical administrator. The map should be updated when tools, permissions, vendors, integrations, staff or data locations change.

What is the minimum AI access map?

At minimum, record the tool, purpose, owner, users, account type, data sources, sensitive information, integrations, settings, review date, approved uses and offboarding path.

Make AI access visible

CyberTECT helps Ontario small businesses map AI access, reduce oversharing and document practical controls through AI Readiness & Governance and Digital Operations review work.

Authoritative sources and further guidance

Using this guidance

CyberTECT resources provide general operational guidance. They do not replace advice specific to your legal, regulatory, contractual or technical circumstances.

Discover more from Cybertect

Subscribe now to keep reading and get access to the full archive.

Continue reading