Tasirio research
When you switch on an AI assistant — Microsoft 365 Copilot, a Copilot Studio agent, Salesforce Agentforce, or one you built in-house — it inherits every permission its users already have, including the ones nobody remembers granting. This report maps where that over-reach hides across a modern estate (Microsoft 365 and Dynamics 365 lead the examples, but the same holds across Google Workspace, AWS, Salesforce, Snowflake and beyond), the patterns native tooling wasn't built to see, and how to prove exactly what your AI can reach — so you can turn AI on with confidence, not hope.
Native platform controls — Microsoft's Purview and Entra, and equally the config tools in Google Workspace, AWS and Salesforce — are a configuration plane, and each is excellent at what it was built for: it tells you how a setting is set. None of them, on its own, computes the question that actually matters once you enable AI: "What can our copilots and agents secretly reach across an over-permissioned org, as which identity, and is that allowed?"
An AI assistant doesn't reach data the way a person browses to it. It follows the transitive, effective path — inherited group memberships, forgotten "anyone with the link" shares, over-scoped app consents, a vector store that flattened away the source permissions. The gap between "what people think Copilot can see" and "what it can actually reach" is where every surprise lives.
Tasirio's assessment framework maps AI reach across 17 surfaces — nine core Microsoft/identity surfaces plus eight "frontier" surfaces that emerged with modern AI agents. This isn't a vendor's checkbox list; it's the map of where AI reach compounds.
"Critical" = no human in the loop, reads everything: over-privileged apps, world-readable confidential content, a vector store that stripped its ACLs, identity-impersonation paths.
| Surface | Why it matters for AI reach |
|---|---|
| Microsoft Entra ID | The identity substrate every other exposure inherits — over-scoped app consents, standing privilege, weak conditional access. |
| SharePoint / OneDrive | The corpus Copilot grounds on. Forgotten org-wide links + inherited group access = the board-level "reachable by everyone" number. |
| Purview / MIP | Label-vs-ACL drift: "you labeled it Confidential, yet Copilot reads it for everyone." |
| Dataverse / D365 / NAXT / F&O | The business-data layer — margins, AP bank details, PII, segregation-of-duties. The dealer-vertical differentiator. |
| M365 Copilot & Copilot Studio | The actual AI surface — who it's enabled for, auto-created site agents, copyable Direct Line secrets. |
| AI-agent runtime (MCP / RAG / A2A) | The fastest-growing surface. Custom vector stores that flatten source permissions — a low-privilege user gets crown-jewel content. No native platform control sees this. |
| Identity breadth (Okta, Google DWD) | Domain-wide delegation is the single largest AI-agent over-reach; cross-IdP privilege aggregation. |
| + Exchange, Teams, Azure, Power Platform, endpoint AI, third-party SaaS AI, audit | Eight frontier surfaces the structured checklists miss entirely — including data leaving to external AI (ChatGPT/Claude/Gemini). |
Across estates, the same shapes recur. Each is a single sentence an owner repeats to their board:
Copilot, Agentforce, and the agents you build do exactly what they're designed to — answer from what the user can access. They're not the problem; they're extraordinary. The over-permissioning was already there, accumulated over years. AI simply makes it instantly, fluently queryable. Tasirio exists to help you adopt AI faster and with confidence — turning "we're not sure what it can see" into "here's exactly what it can reach, and here's what we closed" — so the rollout goes ahead instead of stalling in a security review.
AI over-reach isn't just a security problem — it's a governance-and-audit problem. Tasirio maps every finding to the obligations it implicates, so the same read-only scan doubles as evidence for:
Findings carry a tamper-evident (SHA-256) evidence chain, per-finding "who should actually see this" verdicts, and the exact accounts to remediate — an auditor-grade record, not a screenshot.
Framework names (EU AI Act, NIST AI RMF, ISO/IEC 42001:2023, OWASP LLM Top 10, PCI-DSS) are the property of their respective organizations and are referenced descriptively to indicate the obligations Tasirio helps assess. Tasirio is an independent product — not affiliated with, endorsed, approved, or certified by any of these organizations — and a Tasirio assessment is not a formal conformity assessment or certification.
Everything above is computed from metadata — the locks and keys, never the content. Least-privilege, read-only scopes; the consent screen shows exactly what's requested; revocable anytime. Tasirio reads who can reach what — never what's inside.
This report describes the anatomy of AI exposure — the surfaces and patterns Tasirio assesses. As we complete more read-only assessments, these become a live, anonymized benchmark: "how does your AI-exposure surface compare to peers in your industry?" — reported only in aggregate, never identifying any organization. If you'd like to be part of that cohort, an assessment is the way in.