DRAFT — internal review only. Not indexed or linked publicly until approved.

Tasirio research

The Anatomy of AI Over-Reach

When you switch on an AI assistant — Microsoft 365 Copilot, a Copilot Studio agent, Salesforce Agentforce, or one you built in-house — it inherits every permission its users already have, including the ones nobody remembers granting. This report maps where that over-reach hides across a modern estate (Microsoft 365 and Dynamics 365 lead the examples, but the same holds across Google Workspace, AWS, Salesforce, Snowflake and beyond), the patterns native tooling wasn't built to see, and how to prove exactly what your AI can reach — so you can turn AI on with confidence, not hope.

The one question native tools won't answer

Native platform controls — Microsoft's Purview and Entra, and equally the config tools in Google Workspace, AWS and Salesforce — are a configuration plane, and each is excellent at what it was built for: it tells you how a setting is set. None of them, on its own, computes the question that actually matters once you enable AI: "What can our copilots and agents secretly reach across an over-permissioned org, as which identity, and is that allowed?"

An AI assistant doesn't reach data the way a person browses to it. It follows the transitive, effective path — inherited group memberships, forgotten "anyone with the link" shares, over-scoped app consents, a vector store that flattened away the source permissions. The gap between "what people think Copilot can see" and "what it can actually reach" is where every surprise lives.

The exposure surface is bigger than one product

Tasirio's assessment framework maps AI reach across 17 surfaces — nine core Microsoft/identity surfaces plus eight "frontier" surfaces that emerged with modern AI agents. This isn't a vendor's checkbox list; it's the map of where AI reach compounds.

17exposure surfaces
17surfaces mapped
61"critical" class
1blast-radius number

"Critical" = no human in the loop, reads everything: over-privileged apps, world-readable confidential content, a vector store that stripped its ACLs, identity-impersonation paths.

Where AI over-reach hides

SurfaceWhy it matters for AI reach
Microsoft Entra IDThe identity substrate every other exposure inherits — over-scoped app consents, standing privilege, weak conditional access.
SharePoint / OneDriveThe corpus Copilot grounds on. Forgotten org-wide links + inherited group access = the board-level "reachable by everyone" number.
Purview / MIPLabel-vs-ACL drift: "you labeled it Confidential, yet Copilot reads it for everyone."
Dataverse / D365 / NAXT / F&OThe business-data layer — margins, AP bank details, PII, segregation-of-duties. The dealer-vertical differentiator.
M365 Copilot & Copilot StudioThe actual AI surface — who it's enabled for, auto-created site agents, copyable Direct Line secrets.
AI-agent runtime (MCP / RAG / A2A)The fastest-growing surface. Custom vector stores that flatten source permissions — a low-privilege user gets crown-jewel content. No native platform control sees this.
Identity breadth (Okta, Google DWD)Domain-wide delegation is the single largest AI-agent over-reach; cross-IdP privilege aggregation.
+ Exchange, Teams, Azure, Power Platform, endpoint AI, third-party SaaS AI, auditEight frontier surfaces the structured checklists miss entirely — including data leaving to external AI (ChatGPT/Claude/Gemini).

The patterns that stop a room

Across estates, the same shapes recur. Each is a single sentence an owner repeats to their board:

Copilot surfaces a labeled-Confidential document — HR, M&A, or pricing — that the asker never knew existed, reachable only through a forgotten "people in your organization" link.
"What's our margin on this model?" typed into Dynamics Copilot by an over-scoped service rep returns the real cost-and-margin number.
Copilot returns a vendor's bank account to a non-finance user — payment-fraud exposure in one conversational answer.
One forgotten app consent can read every mailbox and every SharePoint site — no user, no conditional access anywhere in the path.
A custom RAG assistant answers from a flattened corpus — once documents are embedded, the source ACL is gone, so a low-privilege user gets crown-jewel content. No native tool measures this.
A departed employee's account still works — and the audit log proves an automated client already used it.

This is not an argument against AI

Copilot, Agentforce, and the agents you build do exactly what they're designed to — answer from what the user can access. They're not the problem; they're extraordinary. The over-permissioning was already there, accumulated over years. AI simply makes it instantly, fluently queryable. Tasirio exists to help you adopt AI faster and with confidence — turning "we're not sure what it can see" into "here's exactly what it can reach, and here's what we closed" — so the rollout goes ahead instead of stalling in a security review.

Why this maps directly to compliance

AI over-reach isn't just a security problem — it's a governance-and-audit problem. Tasirio maps every finding to the obligations it implicates, so the same read-only scan doubles as evidence for:

EU AI ActNIST AI RMFISO/IEC 42001:2023OWASP LLM Top 10GLBA / PCI-DSS (where applicable)

Findings carry a tamper-evident (SHA-256) evidence chain, per-finding "who should actually see this" verdicts, and the exact accounts to remediate — an auditor-grade record, not a screenshot.

Framework names (EU AI Act, NIST AI RMF, ISO/IEC 42001:2023, OWASP LLM Top 10, PCI-DSS) are the property of their respective organizations and are referenced descriptively to indicate the obligations Tasirio helps assess. Tasirio is an independent product — not affiliated with, endorsed, approved, or certified by any of these organizations — and a Tasirio assessment is not a formal conformity assessment or certification.

Read-only by design

Everything above is computed from metadata — the locks and keys, never the content. Least-privilege, read-only scopes; the consent screen shows exactly what's requested; revocable anytime. Tasirio reads who can reach what — never what's inside.

What's next: from landscape to benchmark

This report describes the anatomy of AI exposure — the surfaces and patterns Tasirio assesses. As we complete more read-only assessments, these become a live, anonymized benchmark: "how does your AI-exposure surface compare to peers in your industry?" — reported only in aggregate, never identifying any organization. If you'd like to be part of that cohort, an assessment is the way in.