Govern SharePoint-Grounded Agents
Reduce oversharing and grounding-data exposure for agents that ground on SharePoint — find overshared sites, restrict what agents can discover and access, and protect the sensitive data behind them.
Core capabilities
-
Find the overshared, sensitive, ownerless, or inactive sites Copilot could surface, using Data Access Governance reports and the Content Management Assessment
-
Exclude sensitive sites from Copilot and agent discovery while you remediate, without changing their permissions
-
Lock a site down to a specific group so users outside it — and agents acting for them — cannot reach it, even through old links
-
Add a Microsoft 365 Copilot DLP policy so agents cannot process files carrying sensitive labels when grounding on SharePoint
Supporting capabilities 8
-
Rely on the baseline that a SharePoint agent only returns content the requesting user can already access
-
Tighten organization- and site-level sharing defaults to shrink the oversharing surface at the source
-
Retire or attest stale and ownerless sites so obsolete content leaves the discoverable surface
-
Archive inactive sites to a cold-storage tier that Copilot never uses
-
Label and encrypt sensitive content so agents cannot process it even when it sits in a discoverable site
-
Carry the source sensitivity label onto agent responses and generated files so protection follows content out of SharePoint into the AI output
-
Discover which sensitive data is actually flowing through agent interactions to prioritize remediation
-
Investigate oversharing, sprawl, and access risks through natural-language queries and follow guided remediation before opening SharePoint to agents