Skip to content

Guide

Questions to ask before AI reads your company files.

About 7 minutes

The problem.

Someone on your team found an AI tool that can read your SharePoint. It looks useful. Before you click Accept, you want to know what you are agreeing to. This checklist works for any AI tool, including Microsoft’s and ours. You need the vendor to answer each question separately.

Where are files stored, and where are requests processed?

These are two different questions. Storage is where your documents live. For most Microsoft 365 companies, that is SharePoint, OneDrive and Outlook.

Processing is what happens when someone asks a question. The AI has to read the question, pull in relevant text from your files and write an answer. That work happens on a computer somewhere, run by someone. A tool can leave your files where they are and still send questions and excerpts to an AI service to be answered.

  • Which services receive my questions?
  • Which services receive text from my files to answer them?
  • Can I see which service handled a given request, or only a list of possible ones?

Does it only show people what they can already open?

A good AI tool follows the permissions you already set. If Dana cannot open the payroll folder, the AI should not quote payroll to Dana. Microsoft states this for its own Copilot: it only surfaces organizational data that the person has at least view permission for.

There is a catch. An AI that respects permissions also respects bad permissions. If a salary spreadsheet was shared with the whole company by mistake three years ago, an AI will find it faster and summarize it. Microsoft’s own setup guidance starts with finding and fixing overshared sites.

  • Does the tool check permissions for each person, or does it read everything through one shared account?
  • What happens when someone loses access to a file? Does the AI stop showing it?
  • What should we clean up before we connect it?

Is my data used to train AI models?

“We don’t train on your data” is a common answer. Check who “we” is. Many AI tools send requests to an AI provider they do not own. The tool vendor’s promise covers the tool vendor. The provider’s promise covers the provider, for the service and terms you are actually on.

Microsoft, for example, says Copilot prompts, responses and the data it reads through Microsoft Graph are not used to train foundation models. That describes Microsoft’s Copilot services. It does not describe any other vendor’s tool, even one built on Microsoft 365.

  • Which company makes the promise, and for which service?
  • Does it cover my questions, the answers and the file text sent along with them?
  • Is it in the contract or only on a web page?

What is kept, and for how long?

Not training on your data is different from not keeping it. AI tools often keep chat history so you can go back to an earlier answer. They may keep logs for troubleshooting, abuse detection or billing.

  • Are my questions and answers saved? Where, and for how long?
  • Are copies of file text saved anywhere, such as a cache or a search index?
  • Can a user delete their own history? Can an admin?
  • Are there logs that stay after history is deleted?

Does the vendor record screens or usage?

Many software products use analytics. Some record sessions: a replay of what appeared on screen. This is separate from the AI. A vendor can truthfully say it does not keep your files and still record the screen where an answer was displayed.

  • Do you record sessions on your website or inside the app?
  • If so, is on-screen business content hidden, or only passwords?
  • Can we turn recording off? Who can watch the recordings, and how long are they kept?

What happens when we cancel, disconnect or ask for deletion?

Cancelling, disconnecting and deleting are three different outcomes. Get an answer for each.

  • Cancel. Does the tool stop working immediately or at the end of the billing period? Do files it created stay in your Microsoft 365?
  • Disconnect. How do we remove it from our tenant? Does removing it stop all future access?
  • Delete. Which records does the vendor still hold after cancelling: account details, billing records, chat history, analytics, support tickets? Which can we ask them to delete, and which do they keep by law or policy?

A vendor that says your files stay yours may be answering the first question only.

Who else handles our data?

Most software companies use other companies to run their service: hosting, databases, payments, email, analytics and AI providers. These are usually called subprocessors. Commitments can differ even inside one provider. Microsoft’s documentation says Copilot web search queries are handled under different terms from prompts and responses.

  • Is there a published list of subprocessors, with what each one does?
  • Which of them receive our questions, file text or screen recordings?
  • Will you tell us before adding a new one?

What are we being asked to approve?

When an app connects to your Microsoft 365, it asks for permissions. Some can be accepted by a regular user. Others need an administrator to consent for the whole organization. An admin who consents on behalf of the organization approves that access for everyone, not only themselves.

  • What is the full list of permissions, in plain words? Read, write, send, delete?
  • Does the app act as each signed-in person, or as itself with its own access?
  • Why does it need each one? What stops working if we decline?
  • Who in our company should approve this, and how do we remove it later?

The one-page version.

Bring this to the demo. A vendor that has done the work can answer each row in a sentence or two. If an answer is “it’s all private” or “you’re fully covered,” ask the question again, more specifically.

TopicAsk
ProcessingWhich services receive our questions and file text?
PermissionsDoes it follow each person’s permissions? What should we clean up first?
TrainingWho promises not to train on our data, for which service, in which contract?
RetentionWhat is saved, where, for how long, and who can delete it?
RecordingAre sessions or screens recorded? What is hidden?
ExitWhat happens on cancel, on disconnect and on a deletion request?
SubprocessorsWho are they, and which ones see our content?
ConsentWhat permissions does it request, and does it need admin consent?

Sources

Where this comes from.

More guides

Also worth a few minutes.

  • Which version did we send?

    Find the attachment you actually sent. Search Sent Items in Outlook, see why FINAL filenames lie, and set a naming rule that ends the question.