
Permissions Audit for Small Business: Why AI Made It Urgent
- AI tools like Microsoft Copilot inherit user permissions — if access is sloppy, the AI surfaces everything (Microsoft)
- 88% of organizations have stale “ghost” user accounts still enabled in their environments (Varonis, 2025)
- A permissions audit reviews who has access to what — and removes what they don’t need
- The principle of least privilege is the fix, and most SMBs have never applied it
Ninety-nine percent of organizations have exposed sensitive data that can be surfaced by AI tools, according to Varonis’s 2025 State of Data Security Report. That number isn’t an enterprise-only problem. If your business uses Microsoft 365 or Google Workspace and has connected any AI assistant — Copilot, Gemini, ChatGPT — those tools now have access to everything your users can see.
For most small businesses, that’s far more than anyone realized. Files from three employees ago. A shared drive that was supposed to be temporary. A contractor account that never got shut down. None of this was urgent when only humans were browsing folders. Now that AI can search, summarize, and surface anything it has access to, the mess becomes visible — and risky.
A permissions audit is how you find out what’s actually exposed. And for most small businesses, it’s the first time anyone has looked.
What Is a Permissions Audit?
A permissions audit is a structured review of every user account, shared drive, and application in your business to answer one question: who has access to what, and should they? It covers file storage, email, line-of-business apps, and any third-party tools connected to your environment. The output is a clear map of your current access structure — and a list of what needs to change.
This is different from a security scan or vulnerability assessment. Those look for external threats. A permissions audit looks inward — at the access your own people have accumulated over time. It checks for former employee accounts that were never deprovisioned, shared folders with no access restrictions, and users whose roles changed but whose permissions didn’t.
Think of it as a financial audit, but for data access. You’re verifying that the current state of things matches what it should be. Running a permissions audit is one of the most impactful security steps a small business can take — and one of the least common.
Why Most Small Businesses Have Never Done One
Only 38% of small and mid-sized businesses have a formal vulnerability management program in place, according to NinjaOne’s 2026 SMB cybersecurity data. Permissions reviews are even rarer. The reason is straightforward: until recently, there was no forcing function.
When a small business starts out, everyone shares everything. The owner creates a shared drive, gives everyone access, and moves on. People join, people leave, and nobody goes back to clean up. An employee moves from sales to operations but keeps access to the sales pipeline. A temporary contractor gets full access to the file server because it’s easier than setting up limited permissions. Over months and years, access accumulates with no process to reduce it.
This is sometimes called “permission sprawl” or “identity sprawl,” and it’s the default state for nearly every business under 50 employees. It wasn’t treated as a risk because the consequences were theoretical. That changed when AI entered the picture.
How AI Tools Exposed the Permissions Problem
Research from Concentric AI found that 16% of business-critical data is overshared in the average organization, with roughly 802,000 files at risk per company. That oversharing existed before AI. But AI made it dangerous by making it searchable.
When you connect Microsoft Copilot to your 365 environment, it inherits the permissions of the user it’s assigned to. It doesn’t apply its own judgment about what’s appropriate. If a user can view an HR document, Copilot can summarize it. If a departed employee’s account is still active and has broad access, any AI tool tied to that account can query across it.
This is why the Microsoft 365 team published specific guidance on mitigating oversharing before Copilot deployment. It’s also why the U.S. House of Representatives banned staff from using Copilot due to concerns about data leaking to unauthorized cloud services.
The AI didn’t create the problem. It revealed it. And for many small businesses, it was the first time anyone noticed how wide open their file access really was.
What Permission Sprawl Actually Looks Like
Varonis’s research across 1,000 IT environments found that 88% of organizations have stale but enabled “ghost” user accounts, and 66% have cloud data exposed to anonymous users (Varonis, 2025). In our work with Colorado small businesses, we see these patterns constantly. How many former employees still have active accounts in your system? Here’s what permission sprawl typically looks like:
- The departed employee. A bookkeeper left 18 months ago. Their Microsoft 365 account is still licensed and active. They still have access to the accounting folder, the shared QuickBooks file, and the HR drive. If Copilot is deployed to that tenant, it can query all of it.
- The shared drive with no boundaries. When the company was five people, a single shared drive made sense. Now there are 20 employees and the drive contains HR files, client contracts, financial documents, and internal memos — all visible to everyone.
- The contractor who never got cut off. A web developer was given admin access to the Microsoft 365 tenant to set up email. The project ended, but the account was never disabled. It still has global admin privileges.
- The role change. A team lead moved from operations to marketing. They kept all their old access and gained new access for their new role. They can now see files across both departments — not because anyone decided they should, but because nobody revoked the old permissions.
None of these scenarios involve malicious intent. They’re all the result of normal business operations without a process for access management. In our experience, most businesses under 25 employees have at least two or three of these issues when we run their first audit.
What a Basic Permissions Audit Covers
Up to 74% of data breaches involve privileged access misuse, often by insiders or former employees (Secureframe, 2025). A permissions audit is designed to close those gaps before they become incidents. While the specific tools vary by platform, the framework is consistent:
| Audit Step | What It Checks | Common Findings |
|---|---|---|
| User Account Inventory | All active accounts across platforms | Ghost accounts from former employees |
| Access Mapping | What each user can see vs. what they need | Users with access far beyond their role |
| Shared Resource Review | Drives, SharePoint, Teams sharing settings | “Everyone” or public link sharing enabled |
| Third-Party App Permissions | OAuth/API connections to your environment | Unsanctioned apps with data access |
| Remediation Plan | Action items and documentation | No baseline documentation existed |
1. User Account Inventory
List every active account across Microsoft 365, Google Workspace, and any line-of-business apps. Flag accounts that belong to former employees, inactive users, or generic shared logins. This alone often reveals surprises — most businesses find at least one account they forgot to disable.
2. Access Mapping
For each active user, document what files, folders, applications, and admin roles they can access. Compare that to what they actually need for their current role. The gap between “has access to” and “needs access to” is where the risk lives.
3. Shared Resource Review
Review every shared drive, SharePoint site, and Teams channel. Identify resources shared with “Everyone” or “Anyone with the link.” Check external sharing settings — file storage that’s been shared broadly is one of the most common exposure points.
4. Third-Party App Permissions
Check which third-party apps have been granted access to your environment via OAuth or API connections. Varonis found that 98% of organizations have unverified apps, including unsanctioned AI tools, connected to their data. Each one is an access point that should be reviewed.
5. Remediation Plan
Disable stale accounts. Reduce over-permissioned users. Tighten shared resource access. Document the results so the next review has a baseline to compare against.
The Principle of Least Privilege — and Why It Matters Now
The principle of least privilege means every user gets exactly the access they need to do their job — nothing more. Fortinet defines it as one of the foundational controls for reducing insider risk, and it’s a core component of zero-trust security frameworks.
For small businesses, this doesn’t mean buying enterprise identity management software. It means applying role-based access controls — grouping permissions by job function instead of assigning them individually. A marketing coordinator gets access to the marketing folder, the social media tools, and the CMS. Not the accounting drive. Not the HR folder. Not the admin console.
This matters more with AI in the picture because AI tools amplify access. A human might never browse into the finance folder even though they have access. But Copilot, if asked “find the most recent budget,” will surface it instantly if the permissions allow it. Least privilege shrinks the blast radius of every account — whether it’s used by a person or an AI assistant.
Pairing least privilege with multi-factor authentication and a solid onboarding and offboarding process closes the three biggest access gaps most SMBs have.
Who Should Handle Your Permissions Audit?
Businesses with 5–25 employees rarely have dedicated IT staff, and permissions management isn’t something most office managers are trained for. Running an audit in Microsoft 365’s admin center or Google Workspace’s admin console is possible, but interpreting what you find — and knowing what to change without breaking workflows — takes experience.
This is one of the reasons managed IT providers include permissions reviews as part of ongoing service. A provider who already manages your environment can run a permissions audit faster and with less disruption because they have the context for how your systems are set up.
At Engel Tech, we run permissions audits for Colorado small businesses as part of our managed IT services. If you’ve connected an AI tool to your Microsoft 365 or Google environment — or you’re thinking about it — a permissions review should happen first. Not after. Reach out and we’ll help you see what’s actually exposed.
Frequently Asked Questions
What is a permissions audit?
A permissions audit is a structured review of every user account in your business systems to determine who has access to what files, folders, and applications. The goal is to verify that each person only has the access they need to do their job — and that former employees, contractors, and outdated roles have been cleaned up.
How often should a small business run a permissions audit?
Most small businesses should run a permissions audit at least twice per year, with additional reviews after any employee departure, role change, or new software deployment. Businesses using AI tools like Microsoft Copilot or Google Gemini should audit quarterly, since these tools amplify the impact of any existing oversharing.
Does Microsoft Copilot access files beyond what a user can see?
No. Microsoft Copilot inherits the exact permissions of the user it is assigned to. It cannot access files the user cannot access. However, this is precisely the problem — most users have far more access than they actually need, and Copilot surfaces that over-access by making it searchable and queryable.
What is the principle of least privilege?
The principle of least privilege means every user account should have the minimum level of access required to perform their job — nothing more. It is a foundational security practice that reduces the damage any single compromised or misused account can cause, and it is especially important when AI tools are connected to business data.
Can a small business do a permissions audit without an IT provider?
Technically yes, but it is difficult without the right tools. Microsoft 365 admin center and Google Workspace admin console allow you to review user access, but interpreting what you find — especially across shared drives, third-party apps, and legacy accounts — requires experience. Most small businesses benefit from professional IT support for their first audit.
Engel Tech provides IT compliance support for Colorado businesses including permissions audits, access documentation, and ongoing access management. Serving Denver, Aurora, Centennial, Lakewood, and the greater Front Range.