Skip to content
All articles

AI answers from your documents, with the right access

Help people find answers in business documents without giving everyone access to everything. Start with current sources, permissions and useful tests.

On this page
  1. Begin with questions people already ask
  2. Check the options in your current software
  3. Permissions need to mean what you think they mean
  4. Ask for a useful answer shape
  5. Test with different people
  6. Decide whether the work is easier

Someone asks which onboarding checklist to use. A colleague finds a file. Another colleague has a newer version.

The answer exists. Finding the answer is the job.

For an established business, AI search can be worth exploring here. You ask a question in ordinary language and get an answer linked to your own documents.

The useful part is getting back to the right source. Access, accuracy and ownership still need attention.

Begin with questions people already ask

Pick a small area of work. Customer onboarding, service procedures or approved product information can give you a clear starting point.

Ask the people doing that work what they keep searching for. Write down their actual questions. “Where is the latest checklist?” is a better test than “Tell me about our business.”

For each question, name the document that should answer it. Add the person who owns that document and the date it was last checked.

If nobody can identify the right source, fix that first. An AI answer cannot settle an internal disagreement about which process applies.

Check the options in your current software

Microsoft’s work-connected Copilot uses information from Microsoft Graph, including documents the user has permission to access. Microsoft says it only surfaces organisational information the individual can view. Microsoft’s data and permissions guidance.

ChatGPT’s company knowledge is another option for eligible Business, Enterprise and Edu workspaces. It can answer using connected sources and provide citations. OpenAI says it respects the user’s existing permissions. Supported apps and workspace configuration determine what is available. Company knowledge in ChatGPT.

These are starting points for an evaluation. You do not need a custom knowledge system just because your documents belong to your business.

Check the exact account before buying or connecting anything. OpenAI distinguishes live SharePoint access from administrator-managed indexing. The latter is a separate feature for eligible Enterprise and Edu workspaces. A personal connection does not create a personal synced index. SharePoint setup in ChatGPT.

Permissions need to mean what you think they mean

An assistant can respect the file permissions and still reveal something you did not intend everyone to see. That happens when the original file is already shared too widely.

Review the source folders with whoever looks after your systems. Check broad sharing links, old project groups and guest access. Microsoft’s preparation guidance specifically includes finding and addressing overshared content. Preparing SharePoint for Copilot.

Keep the existing access boundaries when choosing a tool. Ask the supplier how each person’s permission is checked when a document is retrieved.

Avoid taking a collection of restricted files and putting them into a common folder simply to make the demonstration work. Also avoid relying on a prompt that says certain people must not see certain documents. The access check belongs in the system.

Ask for a useful answer shape

A short answer with a relevant source is easier to check than a confident page of explanation.

Here is a prompt to adapt once the approved sources are connected:

Find the current approved customer onboarding checklist I can access.

Give me:
- The steps the document says I should follow.
- A link to the source for those steps.
- Its review date or version, if stated.
- Any missing information or conflicting instructions.

Do not fill gaps with a general onboarding process.
If the available sources do not answer the question, say so.

Open the linked document. Check that it supports the answer, rather than simply mentioning the same topic.

If two sources disagree, the answer should make that visible. Then the document owner can resolve it. Hiding the disagreement in a smooth summary would make the problem harder to spot.

Test with different people

An administrator’s successful test tells you little about an ordinary colleague’s experience.

Try the same questions with people who have different authorised access. Use harmless test documents when checking restricted access. A person outside the test group should not receive the restricted answer or excerpts from its source.

Include questions the documents cannot answer. The assistant should explain the gap rather than invent a company rule.

Then change a test document and remove a test user’s access. Check what happens in a fresh conversation. Ask your supplier how updates, indexing and previously generated answers are handled. Do not assume that removing source access erases text already shared elsewhere.

For a reading-only trial, keep file-changing actions disabled where the product allows it. Search access and permission to edit documents are separate decisions. OpenAI’s SharePoint guide describes separate controls for live actions and indexed content. SharePoint permissions and actions.

Decide whether the work is easier

Compare the trial against finding the document normally. Include the time spent opening citations, correcting answers and maintaining the sources.

Watch for repeated missing answers, outdated instructions and unexpected access. If those keep appearing, improve the document set before widening the rollout.

Assign someone to keep the sources current and review reported mistakes. A smaller collection that people can trust is a useful place to start.

If you want help choosing that starting point, explore the Workflow Review. We can look at the recurring questions, the available documents and the access boundaries before recommending a build.

Tool documentation checked on 7 September 2026. Availability and administrator controls vary by plan and can change.