Legal Technology

Before Giving an AI Agent Access to Your Law Firm: What Should It Be Allowed to See?

Law firms considering AI agents usually start by looking at what the technology can do. The great thing about an AI agent is that it does not have to manually hunt through five different places to find information. It can work across email, documents, calendars, matter folders and other systems the firm already uses. That is also where the access problem starts. Once an agent is connected to Microsoft 365, it may be able to reach far more information than the person setting it up expected, especially in firms where SharePoint sites, Teams folders and user permissions have accumulated over several years.

5 min read

Law firms considering AI agents usually start by looking at what the technology can do. The great thing about an AI agent is that it does not have to manually hunt through five different places to find information. It can work across email, documents, calendars, matter folders and other systems the firm already uses. That is also where the access problem starts. Once an agent is connected to Microsoft 365, it may be able to reach far more information than the person setting it up expected, especially in firms where SharePoint sites, Teams folders and user permissions have accumulated over several years.

For many firms, answering that question requires looking at permissions that were created years before anyone was thinking about AI. SharePoint sites may have been shared with broad groups. Old Teams workspaces may still contain client files. OneDrive folders may hold documents that should have been transferred into a matter workspace. People who changed roles may still belong to security groups they no longer need. Microsoft specifically recommends assessing overshared information and limiting access to users who need it when preparing Microsoft 365 environments for Copilot and agents.

AI Agents Can Expose Permission Problems That Have Been Sitting Unnoticed

An employee generally searches for information when there is a reason to look for it. That limits how often an overly broad permission gets noticed. A lawyer who has technical access to hundreds of folders may only work inside five of them during a normal week.

An AI agent can work differently. If it has permission to search a large SharePoint environment, mailbox or collection of connected data, it can retrieve information from those locations quickly and combine information that previously sat in separate places. A permission that looked harmless when employees were browsing files manually can become more significant once software can search, summarize and use those files at scale.

Microsoft's current Copilot security guidance specifically identifies oversharing as an issue organizations should assess before wider deployment. SharePoint Advanced Management and Microsoft Purview can be used to identify potentially overshared sites, review access and restrict content discovery while permissions are being corrected.

The concern is particularly important for law firms because Microsoft 365 often contains several categories of sensitive information in the same tenant. Client matter files may sit alongside billing records, internal financial information, employee documents, partner communications and administrative material. Giving an agent access to Microsoft 365 should therefore begin with understanding where those categories of information are stored and who can already reach them.

That review also has a professional-responsibility dimension. The American Bar Association's Formal Opinion 512 states that lawyers using generative AI tools must consider existing duties including competence, confidentiality, supervision and the protection of client information. An AI project within a law firm should account for those obligations before client information becomes part of an automated workflow.

Start With the Agent's Job

A useful way to design permissions is to define the agent's job before connecting data sources. Consider an AI agent built for new-client intake. It may need access to an intake mailbox, the firm's CRM, conflict-checking information and a set of approved templates. Giving the same agent access to every active matter in SharePoint would usually add little value to that workflow.

A matter-reporting agent is different. It might need access to documents and correspondence for a specific matter or practice group, but there may be no reason for it to search employment records or the firm's accounting files. An internal knowledge agent could be limited to firm policies, training materials, approved precedents and internal guidance.

Thinking about AI agent permissions this way gives the firm a clearer question to answer. Instead of asking whether an agent should have access to SharePoint, determine which SharePoint sites, libraries or folders it needs to perform its assigned work.

Microsoft provides several controls that can support this structure. Microsoft Entra can manage identities, groups and access. Microsoft Purview provides information protection, auditing and data-governance capabilities. Copilot Studio also supports controls over knowledge sources, connectors, sharing and data policies. Microsoft recommends limiting connectors and settings to those required for a particular agent project. Those products provide the controls. The firm still needs to decide what access makes sense.

Reading Information and Taking Action Should Be Treated Differently

There is another distinction that becomes important as law firms move beyond basic AI assistants. An agent that can read information presents one level of risk. An agent that can change information or communicate externally presents another.

For example, a firm might be comfortable allowing an agent to review matter information and prepare a draft status summary for a lawyer. Allowing the same agent to send that summary directly to the client creates a different workflow. Similar questions arise when an agent can create documents, move files, modify records, schedule meetings, initiate approvals or trigger another application.

These capabilities should be reviewed separately. A useful AI agent does not need unrestricted authority simply because the underlying technology supports it. Microsoft's Copilot Studio governance framework allows administrators to control which connectors and knowledge sources are available, restrict agent sharing and separate environments according to their purpose and risk. Microsoft also recommends isolating development, testing and production environments when managing agents.

For law firms, human approval can remain part of workflows where the consequence of an error is higher. An agent could prepare a client email without being permitted to send it. It could identify documents requiring attention without being allowed to delete or move them. It could draft an update to a matter record while requiring a user to approve the change.

Old Microsoft 365 Permissions Deserve Another Look Before Copilot Deployment

AI projects often uncover problems that have little to do with AI itself. A SharePoint site created six years ago may still grant access to an organization-wide group. A lawyer who moved practice groups may continue to have access to matters from the former team. A departed employee may have owned folders, workflows or shared resources that were never properly reassigned. Duplicate client files may exist across Teams, SharePoint and individual OneDrive accounts.

These are standard Microsoft 365 governance problems. AI makes cleaning them up more important because agents can rely on the same information environment.

This is why an effective Microsoft Copilot readiness review should extend beyond purchasing licenses and enabling features. Firms should understand their Entra ID groups, SharePoint permissions, OneDrive sharing, Teams membership, data classifications and administrative roles before allowing AI agents to work broadly across the tenant.

Microsoft recommends using data-access governance reports to identify potentially overshared SharePoint sites and conducting access reviews with site owners. Its guidance also recommends removing unnecessary organization-wide access and using sensitivity labels or access restrictions where appropriate. For many firms, that work improves the environment even before an AI agent is deployed.

Test a Narrow AI Agent Before Expanding Access

A smaller deployment makes it easier to see how an agent behaves with real law-firm information.

Suppose a litigation team wants an AI agent to prepare an internal daily matter summary. The first version could be connected to one controlled SharePoint matter workspace and made available to a small group of users. The firm can then see what information the agent retrieves, whether its answers stay within the intended data set and which activities appear in audit records.

The same test can reveal permission issues that were previously difficult to spot. If an agent retrieves a document from another matter, the problem may be the underlying access configuration. If confidential administrative information appears unexpectedly, the firm can trace why the agent had permission to reach it before expanding deployment.

Once the boundaries are working properly, additional sites, workflows or actions can be introduced gradually. Microsoft's current Copilot Studio guidance supports this type of segmented approach by allowing organizations to apply different governance policies according to an agent's purpose and risk level.

Five Questions to Answer Before Giving an AI Agent Access

Before an AI agent starts working with client or firm information, the team responsible for the deployment should be able to answer 5 questions clearly:

1. What systems can the agent access?

2. What information inside those systems can it retrieve?

3. Which identity or user permissions determine what it can see?

4. What actions can the agent perform after it finds the information?

5. Where can administrators review what the agent has done?

If any of those answers are unclear, there is probably still work to do in the Microsoft 365 environment before the agent is opened up more widely.

In practice, many law firms find that the AI project becomes a useful reason to clean up issues that have been sitting in Microsoft 365 for years. Old permissions get reviewed. SharePoint sites are reorganized. Access for former employees or old practice groups is removed. Sensitive information is separated more carefully. The result is a better foundation for AI, but also a cleaner and more manageable IT environment in general.

AKAVEIL TECHNOLOGIES works with law firms on Microsoft 365, cybersecurity, cloud infrastructure and AI readiness, including the access and governance issues that often surface before Copilot or AI agents are rolled out. If your firm is considering Microsoft 365 Copilot, Copilot Studio or another AI workflow and you want to understand what the technology will be able to see inside your existing environment, contact AKAVEIL or write to info@akaveil.com.

About Ariel Perez

Ariel Perez is the Founder and CEO of AKAVEIL Technologies, where he works with law firms on Microsoft 365, cybersecurity, cloud infrastructure and AI readiness. His work often involves reviewing the systems, permissions and access controls that sit underneath tools such as Microsoft Copilot and other AI workflows.

With nearly two decades of experience in IT, cloud infrastructure and cybersecurity, Ariel helps law firms understand how new technology interacts with the environment they already have in place, including SharePoint, OneDrive, Teams, Microsoft Entra and other parts of Microsoft 365.

For questions about Microsoft 365, AI readiness or cybersecurity for your law firm, contact Ariel and the AKAVEIL team at info@akaveil.com.

Ariel Pérez

About the Author

Ariel Pérez

Founder & CEO of AKAVEIL Technologies, Ariel brings nearly two decades of expertise in IT, cloud infrastructure, and cybersecurity exclusively for law firms. He specializes in Microsoft 365, Azure Virtual Desktop, and AI-driven automation, helping legal organizations transition from legacy systems to modern cloud platforms. Ariel's deep understanding of legal workflows and hands-on technical approach makes him a trusted advisor for law firm leadership seeking to enhance security, compliance, and operational efficiency.

Related Service

Microsoft 365 Copilot

AI-powered productivity solutions integrated with Microsoft 365 for law firms.

Learn More

Ready to Secure Your Law Firm?

Let AKAVEIL help you implement comprehensive cybersecurity solutions.

Schedule Consultation

Continue Reading

Explore more insights on legal technology and IT solutions.

AI
Chat with AI Assistant