AI data access audit NZ

AI Data Access Audit NZ: What to Check Before Staff Connect AI to Company Files

Check what AI can see before you connect business tools

Before connecting AI to company files, an NZ business should audit who can access sensitive documents, which tools AI may read, what staff may paste into prompts, what outputs need review, and how access is logged or revoked.

An AI data access audit reviews the information AI could reach through staff accounts, connected apps, folders, inboxes, CRM records, and custom agent permissions. It does not certify security. It finds access risks before AI makes them easier to surface or reuse.

If you are planning Copilot, Google Workspace AI, ChatGPT use, or a custom agent, start by naming one workflow and checking the data it needs. The $1,000 AI Agent Assessment maps the workflow, sources, permissions, approval gates, and safe next step.

What is an AI data access audit?

An AI data access audit checks what information people and AI-enabled tools can reach, whether that access is appropriate, and what should stay restricted, read-only, draft-only, or human-approved.

The plain-English definition for business owners

In plain English, the audit asks: if staff or AI searches, summarises, drafts from, or connects to this information, what could it see and do next?

It covers files, CRM notes, inboxes, calendars, meeting notes, exports, HR folders, website systems, templates, and third-party tools.

Why AI makes old permission problems visible

AI usually does not create permission problems from nothing. It makes existing problems visible: overshared folders become searchable, outdated templates get reused, and broad CRM exports feed sensitive drafts.

Run the audit before a broad rollout, not after staff have connected tools.

What AI might access in a normal business

Most access risk sits in everyday systems, not exotic AI infrastructure. Start with the tools your staff already use.

SharePoint, OneDrive, Teams, and Microsoft 365

Check shared folders, Teams channels, meeting recordings, templates, board papers, archived projects, staff files, client folders, and inherited permissions. If staff use Microsoft 365, compare the audit with the Microsoft 365 Copilot Governance Checklist.

Google Drive, Gmail, Calendar, and Workspace tools

Review shared drives, document links, Gmail labels, calendar visibility, Meet notes, Docs, Sheets, and Chat history. If the business uses Gemini or Workspace AI, use the Google Workspace AI Governance Checklist.

CRM records and sales notes

CRM data can include lead sources, pricing context, complaints, relationship notes, proposal history, and permission signals. A sales agent may need some context, but not broad access by default.

Website, CMS, analytics, and SEO systems

Website agents may read public pages, forms, analytics summaries, approved offer copy, issue queues, and schema. They should not publish, change pricing, edit forms, alter tracking, touch DNS, or invent proof without review.

Finance, HR, contracts, and client files

Finance, HR, contracts, disputes, credentials, and confidential client material need stronger rules. For many first pilots, exclude these sources or use a human-prepared summary.

The AI data access audit checklist

Use this checklist before connecting AI to live company systems.

1. List approved AI tools and accounts

Name approved AI tools, account owners, whether business data can be entered, and whether personal accounts are allowed. If unapproved AI use is common, read the Shadow AI policy guide before expanding access.

2. Identify sensitive folders and records

Mark customer, staff, finance, legal, commercial, strategy, credential, and confidential project information. Decide whether each source is allowed, restricted, excluded, or human-summarised. If personal information is involved, run an AI Privacy Impact Assessment NZ before connecting tools.

3. Find “everyone” or broad staff permissions

Look for folders, drives, channels, dashboards, or exports visible to wider groups than intended. Broad access is convenient until AI makes search and summarisation easier.

4. Separate read-only access from edit, send, or publish access

Reading a source is not the same as changing it. Separate read, draft, recommend, update, send, publish, delete, admin, and blocked permissions with the AI Agent Permissions Checklist.

5. Decide what staff must not paste into AI tools

Write simple prompt rules for customer information, staff information, contracts, pricing, credentials, finance data, private disputes, and confidential strategy.

6. Set approval gates for customer-facing outputs

AI-prepared customer emails, proposal wording, public copy, pricing, promises, reports, legal wording, HR material, or privacy statements should stay human-approved. Use AI Approval Gates for Business Automation for the stop points.

7. Log exceptions and revoke unused access

Record unusual access, incorrect outputs, staff questions, incidents, and permissions no longer needed. Remove stale accounts, old contractors, unused integrations, and abandoned exports.

Copilot, Google Workspace AI, ChatGPT, and custom agents: what changes?

The audit changes by tool because each tool reaches business information differently.

Copilot can surface Microsoft 365 permission problems

Copilot-style workflows make Microsoft 365 access hygiene more important. Check whether the right people can see the right files before AI helps them find those files faster.

Google Workspace AI needs Drive and Gmail rules

Workspace AI may touch Drive, Docs, Sheets, Gmail, Meet, Calendar, and Chat. Define approved folders and draft-only outputs.

ChatGPT needs staff prompt and data-entry rules

ChatGPT use often starts with copy-paste. Define what staff may paste, what must be redacted, which outputs need review, and when an approved business workflow is required.

Custom agents need scoped tool permissions

A custom agent may connect to CRM, inbox, website, finance, project, or reporting systems. Give it the lowest useful permission first.

What to fix before connecting AI to live workflows

The audit should produce a practical cleanup list, not a vague warning.

Clean folder permissions

Fix broad access on sensitive folders, archive old material, remove stale sharing links, and separate current source documents from outdated references.

Name source-of-truth documents

AI should know which offer page, policy, SOP, template, FAQ, price note, or CRM field is current. If sources conflict, the workflow should flag uncertainty. Use the AI Data Readiness Checklist for NZ Businesses when source quality or ownership is unclear.

Remove stale access

Review ex-staff, old contractors, unused integrations, shared inboxes, API keys, exports, and personal-account workarounds. Remove or narrow access that no longer supports a current workflow.

Define human review rules

Decide who reviews AI output, what they check, where approval is recorded, and which exceptions require escalation.

How an AI Agent Assessment turns access risk into a workflow map

The AI Agent Assessment turns the access audit into a decision for one real workflow.

What the agent may read

The assessment names approved and excluded sources: folders, pages, CRM fields, exports, SOPs, reports, or inbox labels.

What the agent may prepare

The agent might prepare summaries, checklists, draft replies, CRM notes, exception lists, briefs, or website recommendations.

What the agent may update

Most first workflows should avoid live updates. If updates are useful, start with low-risk internal notes before changing customer records, public pages, pricing, or permissions.

What must always stay human-approved

Customer communication, pricing, legal wording, HR decisions, finance actions, privacy commitments, public publishing, access changes, and sensitive updates should stay human-approved.

Frequently asked questions

What should an AI data access audit include?

It should include approved AI tools, sensitive sources, folder permissions, CRM access, inbox rules, prompt restrictions, read versus edit permissions, approval gates, logs, and access removal.

What can Microsoft Copilot see in a business?

Copilot-style access depends on the Microsoft 365 environment, user permissions, configuration, and connected data. Review SharePoint, OneDrive, Teams, meetings, and file permissions before broad rollout.

Should staff paste customer information into ChatGPT?

Not by default. Staff need clear rules for customer, staff, finance, legal, credential, and confidential information. Sensitive context needs an approved workflow and review.

Is read-only AI access safer than edit access?

Read-only access is usually lower risk than edit, send, publish, delete, or admin access, but sensitive information can still be exposed through summaries or drafts.

Who should approve AI access to CRM, files, or email?

The workflow owner should approve it with input from the data-source owner: often the business owner, operations lead, sales lead, finance owner, privacy owner, or IT provider.

Next step

Do not connect AI to company files as an experiment. Choose one workflow, name the sources, remove unnecessary access, define what AI may prepare, and keep consequences human-approved.

Book the $1,000 AI Agent Assessment to map one workflow’s data sources, permissions, approval gates, and safe next step before connecting AI to business systems.