It only sees your slice: how permissions shape what your work assistant tells you
Overview
When your employer’s assistant can “ask across all of work” — email, chat, documents, tickets — and answer in a tidy paragraph with citations, it is easy to read that answer as the answer. It isn’t. It’s the answer for you, shaped by what you happen to be able to reach.
Why now. On 15 June 2026 the security firm Varonis disclosed SearchLeak (CVE-2026-42824, rated critical), a flaw in Microsoft 365 Copilot Enterprise Search where a single crafted link could make the assistant quietly hand over content from a victim’s “mailbox, calendar, SharePoint, and OneDrive.” The mechanism is the part worth your attention: “because Copilot Enterprise operates with the user’s full graph permissions, the attacker effectively inherits the victim’s access.” Microsoft fixed the bug. The property it exploited is not a bug — it’s how every permissions-aware assistant works, and it quietly shapes the answers you get every day.
What you’ll be able to do. Read a permission-scoped answer for what it is — bounded by your access, not the whole organisation — and recognise the one surprise that should make you stop and flag it.
The content
The obvious read is that “search all of work” means it searched everything. It didn’t. It searched everything you can open. But what your account can reach is three different things wearing one label: what the assistant can pull, what your task actually needs, and what you’re meant to see. The tool only knows the first. Microsoft documents the rule plainly: Copilot “only surfaces organizational data to which individual users have at least view permissions,” and its Semantic Index “honors the user identity-based access boundary so that the grounding process only accesses content that the current user is authorized to access.” Before the model sees anything, the system trims the results to your identity.
For most tasks, what it can reach is close enough to what you need and what you’re allowed, and none of this shows. It matters in the uncommon case where they come apart. When they do, it cuts two ways, and most people only feel one of them.
The first: the answer is bounded by your slice. When the assistant says it found nothing on a deal, a policy, a precedent, that can mean nothing you can see — not nothing exists. A summary that reads as complete is complete only over the files your account reaches. Scoped is not complete. Treat a confident “there’s nothing on this” as a statement about your permissions, and go and check the way you would have before the tool existed.
The second is the one that bites. The promise — it only shows you what you can access — quietly assumes your access is correct. In real organisations it isn’t. Concentric AI’s 2026 data-risk report, drawn from over 500 million records, found 16% of an organisation’s business-critical data is overshared — on average around 802,000 files per organisation sitting open to people who were never meant to see them. Years of stray sharing links and stale group memberships pile up, and a human rarely trips over them because you have to know a file exists to open it. An assistant that reads everything you can reach trips over all of them at once, then summarises the contents into a clean, cited paragraph. SearchLeak turned that blast radius into one click; on an ordinary day it just means the assistant occasionally hands you something you were never supposed to have — and you may be the first person to actually open it.
Try it
Use this the next time you lean on a work assistant for an answer you’d treat as complete, or when it surfaces something that feels outside your lane. Run it in the assistant you actually use, on a real question.
You're searching across my connected work sources to answer this. Before I
rely on the result:
1. List which of my sources you actually searched for this, and any you
could not access or that returned nothing.
2. Flag anything you surfaced that sits outside my own team, role, or
project — name the source document so I can judge whether I'm really
meant to see it.
3. Give me the direct link to each citation so I can open it under my own
login.
My question: [your real question]
Where it breaks: a citation that won’t open under your own login, or a neighbouring team’s file you can’t place, isn’t a clever find — it’s a permission that drifted, and the move is to flag it to whoever owns access, not to use it. And a clean result only proves what you can see today; it clears nothing for anyone else, and tomorrow’s access change won’t reach the index instantly. Org-wide permission hygiene is a governance job — your spot-check is the canary, not the cure.
Additional reading
- SearchLeak — Varonis (15 June 2026) — the one-click exfiltration chain in Microsoft 365 Copilot Enterprise Search (CVE-2026-42824), and the line that matters for everyone: the assistant runs with the user’s full graph permissions.
- Data, Privacy, and Security for Microsoft 365 Copilot — Microsoft Learn — the vendor’s own statement of the rule: Copilot surfaces only data the individual already has at least view permissions to (a continuously-updated page; read as of June 2026).
- Is Copilot Safe? — Concentric AI Data Risk Report (23 April 2026) — the oversharing numbers: 16% of business-critical data overshared, ~802k files per organisation, from 500M+ records analysed.
Editor’s note
The questions in the example should be used as the key to understanding how this is relevant to knowledge workers, more than the actual research the thesis is based on. What users need to understand is that access is not context, and nor is it necessarily permission. For most tasks, this won’t be a problem. I’ve added it as a module because for the 0.2% of the time when there’s a material issue with a collision between your session context and your access permissions, it could be a big deal. My hope is that because you’ve seen this, you’ll be able to catch it before it becomes a problem.
// three assertions against what you just read · results stay in this browser
When your work assistant "searches across all of work" to answer a question, what has it actually searched?
You ask the assistant for background on a supplier contract, and its cited summary includes a finance-team file you've never seen and can't place. What's the right move?
You run the spot-check prompt from this module and everything comes back clean: every citation opens under your login and nothing sits outside your lane. What has that actually established?
Was this useful for your daily work?