
Treat a connected AI assistant as a new way to find and combine company information. Pilot its access by job, source, role, and time period.
How to give an AI assistant company data safely, which sources to connect first, and how to test permissions.
Major workplace tools increasingly let administrators choose which internal sources can ground AI features, often by user group.
Choose the business question first. Then decide which group should use the assistant and which sources it needs to answer that question.
A good pilot gives people useful answers from approved material, exposes mistakes while the scope is small, and leaves a clear path to reduce or remove access if the evidence does not support expansion.
How should a business start an AI assistant access pilot?
Start with one information job that has an accountable owner and a visible quality test. “Help the service desk find the current warranty policy” is a pilot. “Make our internal knowledge smarter” is not. The first job lets you choose relevant sources, write expected answers, and spot a result that is too broad, stale, or unsupported.
Connected workplace assistants can use information from several internal services to produce a response. Current administrator guidance for a major workplace suite says administrators can select which services may contribute to an AI feature, apply settings to organizational units or groups, and expect a delay before some configuration changes take effect. It also says user level content permissions remain in force. Those are useful controls. They do not decide whether the underlying sharing structure is appropriate for a new search experience.
Start with a collection someone owns and maintains, such as the support policy library, product specifications, or a process handbook. A well-kept shelf is easier to check than years of accumulated email and chat, and its regular users can judge whether the answer is right.
What belongs in the pilot access register?
An access register turns a broad configuration choice into a reviewable operating decision. It should be short enough for the business owner to read. It should also capture enough detail that a security, privacy, or operations reviewer can see what information may reach the assistant and why.
| Register field | Example pilot entry | Decision it supports |
|---|---|---|
| Business job | Find the current warranty answer for a support reply. | Keeps the pilot tied to a useful outcome. |
| Approved sources | Published warranty pages and the owned policy library. | Prevents convenience access from becoming default access. |
| Pilot group | Five support leads and one policy owner. | Makes role testing manageable. |
| Blocked content | Personnel records, contracts, private inboxes, and draft negotiations. | Names material that requires a separate decision. |
| Review record | Test prompts, corrections, defects, owner, review date, and rollback method. | Shows whether access should stay limited, change, or stop. |
Keep the register factual. “Drive access enabled” does not explain the business purpose or the content class. “Support policy library for warranty answers, reviewed by the policy owner every quarter” does. The difference matters when someone asks why an assistant saw a document or why a source was excluded.
Why existing permissions are necessary but not enough
Permission inheritance answers who may see a record. It does not settle whether a new assistant should search across that record while answering a different question. A person may already be able to open a file, but they may not expect an assistant to pull a detail from it while it composes an answer from several systems.
Review broad access groups, stale external sharing, old project folders, sensitive labels, and record ownership before expanding the source set. Leave out any record the team cannot justify including. Finding that gap gives you information to fix before the assistant draws on it.
The NIST AI Risk Management Framework treats governance as a cross cutting function and calls for documented risks, impacts, and response plans. Use that principle in proportion to the work. A small pilot does not require a large program. It does require a written purpose, informed people, evidence from testing, and a decision about what happens next.

How do you test an assistant before expanding access?
Test the intended answer, the forbidden answer, and the uncertain answer with people who have the same access patterns as the pilot group. Give each participant a short prompt set. Include a normal question, a question that should return no answer because the source is excluded, a question that asks for an outdated fact, and a request that should move to a human owner.
Check the answer against the approved material and record any human corrections. Where the product supports citations, check those too. Fluent wording is not evidence that the source is current; the assistant should make missing information clear.
Never use a pilot to discover access boundaries through real customer, payroll, legal, health, or payment information. Use representative synthetic prompts and safely scoped test records when possible.
What does this have to do with AI search, AEO, and GEO?
The same discipline that limits internal AI access improves the public proof a business offers to search and answer systems. Public pages should state product facts, policies, qualifications, and availability in a current, accessible form. Internal assistants need a named source of truth for the same reason: they cannot resolve ambiguity just because a model can write a smooth response.
For public visibility, build a citation environment beyond one blog post. Keep facts aligned across owned pages, technical documentation, support content, reviews, directories, case studies, and current customer proof. An AI search surface may draw on several sources. Inconsistent claims make a brand harder to describe with confidence. Strong SEO does not guarantee an AI answer or citation, but crawlable pages, clear entities, current evidence, and independent corroboration give people and systems more material to evaluate.
Teams that need a narrower design can start with our guides to AI agent data boundaries and choosing the right first AI workflow. A customer facing source set needs the same care described in our article on AI help center operations.
When should the pilot expand or stop?
Expand only after the owner can show that the assistant answered the intended job well, stayed inside the source boundary, and can be changed or disabled without confusion. Expansion should be another decision with a new source set, another role test, and a new review date. It should not be the default reward for enthusiasm.
Stop or reduce the pilot when the source ownership is unclear, sensitive material appears outside the planned scope, users cannot tell which record supports an answer, or the team cannot identify who changes the setting. A controlled stop is a valid result. It protects the business while the owner fixes the underlying information problem.
Questions business teams ask about AI assistant access
What is the smallest useful pilot?
Choose one recurring information task, one small pilot group, and one owned source collection. A support policy lookup or product specification check gives the team a clear answer quality test without requiring broad company wide access.
Can we disable a source after the pilot begins?
Yes, but verify the product's propagation time and its separate controls. Current workplace administrator guidance notes that source setting changes can take time and that directly referenced content may have different behavior from broad source search. Keep the exact rollback steps and owner in the register.
Does this make us compliant with every privacy or security requirement?
No. This is an operating pattern, not legal advice or a compliance certification. Regulated, contractual, customer, and regional requirements may require additional review.
Sources
- Workspace data source controls for generative AI features
- Administrator and content owner controls for workplace AI data access
- NIST AI Risk Management Framework Core
- NIST AI Risk Management Framework Playbook
- Search Central guidance for AI features and websites
Need to pilot an AI assistant without broad access?
Deploy Agentic can help your team choose the first information job, map the source boundary, design role tests, and leave a clear review and rollback record.
Plan an access pilot