... Skip to main content

Davis Powers

Success Story: Governing AI Access in Microsoft 365 for a Financial Services Firm

Overview

An energy equities firm wanted to put AI to work without exposing the data it is trusted to protect. Like most firms adopting tools such as Microsoft Copilot or the Claude Microsoft 365 connector, it faced a quiet risk: once an AI tool is connected to Microsoft 365, it can read whatever the signed-in user can read. In an environment built around a large SharePoint Online library, that often means far more than any single tool should reach. The firm partnered with Davis Powers to answer one question with evidence before going further. What could a connected AI tool actually see today? We assessed the environment, mapped the real access paths, and applied Microsoft sensitivity labels and auto-label policies to restrict third-party AI access to protected files. The result is a firm that can use AI on ground it controls and can prove exactly what its AI can and cannot reach.

The Challenge

Adopting AI Without Losing Control of Data

The firm was ready to adopt AI, but its Microsoft 365 environment had grown the way most do, with broad access and few boundaries between what tools could read and what they should. Before our engagement, the firm faced several specific exposures:

  • No current map of what a connected AI tool could surface if prompted for sensitive information.
  • Sensitive files stored alongside general content in a broadly permissioned SharePoint Online structure.
  • No sensitivity labeling in place to distinguish protected data from everyday documents.
  • No documented, provable answer to the access questions an auditor or an investor would ask.

 

The firm recognized that turning on an AI connector without addressing these gaps would expose data it could never afford to leak. It turned to Davis Powers for a scoped, execution-grade solution rather than a policy memo.

The Solution

Assess, Label, and Restrict AI Access by Configuration

Our team designed and executed a defined project to make the firm’s SharePoint Online environment safe to connect AI to, addressing exposure at the configuration level.

AI Access Assessment

  • Mapped what a connected AI tool, including the Claude Microsoft 365 connector, could reach in the current configuration.
  • Identified where sensitive data lived across the SharePoint Online environment.
  • Documented the gap between how permissions were set and how data was actually used day-to-day.

Sensitivity Labeling and Auto-Label Policies

  • Applied Microsoft sensitivity labels to distinguish protected files from general content.
  • Configured auto-label policies so that protected data is restricted from third-party AI tools automatically, not by manual effort.
  • Walled off the data that can never leave the firm from the AI connector through deliberate configuration.

A Provable, Repeatable Standard

  • Delivered the work as a complete, scoped project with a clear beginning and end.
  • Established labeling and policy as an ongoing standard rather than a one-time cleanup.
  • Gave the firm documentation it can show on demand.

The Results

AI Adoption on Ground the Firm Controls

Following the engagement, the firm moved from uncertainty to a governed, demonstrable position:

  • Clear Visibility: The firm now knows exactly what a connected AI tool can and cannot reach.
  • Protected Data: Sensitive files are restricted from third-party AI access by sensitivity labels and auto-label policies.
  • Safe AI Adoption: The firm can use AI on ground it controls rather than choosing between banning it and risking exposure.
  • Audit and Investor Readiness: The firm can answer access questions with documentation before anyone asks.
  • A Maintained Standard: Labeling and policy remain in force as data and tools change.

 

The firm resolved the exact exposure that turns into a problem the moment an AI connector is switched on or an examiner asks a pointed question.

Conclusion

Governing AI, Not Just Allowing It

Most firms feel stuck between two options with AI: keep it locked out and fall behind, or turn it on and hope nothing sensitive leaks. This engagement shows a third path. Use AI, but audit and lock down what it can reach first, so the data that must stay inside the firm never leaves. That is configuration work, and it is the difference between allowing AI and governing it. For financial firms preparing to adopt AI, Davis Powers provides the assessment, configuration, and documentation needed to do it safely and provably.

About Davis Powers, Inc.

Davis Powers, Inc. is a Chicago-based managed service provider delivering managed IT, cloud, cybersecurity, and networking solutions. As a Microsoft Solutions Partner with specializations in Data & AI, Modern Work, and Azure Infrastructure, we bring deep expertise to AI governance and Microsoft 365 security. With 24 years of executing complex IT solutions for financial services firms, commercial real estate operators, and multi-location retailers, Davis Powers builds the accountability layer that lets clients adopt technology with confidence.