Closing the AI Visibility Gap Starts With Permissions

GenAI Security
Webcasts

Key Takeaways

AI didn’t create the data oversharing problem. It just made it impossible to ignore. Most enterprises have years of accumulated permission drift across their data landscape. For most of that time, the risk was theoretical. Then generative AI started surfacing sensitive files to anyone who asked the right question, and a slow-burn hygiene issue became an urgent security problem.

In this 45-minute session, Ryan Wood, CISO at VGM & Associates, and Creed Krueger, Cybersecurity Manager at VGM, share what they found when they finally got measurable visibility into their Copilot environment, how they prioritized remediation when nearly everything looked critical, and what they wish they’d known before AI rollout outran their controls.

They’ll also touch on what’s coming next: the rise of employee-built agents, the identity and ownership questions that don’t have clean answers yet, and why agent sprawl is the next visibility gap CISOs need to close.

James Pham, CEO and co-founder of Opsin, shared the patterns Opsin is seeing across enterprise deployments and where AI data security is heading over the next 6 to 12 months.

A few key insights from the conversation:

  1. Fix before you broadcast | When VGM found oversharing that potentially touched PHI, they didn't send an alarm to the company. They built a remediation plan first, then had a grounded conversation with leadership. Raising alarms without a fix in hand creates panic without action, and panic gets AI adoption paused entirely.
  2. Governance needs five hard questions before an agent gets approved | VGM's risk framework for any new AI agent request: What data can it access? What identity does it use? Where can it act? How autonomous is it? Can we audit it? If a request can't answer all five, it's a no by default.
  3. Identity (not just data) is the next governance gap | Agents inherit their creator's permissions by default, and agents increasingly talk to other agents, passing context and access between them without a human in the loop. Securing agentic AI means governing identity and inter-agent communication, not just locking down what data an agent can touch.
  4. Agent sprawl outpaces any team's ability to manually review it | VGM's environment surfaced over 1,400 agents, most spun up inside Copilot and Copilot Studio. Volume alone becomes a security problem.
  5. Assumed security and measured security are two different things | VGM believed their SharePoint and Teams permissions were reasonably locked down after years of tightening had gone into it. Yet, once they measured exposure, they found broad access patterns that had accumulated silently through normal collaboration. Nothing malicious but drift that needed active managing.

Interested in seeing Opsin in action?

Get a Demo →

Table of Contents

LinkedIn Bio >

FAQ

What is agent sprawl, and why is it a security risk?

Agent sprawl is the rapid, often ungoverned proliferation of AI agents across an organization, created inside tools like Microsoft Copilot Studio, ChatGPT, or Claude, often by individual employees without security review. It's a risk because each agent can inherit its creator's data access and permissions, and the sheer volume makes manual review impossible without a system for discovery and prioritization.

How should security teams prioritize AI agent risk when there are hundreds or thousands of agents to review?

Start at the broadest layer first. Triage critical and high-severity issues at the site level (SharePoint, OneDrive) before moving to folder-and file-level findings. Pairing that with a risk framework: what data an agent touches, what identity it uses, how autonomous it is, and whether it's auditable, helps separate what needs immediate action from what can wait.

What's the right way to communicate AI security findings to leadership without causing panic?

Build the remediation plan before you broadcast the finding. Surfacing a risk (like PHI exposure) without a plan in place creates urgency without direction, which can stall AI adoption altogether. A grounded conversation with a fix already underway lands better with leadership than an unstructured alarm.

Do AI agents need their own identity and access governance, separate from the employees who create them?

Yes. Agents commonly inherit the permissions of the person who built them, which can grant broad access if that creator has elevated privileges. Agents also increasingly communicate with other agents, passing data and context between them without human oversight. Treating agent identity as a distinct governance category, separate from standard employee access,. is becoming a core requirement for AI security programs.

About the Author
Opsin Security
Purpose-built for enterprise AI, Opsin delivers visibility, context, and protection across the LLMs and cloud environments your organization is already using, from Microsoft Copilot and ChatGPT Enterprise to Google Gemini and Claude. Opsin makes AI risk visible, clear, and actionable, enabling security teams to safely scale AI adoption.
LinkedIn Bio >
Opsin Security
Purpose-built for enterprise AI, Opsin delivers visibility, context, and protection across the LLMs and cloud environments your organization is already using, from Microsoft Copilot and ChatGPT Enterprise to Google Gemini and Claude. Opsin makes AI risk visible, clear, and actionable, enabling security teams to safely scale AI adoption.
LinkedIn Bio >
Opsin Security

Closing the AI Visibility Gap Starts With Permissions

AI didn’t create the data oversharing problem. It just made it impossible to ignore. Most enterprises have years of accumulated permission drift across their data landscape. For most of that time, the risk was theoretical. Then generative AI started surfacing sensitive files to anyone who asked the right question, and a slow-burn hygiene issue became an urgent security problem.

In this 45-minute session, Ryan Wood, CISO at VGM & Associates, and Creed Krueger, Cybersecurity Manager at VGM, share what they found when they finally got measurable visibility into their Copilot environment, how they prioritized remediation when nearly everything looked critical, and what they wish they’d known before AI rollout outran their controls.

They’ll also touch on what’s coming next: the rise of employee-built agents, the identity and ownership questions that don’t have clean answers yet, and why agent sprawl is the next visibility gap CISOs need to close.

James Pham, CEO and co-founder of Opsin, shared the patterns Opsin is seeing across enterprise deployments and where AI data security is heading over the next 6 to 12 months.

A few key insights from the conversation:

  1. Fix before you broadcast | When VGM found oversharing that potentially touched PHI, they didn't send an alarm to the company. They built a remediation plan first, then had a grounded conversation with leadership. Raising alarms without a fix in hand creates panic without action, and panic gets AI adoption paused entirely.
  2. Governance needs five hard questions before an agent gets approved | VGM's risk framework for any new AI agent request: What data can it access? What identity does it use? Where can it act? How autonomous is it? Can we audit it? If a request can't answer all five, it's a no by default.
  3. Identity (not just data) is the next governance gap | Agents inherit their creator's permissions by default, and agents increasingly talk to other agents, passing context and access between them without a human in the loop. Securing agentic AI means governing identity and inter-agent communication, not just locking down what data an agent can touch.
  4. Agent sprawl outpaces any team's ability to manually review it | VGM's environment surfaced over 1,400 agents, most spun up inside Copilot and Copilot Studio. Volume alone becomes a security problem.
  5. Assumed security and measured security are two different things | VGM believed their SharePoint and Teams permissions were reasonably locked down after years of tightening had gone into it. Yet, once they measured exposure, they found broad access patterns that had accumulated silently through normal collaboration. Nothing malicious but drift that needed active managing.

Interested in seeing Opsin in action?

Get a Demo →

Get Your Copy
Your Name*
Job Title*
Business Email*
Your copy
is ready!
Please check for errors and try again.

See, secure, and scale AI

Get your free AI agent risk assessment.
Results in 24 hours.
Start Your Free Risk Assessment →