Microsoft Copilot (Microsoft 365): Workforce Insights Agent
🚨 The Signal: A new Copilot agent, Workforce Insights, can access and summarise sensitive HR data. This introduces new risks for data exposure and requires strict access controls and governance to prevent misuse.
The Impact
Leaders and managers are affected, with a high risk of sensitive workforce data exposure if not properly governed.
- Leaders/Managers: Risk of over-sharing sensitive HR data if not carefully managed.
- Security Teams: Increased surface area for data exfiltration and unauthorised access.
- HR Teams: Potential for misinterpretation or misuse of sensitive employee information.
- All Employees: Personal data (skills, work patterns) is now accessible via AI, raising privacy concerns.
The Action
- Review and update Microsoft 365 Copilot data access policies to restrict WFI Agent's scope.
- Implement strict role-based access controls (RBAC) for who can use the WFI Agent.
- Define and enforce data loss prevention (DLP) policies specific to WFI Agent outputs and interactions.
- Conduct a privacy impact assessment (PIA) for the WFI Agent's use of workforce data.
- Educate leaders and managers on responsible use and data handling when interacting with the WFI Agent.
Domain: Agentic-AI · Impact: high · Workload: Other · Essential Eight: Restrict Administrative Privileges · ISM: ISM-0445, ISM-1175, ISM-1380, ISM-1507, ISM-1508, ISM-1509, ISM-1647, ISM-1648, ISM-1650, ISM-1686, ISM-1688, ISM-1689, ISM-1883, ISM-1897, ISM-1898