FIO Solutions

Field note

You can't secure what you can't describe

Jul 29, 20266 min readdatasecurity

The first article argued that organization is the precondition for AI, and the second wrote the rules out. There's a third reason to do this work first, and it's the one that eventually becomes a 6pm phone call: you cannot secure what you cannot describe.

A permission is a sentence, and it needs a noun

"The service team can read client policy documents." That's a permission rule. It requires a group that actually exists and a set of documents that has a name.

Miss either half and the rule can't be written — so it doesn't get written. What happens instead is case-by-case: someone asks for a file, someone shares it, everybody moves on. No one records the grant, and no one ever revokes it, because revoking requires remembering. Ten years of that isn't an access model. It's an accumulation, and it only ever grows in one direction.

This is why "we should tighten up permissions" stays on the list for years without moving. It isn't procrastination. The prerequisite work hasn't been done, so the task as stated is genuinely impossible.

Your folder shape is your access model

Permissions attach to containers, not to individual documents — that's true in every system you're likely to own. Which means the tree you built in step 2 is your security model, whether you designed it that way or not.

A tree that mirrors how work moves puts its boundaries on lines that mean something: this client, this engagement, this document type. Those are the same lines a permission rule wants to be drawn on, so the rules end up short and there are few of them. A tree that grew by accident has no such lines, so every permission becomes an exception — and exceptions are never reviewed, because reviewing them requires understanding why each one exists.

The test is one sentence long. Can you state who can reach a given client's folder? If answering requires a meeting, the honest description of your current state is "unknown," and unknown access should be treated as broad access until proven otherwise.

The diagnostic, which takes an afternoon

Pick the folder you'd least like to see forwarded outside the company. Produce a complete list of every person, group, and share link that can reach it. Time yourself.

What happensWhat it means
Answered in ten minutes from the folder itselfStructure is doing its job
"We'd have to check with IT"The answer is unknown — treat it as everyone
The list includes someone who leftNot hypothetical anymore
The list includes a link marked "anyone with the link"Neither is that

We're not going to price a breach for you. Any vendor who hands you a dollar figure for one is quoting an industry average that has nothing to do with your business, which is the same objection we raised about borrowed process numbers in the cost article. What the exercise above produces isn't a number — it's a yes or no on whether you can describe your own exposure. That's the finding.

What actually changed when the agents arrived

Over-broad access is not new, and most companies have carried it for years without incident. It was survivable because exercising it required a person who knew a particular file existed, cared enough to open it, and had a reason to go looking. Three frictions, all human, all doing quiet security work that nobody budgeted for.

Retrieval removes all three at once. An assistant reads everything within its reach, on every question, whether or not anyone suspected the document was there — and then hands back a fluent paragraph in which the source is invisible. Nobody had to go looking, and nobody can tell by reading the answer that something sensitive contributed to it.

The permission was already wrong. The agent is just the first thing that ever used all of it.

A prompt is not a permission

This is the mistake worth naming plainly, because it's being made right now in a lot of places: telling an assistant "don't discuss compensation" is a preference, not a control. It's enforced by the same machinery that writes the answers, and it fails the same ways that machinery fails — a rephrased question, an indirect one, a document that doesn't look sensitive until page four.

The control is not granting the access. Three rules make that mechanical:

  • The agent gets its own identity. Not a borrowed employee login, not the admin account someone had handy during setup. Its own service account, so its permissions can be narrower than any human's and its reads land in the log under a name you recognize.
  • Scope it to the job. An assistant that answers billing questions has no business reaching HR. Note that this rule is only writable if the filing work is done — "billing documents" has to be a set you can point at before you can grant access to it and nothing else.
  • Log it, and then actually read the log. Retrieval logs are the only record of what an assistant touched. They are also worth precisely nothing if every entry reads scan0142.pdf. A log is only as useful as your naming convention, which is the least obvious payoff of doing step 2.

Staff guardrails and agent guardrails are not the same thing

StaffAgents
What stops overreachJudgment, context, social frictionOnly what's configured
Scale of one mistakeOne person, one file, one timeEvery question, everything in scope
Effect of trainingImproves with itNot applicable — instructions aren't controls
The real controlAccess plus accountabilityAccess plus identity plus logs

Here's the uncomfortable part. In most companies under 100 people, the thing actually preventing misuse isn't the permission settings — it's that an employee who opens a folder marked HR — Confidential knows to close it. Discretion has been carrying the load. It doesn't show up in any configuration, it was never designed, and it is exactly the layer an agent does not have.

That's not an argument against giving agents access. It's an argument for making explicit what was previously implicit, before you hand the keys to something that reads every door as identical.

Three tiers, applied to folders

Classification is where this gets over-engineered fastest. For a business this size, three tiers is enough: Public, Internal, Restricted. Apply them to folders, not to files, so filing stays a single decision rather than two. A three-tier scheme everyone follows beats a five-tier scheme that gets skipped whenever someone's in a hurry — the same reason a plain naming convention beats an elegant one.

And retention is quietly a security control, not just housekeeping. A document you deleted on schedule can't leak, can't be cited by an assistant, and can't surface in discovery. The cheapest way to protect a file is to no longer have it.

The same order, for a second reason

Least privilege requires knowing what the privileges are over. Classification requires a stable unit to classify. Audit requires names that mean something. All three are outputs of steps one through three — which is why the order isn't just an AI sequencing argument, and why "we'll sort out permissions later" and "we'll sort out filing later" have always been the same sentence.

An assessment produces the access map as a byproduct of documenting how the business runs: who can reach what, which is a different question from who should, and the gap between those two lists is usually the most useful page in the deliverable.

Work with FIO

FIO documents how your business actually runs, then prices what the manual work costs. That's the $999 assessment — and the fee credits toward any build work.

See the assessment