File, folder and external-sharing review
We inspect permissions across your tenant to identify broadly shared content, external links and inherited access that would be exposed if AI search were enabled today.
A standalone engagement that makes your data estate safe for artificial intelligence, covering permissions, identity, classification, policy and executive oversight.

In summary
Overview
The AI Governance & Security Project is a structured engagement that helps organisations deploy AI safely and responsibly. It is designed for leadership teams that want the benefits of AI without the risks that come from poor permissions, uncontrolled data access and unclear staff guidance. The project establishes practical rules, reviews and remediates oversharing, and produces a prioritised action plan so management can move forward with confidence.
The project is independent of any specific AI platform. Whether you are preparing for Microsoft 365 Copilot, introducing ChatGPT, Google Gemini or Anthropic Claude, or simply want to make sure your current environment is ready for AI, the work focuses on the controls that matter regardless of vendor. The result is a clear, proportionate plan that reduces risk before AI adoption scales, rather than a reaction to an incident after it has happened.
Fresh Mango AI is the artificial intelligence consultancy of Fresh Mango Technologies, advising organisations across the United Kingdom and the British Virgin Islands on AI readiness, AI governance and security, AI adoption, business process automation, AI agents and robotics.
Organisations that also want a value and use-case view usually pair this work with the AI Productivity & Readiness Assessment.
Governance findings directly shape the knowledge sources and permissions used in a Custom AI Agent / Assistant Project.
Governance is not a one-off exercise, so controls are re-checked in each Quarterly AI Success Review as new tools and features appear.
Why AI Governance Matters
AI can expose overshared information. Modern AI assistants can surface files, emails and conversations far faster than traditional search. If content has been shared too broadly, or if access was granted years ago and never reviewed, AI can make that oversharing visible to anyone who can ask the right question.
Poor permissions become more visible. A folder that was quietly accessible to the whole company in 2019 may not have mattered when nobody knew it existed. Once an AI assistant can search across the estate on behalf of a user, those weak permissions become a direct confidentiality risk.
Governance must be designed in, not added later. Controls that are bolted on after a problem are less effective and more disruptive than controls built into adoption from the start. Responsible AI use needs clear rules, defined access and a management framework before rollout, not after an incident.
AI adoption requires appropriate controls. Licence purchase and user enthusiasm are not enough. Businesses need controls around data classification, identity, access, acceptable use and oversight so that AI becomes a safe, productive tool rather than an unmonitored channel for sensitive information.
Features
Every element below is delivered by senior consultants and tailored to your organisation.
We inspect permissions across your tenant to identify broadly shared content, external links and inherited access that would be exposed if AI search were enabled today.
We review anonymous links, guest accounts and administrative privileges, then prioritise the exposures that present the highest risk to the business.
We assess identity controls and recommend practical improvements that protect accounts and data from compromise, including stronger authentication and conditional access.
We classify the data that matters and recommend handling rules so sensitive content is protected wherever it travels, including into AI-assisted workflows.
We produce a plain-English policy that tells staff what they can and cannot do with AI, covering approved tools, permitted data, human review and escalation.
Where applicable, we recommend audit, logging and DLP controls that monitor AI use and prevent sensitive information leaving the organisation through unapproved channels.
We present findings in a concise, non-technical briefing and leave you with a sequenced Governance Action Plan that management can act on immediately.
Business challenges solved
These are the situations clients describe to us most often, and how this engagement resolves each one.
We identify and prioritise oversharing, broad permissions and guest access before AI assistants can search across your estate.
We produce a practical AI usage policy with permitted and prohibited use, human review expectations and escalation guidance.
We review file, folder and administrative access, then recommend a proportionate remediation sequence that reduces risk without disrupting work.
The Executive Briefing and Governance Action Plan give leaders a non-technical summary and a sequenced plan they can approve and defend.
We leave you with documented policy, access findings and security recommendations that answer due diligence questions with evidence.
We recommend data classification and handling approaches tailored to the content that matters in your organisation.
Expected outcomes
Outcomes are agreed at the outset and measured against a documented baseline.
Broad sharing links and over-permissioned content are identified and prioritised for remediation.
Staff receive practical guidance on what they can and cannot do with AI tools.
MFA, conditional access and administrative access recommendations improve the security baseline.
Management receives a sequenced Governance Action Plan with dependencies and recommended order.
An Executive Briefing and supporting documents provide a non-technical summary for directors and owners.
Typical timescales
Indicative timings based on comparable engagements. Exact durations are confirmed during scoping.
We review file, folder and external sharing permissions, overshared data, guest access and administrative access, plus current identity controls.
MFA, conditional access, account protection, data classification and handling, and current audit/logging capabilities are assessed.
We draft the AI usage policy and compile security recommendations, DLP and audit/logging guidance where applicable.
Findings are presented in a non-technical briefing and the Governance Action Plan is finalised for management approval.
Focused engagements run at the shorter end; larger or more complex estates may take longer.
Examples of use cases
A firm used the project to close broad sharing and stale access before Copilot indexing, avoiding a confidentiality incident.
An AI governance pack answered professional indemnity renewal questions about controls and policy.
A business replaced consumer AI use with a managed, policy-backed approach after discovering staff sharing client data.
Directors approved a pilot after receiving the Executive Briefing and a prioritised Governance Action Plan.
A supplier presented its AI usage policy and access review summary to satisfy a corporate client's security questionnaire.
The engagement is scaled to the organisation. Below is how it typically applies at each size.
A compact review focusing on the highest-risk shares, a simple AI usage policy and a short Executive Briefing.
The typical engagement, where years of sharing drift and growing AI interest make governance the priority.
Delivered in phases with per-division or per-business-unit access reviews and a central policy framework.
Strongest fit: documented policy, access review and security recommendations are often a commercial requirement.
We deliver this work across regulated and non-regulated sectors in the UK, the British Virgin Islands and internationally.
Client confidentiality and regulatory oversight make controlled AI use essential.
Matter separation, privilege and conflict management require permissions to be reviewed before AI search is enabled.
Special category data demands classification, access control and clear handling rules.
Procurement and indemnity questions about AI governance are answered with policy and evidence.
Transparency, accountability and defensible decision-making sit at the centre of the governance framework.
Sector-specific detail is available on our industries page, and comparable results are published in our case studies.
Why choose Fresh Mango AI
Fresh Mango AI is the artificial intelligence practice of Fresh Mango Technologies, supporting clients across the UK and the British Virgin Islands.
Fresh Mango AI is a dedicated artificial intelligence practice. The AI Governance & Security Project is delivered by senior consultants who do this work every week, not by a general IT team learning on your budget.
Every engagement starts with the work your people actually do and the numbers your leadership team is measured on. Tooling decisions follow the outcome, never the other way round.
Permissions, sensitivity, data residency and human oversight are designed into the engagement from day one rather than retrofitted after an incident or a failed procurement questionnaire.
We work across Microsoft 365 Copilot, Copilot Studio, ChatGPT, Anthropic Claude, Google Gemini and bespoke agents, so our recommendation reflects your estate rather than a single vendor relationship.
As the AI practice of Fresh Mango Technologies we support organisations across the UK, the BVI and the wider Caribbean, with an understanding of both UK GDPR and offshore regulatory expectations.
We baseline before we start and report against that baseline afterwards, so the value of the work is demonstrable to your finance director rather than asserted in a slide.
This service is frequently delivered alongside AI Productivity & Readiness Assessment, Quarterly AI Success Review and Custom AI Agent / Assistant Project. Discover more about Fresh Mango AI.
FAQs
It is a focused governance and security project that reviews your permissions, oversharing, identity controls and data handling, then produces a Governance Action Plan, Access Review Summary, AI Usage Policy, Security Recommendations and Executive Briefing so you can adopt AI safely.
It is for organisations preparing to deploy AI, boards that need assurance, IT and security leaders managing access, and regulated businesses answering client or insurer questions about AI governance.
A focused project typically runs for four to eight weeks, with the access review and high-risk findings delivered early so remediation can start quickly. Larger or more complex estates may take longer.
No. The AI Governance & Security Project is a complete, standalone service. It can be commissioned directly if you already know you want to harden controls and establish governance before or alongside AI adoption.
AI licences, third-party compliance audits, legal advice, penetration testing, security monitoring, advanced DLP configuration and remediation outside the agreed scope are excluded unless separately quoted.
We prioritise high-risk exposures and plan changes with owners, providing a rapid restore path. Most broad access is legacy rather than actively needed, so disruption is usually minimal when changes are communicated in advance.
Yes. We often deliver governance and security expertise alongside an incumbent IT provider, with clear responsibilities and joint change control.
Book a free 30-minute discovery session with an AI consultant, or request information and we will send the detail you need within one business day.
Recommended · Free · 30 minutes
Opens our live booking calendar in a new tab — pick any slot that suits you.
Prefer not to book yet?
Send a short enquiry and we will come back with the detail you need.
Related services
Make informed AI decisions before investing at scale.
Explore this serviceAn ongoing AI advisory and optimisation service that keeps adoption healthy, benefits proven and risk under control.
Explore this servicePurpose-built AI assistants designed around a specific business use case and grounded in your approved knowledge.
Explore this serviceDecision brief
Straight answers to the five questions that decide whether an AI project is worth starting.
Fresh Mango AI is the artificial intelligence practice of Fresh Mango Technologies, an IT, cyber security and cloud provider that has supported businesses since 2004 from offices in Ripon, Leeds, Skipton and Tortola in the British Virgin Islands. The same engineers who secure your identity, data and Microsoft 365 tenant advise on your AI adoption, so recommendations are grounded in what your estate can actually support rather than in vendor marketing.
Clients typically release several hours per person per week on drafting, summarising, searching and reporting, shorten document and approval cycle times, and remove manual re-keying between systems. Every engagement starts by baselining the work involved so that the benefit is measured in hours released and cycle time reduced, not in licences purchased.
Doing nothing is not a neutral position. Staff adopt consumer AI tools on their own, so company and client data leaves your control without record; competitors compress the cost of proposals, reporting and service delivery; and permission sprawl inside your file estate remains unaddressed, which becomes an incident the moment AI search is switched on. Delay also compounds the UK GDPR and EU AI Act governance work that will eventually be required of you anyway.
You book a free 30-minute discovery session. We confirm whether the AI Governance & Security Project is the right engagement for your situation, agree scope and timing, and set out exactly what you receive and when. You get a written summary of the conversation either way.
Book a free 30-minute discovery session with an AI consultant using our live booking calendar, or request information and we will reply within one business day. You can also call the UK office on +44 (0) 1765 606700 or the BVI office on +1 (284) 340 0466.
Recommended next step
Free, 30 minutes, no obligation — speak directly with an AI consultant about your objectives and the fastest safe route to results.
Book a Free 30-Minute Discovery SessionRequest InformationTalk it through with an AI consultant, or request written information — whichever suits you.
Your next step
Whether you're exploring AI for the first time or looking to scale existing AI initiatives, our specialists can help you identify practical opportunities and avoid common pitfalls.
