typing, computer, man, workspace, work, workplace, desk, office, startup, businessman, technology, company, corporate, marketing, professional, internet, project, web, display, monitor, digital, electronic, modern, multimedia, typing, office, office, office, office, office, businessman, marketing, marketing, marketing, marketing, professional, internet, project, web
Photo by StartupStockPhotos on Pixabay

Data Handling

Part of AI tool privacy and data handling

Comparing AI workspace permissions for business users

Compare who can open, submit, share and administer business information in ChatGPT Business, Microsoft Copilot and Gemini Workspace.

Why AI permissions mirror existing access

Creating a Microsoft 365 subscription also creates a tenant that sits inside the Microsoft 365 service boundary, where Microsoft Copilot can access your organisation's data. Operating inside that boundary does not grant Copilot tenant-wide visibility.

Data access is always scoped to the permissions of the person signed in. That data includes information the user can access, such as their activities and the content they create and interact with in Microsoft 365 apps.

Google describes the same model for Gemini in Workspace: Gemini has the same access to Workspace data as the user does. Adding an assistant tends to reproduce the access map you already have rather than expand it.

User-level access: what AI can and cannot see

Copilot only accesses data an individual user is authorised to access, based on controls such as existing Microsoft 365 role-based access controls. It does not access data the user has no permission to access.

Gemini can only access files in Drive that have been shared with the user, and Calendar events the user can view in Workspace.

When a user types a prompt, Copilot grounds the input and queries Microsoft Graph in the user's tenant, then sends the grounded prompt to the language model. The data used to generate the response is encrypted in transit.

Admin controls: disabling, limiting and enforcing sign-in

A Google Workspace administrator can restrict access to Gemini entirely, in which case the user cannot chat with Gemini or invoke agents from any Gemini chat. The administrator can also block access to some or all Google Workspace data, including Drive files and Gmail messages.

Two further admin levers sit alongside data access. Conversation sharing can be restricted so that anyone opening a shared chat link sees an error message, and Gemini Enterprise and its agents can be limited separately.

For Copilot, customer data stays within the Microsoft 365 service boundary and the security, compliance and privacy policies the organisation already deploys. Copilot honours Conditional Access and multifactor authentication.

Content owner and user-level limits

Content owners hold a veto that sits below the admin layer. If a Drive file's owner does not allow download, copy and print, Gemini cannot access the file even when it has been shared with the user.

Users themselves can manage Gemini's access to their data within and between apps through smart feature settings.

Copilot's access decisions follow the permission model already applied in Microsoft 365, including role-based access controls, rather than a separate AI-specific permission list.

Feature access is not the same as data access

Google's admin settings separate the two questions. An administrator can leave users with all Gemini features, including agents, while blocking Gemini's use of the Workspace data their account can access, including Drive files and Gmail messages.

The practical consequence is that a user can have the feature switched on and still receive refusals, because the restriction sits on the data rather than on the interface.

For Copilot, the supplied architecture describes data access scoped to the signed-in user's permissions and existing Microsoft 365 role-based access controls. OpenAI also publishes help documentation titled "Managing feature access with role-based access control in ChatGPT", which covers role-based access control for feature access in that tool.

Delegated, shared and restricted content

Delegated mailboxes are a common edge case. If someone has given a user delegated access to their inbox, Gemini does not have access to those messages, only to the messages in the user's own inbox.

Sharing restrictions apply to the assistant as they do to the person. A Drive file whose owner blocks download, copy and print stays out of reach for Gemini even when it appears in the user's shared items.

Copilot scopes data access in Microsoft Graph to the access rights of the person signed in, within the tenant's existing security, compliance and privacy policies.

A practical checklist for comparing AI workspace permissions

Ask whether the assistant inherits the access rights of the person using it or holds access of its own. Copilot scopes data access to the permissions attached to the account; Gemini matches the user's own Workspace access.

Establish what an administrator can switch off, and at what granularity: the assistant entirely, its access to Workspace data, conversation sharing, or individual agent deployments.

Check whether content owners can veto access. Drive sharing settings that block download, copy and print also block Gemini, so the answer changes what you can promise data owners.

Ask how delegated mailboxes are treated. Gemini reaches only the user's own inbox, not inboxes delegated to them.

Confirm whether Conditional Access and multifactor authentication are enforced for the AI service, and whether feature roles are separated from data access, so you can grant the tool without granting the data.

More from Data Handling

Data Handling

AI document processing

AI document processing can extract fields from invoices, forms and tables, but a convincing preview is not proof that the data is ready for a finance or…