AI Addaiadd.org

What should be revisited when add-on use spreads across roles?

Revisit access to connected content and the documentation of human oversight. Microsoft warns that incorrect connector permissions, including access granted to “Everyone,” can lead to oversharing, while NIST AI RMF states that human-oversight processes should be defined, assessed, and documented.

As add-on use expands across roles, earlier approval should not be carried forward automatically. The reviewing team needs to compare current access, workflows, and oversight arrangements with how the add-on is actually being used.

How to check the controls

Area to revisit Practical check Useful review record
Connector access Identify the content each add-on can reach, the roles that can access it, and any overly broad permissions. Correct grants such as “Everyone” when they are not intended. The connected-content scope, effective access, corrections made, and unresolved gaps.
Human oversight Confirm that the oversight process is defined, assessed, and documented rather than left implicit. The process description, assessment findings, and current documentation.
Role coverage Compare the roles now using the add-on with approved access and workflow ownership. Verify permissions after role or group changes. Differences between actual use and the approved scope, with an owner for unresolved items.
Intervention and exceptions Record who exercises oversight, which decisions are covered, and how intervention or exceptions are handled. Decision rights, escalation routes, and unresolved exceptions.

These records are practical review aids, not additional requirements prescribed by the cited sources.

What the team must still confirm

The cited material does not establish that every add-on uses connectors or that one oversight model fits every organization. It also does not define a universal approval threshold, review interval, retention period, or legal obligation.

Accordingly, the reviewing team must confirm:

  • Which permissions are actually in effect, including any inherited or group-based access.
  • What content the add-on can retrieve or expose.
  • How human oversight operates in the specific workflow.
  • Whether internal security policies, contracts, records requirements, or applicable law impose additional conditions.
  • Whether the access configuration and oversight documentation remain current as roles change.

The central revisit is therefore straightforward: verify that access is no broader than intended, and ensure that human oversight is explicit, assessed, and documented. Everything beyond those controls must be checked against the actual configuration and the organization’s applicable requirements.

Sources