Expert opinions, TECHNOLOGY

Corporate data under control: How companies are rethinking information access rules

With the advent of digital technologies, information security requirements have changed significantly: data has become more accessible and mobile and can now circulate across multiple systems. The development of AI has further increased the risks: information can be processed at far greater speed and scale, creating new opportunities for data leaks and unauthorized access. In this article, I will highlight cases where the digitalization of business processes is truly justified.

Data access rights should not be granted permanently on the basis of an employee’s job title, but rather for a specific task and a limited period

Employees should be given immediate access to the information they need, with those rights automatically revoked once the assignment has been completed.

Example: A finance specialist is granted access to an additional set of reports for 10 business days during the quarterly close. Once this period ends, the system automatically revokes the access rights without requiring a separate request.

Control begins not with restrictions, but with a clear classification of corporate data

Until an organization categorizes information according to its sensitivity and the potential consequences of its disclosure, rigid, uniform restrictions will either impede day-to-day work or leave critical information inadequately protected.

Example: A presentation about a publicly available product can be freely shared within the company, while HR and contractual data is accessible only to the relevant departments, and materials relating to new technologies are stored in a separate, secure environment.

A role-based access model alone is no longer sufficient – the context in which information is accessed also matters

Modern access rules should take into account an employee’s position, device, location, time, connection channel, purpose of the operation, and current level of risk.

Example: A project manager can view a contract on a corporate laptop, but attempting to download the same document to a personal device or access it from an unusual location will require additional verification or result in the action being blocked.

Accumulated legacy access rights pose a greater risk than a one-off provisioning error

When employees move between departments, they often keep the rights attached to their previous roles. Access privileges should therefore be reviewed whenever a person’s status changes.

Example: When an employee moves from Procurement to the Project Office, the system automatically revokes their access to the supplier proposal registry and issues a new set of permissions tailored to project work.

Overly cumbersome security measures breed shadow information-sharing channels

When corporate processes are slow and complicated, employees turn to personal or public channels to share files. Security protocols must therefore offer a convenient, authorized alternative.

Example: Rather than simply banning the transfer of large files, a company introduces a secure file-sharing platform with link expiration, watermarking, and restrictions on re-downloading.

Generative AI has become a new potential channel for corporate data leaks — and requires dedicated policies

Companies need to provide approved AI tools, mask sensitive data, and set clear guidelines on what information may be processed.

Example: Instead of pasting a client contract into a public chatbot, an employee uses a corporate AI assistant that automatically redacts account details, personal data, and commercial terms before processing the text.

Corporate AI systems must not hold broader access rights than the employees they act for

Access rights must be verified both when querying data sources and when generating responses. A unified AI assistant must not become a universal workaround for the existing access control model.

Example: When a standard employee asks about the payroll budget, they receive only authorized aggregated figures; detailed data is available solely to HR staff with the appropriate permissions.

Access controls must extend across the entire AI infrastructure

Corporate data may live in vector indices, system caches, conversation histories, and model logs. Revoking access rights in the source system must also cut off access to these derivative stores.

Example: When an employee leaves a project, the related documents are removed from the corporate AI search index, and previously saved snippets are no longer used to generate new responses.

AI-generated responses inherit the confidentiality level of their source material

Summaries, translations, tables, and presentations do not make restricted information public. The system must carry access labels over to the new material and apply the same storage and transmission restrictions.

Example: A one-page summary of a confidential strategy automatically receives the same classification as the original document and cannot be sent to an external address (in the case of state-owned enterprises).

For AI agents, the right to view information must be separated from the right to act

Access to a document does not imply the ability to send an email, modify a record, export a database, or initiate a payment. The higher the stakes of an operation, the more essential it is to require separate authorization and human confirmation.

Example: An AI assistant drafts a letter to a supplier and fills out a contract record, but the message is sent and the terms are modified only after the responsible employee confirms.

Access for contractors and partners must be isolated, time-bound, and tied to a specific responsible employee within the company

External user rights must be limited to specific projects, folders, systems, AI tools, and the duration of the contract.

Example: A service organization is granted access solely to the technical documentation for the equipment it services, for a period of 30 days; it cannot access other sections or use the corporate AI to reach them.

Decisions about data access and AI usage should not rest solely with IT and information security departments

It is the data owner who must define permitted use cases, the required level of detail, and the instances that demand mandatory human review, while IT and security teams implement and enforce these rules.

Example: A sales manager authorizes the AI to analyze an anonymized customer database to identify trends but prohibits users outside the department from generating full customer profiles.


In the digital environment, corporate data is constantly copied, transformed, aggregated, and used by employees, contractors, and AI tools. Access control must therefore be built as a continuous management system. The goal is not to halt the use of AI, but to integrate it into a secure corporate framework, one where a digital assistant operates within the scope of a specific user’s permissions, every significant action is verifiable, and accountability for the data remains with both the individual and the organization.

By Valery Lyashenko, expert in digital transformation and AI training, lecturer

Previous Article