Skip to main content
CISSP-ISSAP · 20+ Years · #10 OnCon Icon, 2022
Back to Case Studies
Facilities / Fortune 500AI Governance

In-House Graph Broker for ABM SharePoint AI

Built ABM's internal AI governance program and an in-house Graph Broker in front of SharePoint AI tooling, so the Apps team could ship without native Microsoft Graph permissions that would have over-permissioned them.

ABMNamed client
Program build
SharePoint AI

The Challenge

ABM wanted SharePoint AI tooling in production, but native Microsoft Graph permissions would have given the Apps team more access than Security Operations could accept.

  • 1SharePoint AI and Copilot-style tooling needed Graph access to be useful
  • 2Native Microsoft Graph permission models were too coarse for the Apps team
  • 3Blanket Graph access would have over-permissioned application owners
  • 4Internal AI work needed a governance program, not a policy slide
  • 5Security Operations needed a control plane they could operate

Our Approach

Stood up an internal AI governance program and built a tailored in-house application that sits in front of SharePoint AI as a risk-adjusted Graph Broker.

1

Internal AI Governance

Defined who can use SharePoint AI, what data it may touch, and how Security Operations reviews new AI use before it reaches production.

2

Graph Permission Risk

Mapped the native Microsoft Graph scopes the Apps team would have received and marked the ones that over-permissioned application owners.

3

In-House Graph Broker

Built a tailored application that brokers Graph calls for SharePoint AI, granting only the risk-adjusted access each workload needs.

4

Security Operations Handoff

Put the broker in the path that internal SecOps can run, so AI tooling ships without handing the Apps team a blanket Graph token.

The Results

SharePoint AI tooling shipped behind a risk-adjusted Graph Broker. The Apps team was no longer over-permissioned, and internal Security Operations had a control plane instead of a slide deck.

Graph Broker
In-House Control Plane
Least Privilege
Apps Team Graph Access
SharePoint AI
Shipped Without Blanket Access
SecOps
Internal Security Operations Win

Adil rebuilt our AI governance program and shipped an in-house Graph Broker in front of our SharePoint AI tooling. Native Microsoft permissions would have over-permissioned the Apps team; that was a real win for Security Operations.

Stacy Hughes - CISO, ABM

Ready to Achieve Similar Results?

Thirty minutes is enough to see if the same approach fits your next audit, raise, or AI rollout.

See if I should be in the room