Bobby Liu.
← Security notebook

Reference note

Enterprise AI Security Checklist

A practical governance baseline for identity, data handling, integrations, retention, and high-impact AI actions.

Research area

Identity

Controls that apply across approved enterprise AI services and the identity systems used to access them.

BaselineIdentity policy

Personal-account use for company work

Keeps company data within approved workspaces and organizational oversight.

BaselineIdentity provider

Authentication paths that bypass SSO or MFA

Prevents weaker sign-in methods from undermining centralized authentication. Preserve controlled emergency access.

BaselineApplication consent

Unrestricted user consent to third-party applications

Prevents users from granting unreviewed access to corporate email, files, and other sensitive data.

BaselineAccess lifecycle

Stale accounts, sessions, and tokens

Reduces opportunities to exploit abandoned access after departures or role changes.

BaselinePrivileged access

Unnecessary standing administrator access

Limits the damage caused by compromised accounts or administrative mistakes.

Research area

Claude

Claude organization settings, project sharing, connectors, memory, and Claude Code permissions.

BaselineData controls

Optional model-training or data-sharing enrollment

Prevents voluntary sharing beyond approved commercial data protections. Commercial data is not used for training by default.

ConditionalMemory

Memory and past-chat search

Reduces reuse of sensitive information across conversations. Review existing stored information separately.

BaselineSharing

Unnecessary broad project sharing

Limits internal exposure of project content. Claude's Public projects setting concerns organization-wide visibility.

BaselineConnectors

Unapproved connectors and unnecessary write or delete actions

Reduces third-party data exposure and unauthorized changes to connected systems.

BaselineDeveloper tooling

Claude Code permission-bypass mode

Preserves permission checks before commands and tools execute.

Research area

ChatGPT

ChatGPT Enterprise workspace controls for data use, memory, sharing, apps, connectors, and external actions.

BaselineData controls

Optional model-improvement sharing, where applicable

Prevents optional contribution of business information to training. Enterprise data is excluded from training by default.

ConditionalMemory

Persistent memory

Reduces storage and reuse of sensitive context across conversations. Disabling memory does not substitute for reviewing stored information.

BaselineSharing

Unnecessary sharing of chats, files, and GPTs

Limits exposure beyond intended audiences. Review existing shares separately.

BaselineIntegrations

Unapproved apps, plugins, and MCP connections

Prevents unreviewed integrations from accessing company data or connected systems.

BaselineActions

Unnecessary external actions and unrestricted action destinations

Reduces data transfers to unapproved services and consequential actions without appropriate oversight.

Research area

Microsoft 365 Copilot

Workplace Copilot and Copilot Chat controls. This section does not cover GitHub Copilot.

BaselineAccess policy

Personal or consumer Copilot use for company data

Keeps business use within the approved work-account experience and applicable enterprise protections.

ConditionalAdmin center

Allow web search in Copilot

Prevents generated search queries from being sent to Bing for sensitive workflows; disabling it also removes web grounding.

BaselineAgent management

Unapproved agents and extensions

Reduces exposure to unreviewed functionality, integrations, and data access.

BaselineApplication consent

Unrestricted consent to Microsoft Graph and third-party permissions

Prevents excessive access to organizational information and actions.

BaselineData governance

Excessive SharePoint and OneDrive permissions

Reduces the sensitive content Copilot can surface through users' existing access. Fix permissions at the source.

Research area

Gemini / Google Workspace

Managed Workspace access, conversation history, connected apps, consumer activity, and Gemini Live capture permissions.

BaselineWorkspace admin

Gemini access for unapproved users or organizational units

Limits deployment to approved users and managed Workspace services.

ConditionalRetention

Gemini conversation history

Reduces saved conversation history where retention requirements permit. History off does not mean zero retention or immediate deletion of existing history.

BaselineConnected Apps

Unnecessary Connected Apps

Limits access to Gmail, Drive, Calendar, GitHub, and other connected services.

BaselineConsumer activity

Consumer Keep Activity for permitted personal-account use

Limits future consumer activity use for model improvement. Managed Workspace accounts follow different controls.

ConditionalDevice permissions

Unnecessary Gemini Live microphone, camera, and screen sharing

Reduces accidental capture of confidential conversations, surroundings, and on-screen information. Assess recording retention separately.

Research area

Organization-wide governance

Policy controls that apply across vendors. These recommendations synthesize documented capabilities into an organizational security baseline.

BaselineApproved services

Unapproved AI services, browser extensions, and integrations

Reduces unmanaged AI use and data flows outside approved oversight.

BaselineData policy

Submission of prohibited sensitive data

Prevents credentials, secrets, regulated information, and confidential material from entering unauthorized systems.

BaselineHuman oversight

Autonomous high-impact actions without approved oversight

Reduces harmful external communications, production changes, payments, access changes, and destructive operations.

BaselineRetention policy

Indefinite retention without documented justification

Reduces unnecessary accumulation of sensitive information while preserving legal holds and required records.

BaselineChange management

Unreviewed activation of new features and expanded permissions

Prevents new capabilities from introducing unassessed access or data exposure.

Protective controls

Keep enabled

MFA, SSO, security audit logging, monitoring, data-loss prevention, and required compliance retention.

Operational follow-through

Implementation record

Record who owns the control, where it is enforced, how it was verified, and when any approved exception expires.

OwnerEnforcement locationConfiguration evidenceValidation dateException expiry

This checklist reflects independent security analysis. It is a recommended baseline, not a vendor-prescribed standard or a universal set of switches.

Last reviewed October 2, 2026