ACSETRA

Welcome to Acsetra.

We'll build your company brain

Martin Kalberer

Sr Mgr of Project Management, Supermicro

I can't say enough about the Acsetra team.

They turn around code quicker than I have ever experienced, with virtually bug-free releases and enhancements often ready in 1-3 days.

They thoroughly review your requirements, digest your needs, and follow up with attentive discussions.

They have an uncanny ability to absorb all the various inputs and deliver a clear final product quickly and efficiently.

Acsetra — an app factory.

We record the public network address (IP) your visit arrives from, and keep it with your visit history so a return visit can be recognised.

AI Data Center Document Security: PM Tool Vetting Guide

Before uploading a drawing set, baseline schedule, RFI log, or commissioning file to an AI tool, confirm exactly who can access it, whether it can train models, where prompts are stored, and whether web search or third-party agents are involved. “Enterprise AI” is not a security setting by itself; the contract, identity controls, and configuration matter.

Key takeaways

  • Ask vendors separately about model training, file retention, human access, subprocessors, and deletion; one privacy promise rarely covers every issue.
  • Permission cleanup comes before AI rollout because AI can make already-accessible project documents much easier for users to discover.
  • Check whether an AI feature sends derived search queries to the public web, even when uploaded files themselves are not sent.
  • Run a controlled pilot with a non-sensitive document set before connecting live SharePoint, Teams, OneDrive, or project-management repositories.

Start with the one question that matters: what happens to our files?

Ask the vendor to describe the full data path for an uploaded drawing or schedule: upload, processing, storage, retrieval, model use, logging, deletion, and any third-party subprocessors. Get the answer in writing, preferably in the product documentation and your contract—not in a sales demo.

For example, Microsoft states that prompts, responses, and data accessed through Microsoft Graph in Microsoft Copilot are not used to train foundation large language models. That is a useful commitment, but it does not eliminate the need to understand storage, access, connected services, and the precise Copilot experience your team is using.

A good buyer question is: “Show us the policy that applies to this exact plan, tenant, feature, and file-upload workflow.” Tiny differences between a consumer chat tool, a commercially protected chat experience, and a connected enterprise assistant can matter.

  • Will uploaded files, prompts, or outputs train any model?
  • How long are prompts, files, and activity logs retained?
  • Can the vendor’s personnel or subcontractors access content, and under what controls?
  • Which subprocessors process the content, and in which region?
  • Can Acsetra’s team export audit records and verify deletion?

Why existing permissions are the first security control

AI often works by finding and summarizing material a user can already access. Microsoft says Copilot surfaces organizational data only to users with at least view permission, using the permission models in Microsoft 365 services such as SharePoint.

That sounds reassuring—and it is—but it exposes a common project-system problem: old folders, broad Teams memberships, guest access, and inherited permissions. A schedule tucked into a forgotten SharePoint site may have been difficult to find manually; an AI assistant can make it much easier to locate.

Before connecting an AI tool to a document repository, review who can view active construction files, superseded drawings, commercial records, owner materials, and security-related designs. AI does not fix permissive access. It makes permission hygiene more important.

  • Remove inactive project-team and guest access.
  • Review broad groups and inherited library permissions.
  • Separate confidential commercial or security-sensitive libraries from general project collaboration.
  • Test results using a standard PM account, not only an administrator account.

Does the tool inherit your identity, labels, and policies?

For systems connected to Microsoft 365, ask whether the tool respects Microsoft Entra identity, SharePoint permissions, sensitivity labels, retention policies, audit controls, and data-loss-prevention rules. Microsoft describes Copilot as operating within existing Microsoft 365 privacy, security, and compliance commitments, while access to organizational content follows user permissions.

The practical distinction is simple: a tool that merely lets someone drag a PDF into a chat window is not the same as a tool that operates inside governed project repositories. The latter may be easier to control, but only if the repository itself is configured well.

Also ask whether the assistant can cite the source file and page for an answer. That is partly a quality control question, but it is also a security one: project managers need to know whether a response came from an approved drawing, an obsolete revision, or the open web.

  • Does it use single sign-on and enforce multifactor authentication?
  • Does it honor document-level permissions and sensitivity labels?
  • Can administrators restrict uploads, connectors, and external sharing?
  • Are prompts and responses included in audit, retention, and eDiscovery workflows?

Check web search and agents before treating the chat as private

A work-connected AI assistant may still use web search. Microsoft explains that when Copilot uses web search, it identifies relevant terms from a user prompt and sends a generated search query to Bing. Microsoft also says uploaded files are not included in that generated web query, but the feature should still be understood and governed before project teams use it.

The safe operating rule is not “never use web search.” It is “know when it is on, what leaves the tenant, and whether the prompt itself reveals a project name, location, customer, equipment configuration, or issue.” Ask the vendor to demonstrate the behavior rather than relying on a toggle with a cheerful name.

Be especially cautious with agents and plug-ins. Microsoft explicitly advises customers to review the privacy statement and terms of use for an agent because it may handle organizational data differently from the core Copilot service.

  • Can administrators disable web grounding for sensitive workflows?
  • What prompt-derived information is sent to search services?
  • Which agents, plug-ins, or connectors can users enable?
  • Does each connected service have separate terms and data handling rules?

Run a small pilot before uploading live project records

Start with a deliberately limited pilot: a sanitized drawing package, an old schedule, or a non-sensitive sample set. Give a small group of project managers defined tasks, such as finding a revision difference or summarizing a meeting action log. Then review outputs, access behavior, audit records, and administrator controls.

Test the awkward cases, not just the shiny ones. Try a user who should not see a restricted folder. Try an external collaborator. Try an old document that should be retained but not broadly discoverable. Ask the tool to identify its source. A five-minute test can reveal a permission problem that a procurement questionnaire will politely miss.

Finally, create a plain-language upload policy. It should state which document classes are approved, which require owner or security review, which tools are permitted, and who can approve a new connector. Project teams move fast; the policy needs to be faster than an improvised upload.

  • Pilot with least-privilege user accounts.
  • Document approved and prohibited file types.
  • Require source citations for technical or schedule recommendations.
  • Review access and audit evidence before expanding the rollout.

A short vendor questionnaire for data center PMs

Use these questions in procurement calls and keep the answers with the project’s AI governance record. The point is not to turn every PM into a privacy lawyer. It is to make sure the tool’s useful capability does not outrun the team’s ability to control it.

Microsoft’s documentation is a helpful example of the level of specificity to seek: it identifies how organizational data is accessed, states that foundation-model training does not use prompts and responses, and notes that permissions remain central. Other vendors should be able to provide comparably direct answers for their own products.

  • Which data is used for training, evaluation, abuse monitoring, or product improvement?
  • What identities, repositories, and permissions does the tool use?
  • Where are files, prompts, and outputs processed and stored?
  • What web-search, agent, and third-party connector paths are available?
  • What evidence can an administrator review after a file is uploaded?

Sources