A CISO’s take: Enterprise copilot risks with Jim Alkove and Ramy Houssaini

Learn AI copilot deployment risks and identity governance best practices from Jim Alkove (Oleria) and Ramy Houssaini (Cloudflare).

Symmetrical abstract butterfly shape with interlocking loops in brown on a round yellow-green gradient background.
by
 
Oleria
May 28, 2025
 
 
 
Headshots of Ramy Houssaini, Chief Cyber Solution Officer at Cloudflaire, and Jim Alkove, CEO of Oleria.
Key Takeaways
  • Enterprise AI copilots inherit the full permission set of the user account they operate under, making every instance of over-provisioned access immediately exploitable without any additional credential compromise.
  • Conventional identity governance models are static and siloed, unable to track or restrict what a copilot surfaces on behalf of an over-provisioned user account at query speed.
  • The deployment risk is not the copilot itself but the access posture of the underlying user: organizations that have not enforced least privilege before enabling M365 Copilot are exposing their full over-provisioning problem through an AI interface.
  • Oleria provides composite access visibility and automated least-privilege enforcement to right-size user permissions before copilot activation, preventing the AI assistant from surfacing unintended data.

This summary was created with AI and reviewed by an editor.

Thick black downward-pointing chevron arrow with rounded ends.
Media contact
For media inquiries, contact pr@oleria.com

See adaptive, automated
identity security in action