3 ms·
It's also surprising how quickly companies are giving up their strict access control by letting employees basically search through everything. I'm used to custo
by Manfred 2y ago
It's also surprising how quickly companies are giving up their strict access control by letting employees basically search through everything. I'm used to customers asking for more fine-grained access rules, not less strict.
Given the widespread misuse of these systems (eg. "I'm going to look up my friend's bank account for fun"), that doesn't seem like a great strategy.
- funnybeam 2y agoEmployees can already search through everything. Copilot makes it easier to find things but it runs with the user’s permissions and obeys the existing access rules
- mihaaly 2y ago> Employees can already search through everything. Not in the places I worked. Not at all! There were confidential matters that only people with dedicated responsibility can access and act on. Otherwise it would be a disaster whenever a less honest employee come accross data useful to act on the companies behalf or worse, act directly pretending being one of those eligible people. Then I wonder how this bots handle the info. Are those scanning through what's there and build the knowledge into self? I guess so, otherwise how would know what is what when asked about, if something is a thing and being there at all. And then if having limited access then the bot would be clueless about some important things the people with elevated credentials need. Or, if can scan everything, I mean everything!, then that data is built into the bot, it 'knows' it, so it is just time tricking to give it out to those not eligible. Pretending being someone, or pretending getting received elevated credentails, or who knows what ways could be there to trick and squeeze that knowledge out from these chatty things. Or can be there several different bots, training multitude of bots, some left clueless like an ordinary employee and not let talk to, the CEO having an administrative bot that knows it all? I am jut trying to imagine being complete outsider how these things work.
- funnybeam 2y agoEmployees can already search through everything _they have permission to _ Copilot only has access to whatever the user has access to - it uses the same permissions. The copilot bots in the article are slightly different from normal copilot so might have elevated permissions but if you are creating a service with access to your data then you should make sure it has the correct restrictions in place - there is nothing special about copilot in this regard.
- mihaaly 2y agoBut bots need to be trained on data before use. That the bot will 'soak in'. And have acces to the specific set of data allowed during the training. Which then will be given out at the time being used. Either those bots have access to the very same set of data at training time as the user will have at using time, or there will be trouble (not working with right set of data and miss things, or giving too much not having privilege to normally). Right? Jut trying to understand. So then each user need to use a specific bot trained precisely to the level of acces the user is having. And need proper matching mechanism the right bot to the right user without glitch. Right? Switching bots at changing privilege levels, deserting previously used one for a - for the user - brand new one. Like this?