AI Governance for Microsoft 365
Every AI retrieval.
Enforced. Logged. Proven.
Gatepost enforces per-agent access controls on every SharePoint AI query - and produces the audit evidence your regulators will ask for.
Each block is a document chunk an AI agent requested. The gate line enforces your policy - only cleared chunks reach the model.
0
Enforcement steps on every query
Zero exceptions
Average enforcement overhead
Non-blocking audit writes
0%
In-tenant deployment
Zero data egress
12
Direct SharePoint connections
All access through gateway
What Gatepost Enforces
What Microsoft Native
Tooling Doesn't Provide
Purview handles data classification. It was never designed to govern AI agent retrieval. These are the six critical gaps Gatepost closes.
Per-Agent Access Control
Enforce sensitivity thresholds per agent identity - not just per user. Microsoft native tooling has no concept of agent-level data access limits.
Chunk-Level Audit Trail
Log every document chunk retrieved by every agent, with the exact policy version active at retrieval time. Purview logs file-level access, not retrieval context.
In-Tenant Deployment
Gatepost runs as Azure resources in your subscription. No document content, query data, or audit records leave your environment.
Classification Enforcement
Block non-compliant retrievals before they reach the model context window. Prevention at query time, not detection after the fact.
Policy Evidence
Immutably record which policy was enforced at the exact moment of retrieval - essential for audit defense in regulated environments.
Deploys Inside Your Tenant
Every component - gateway, index, audit store, and keys - is owned by your Azure tenant and governed by your security controls.
How Gatepost Works
From agent query to audit evidence in milliseconds.
Agent sends query
Your Azure OpenAI agent calls the Gatepost retrieval gateway instead of querying SharePoint directly.
Seven-step enforcement
Identity, policy, classification, and scope are validated in sequence. Non-compliant queries are blocked with a structured denial record.
Results returned
Only the chunks the agent is permitted to see are returned. Every result is tagged with the classification and policy version that governed it.
Audit record written
An immutable record of every decision - allow or deny - is written to your PostgreSQL governance store. Your auditor can query it directly.
The governance layer your AI stack is missing.
Real enforcement. Real audit trail. Real evidence.

Platform
Five modules.
One governance layer.
Gatepost wraps your Microsoft 365 AI stack - from SharePoint indexing to Copilot queries - with a structured enforcement and audit architecture that regulators can verify.
Explore all five modulesPermission Intelligence
Map every SharePoint, OneDrive, and Teams permission against your sensitivity labels. Surface overprivileged service accounts before agents inherit excessive access.
Governed Indexing
Intercept the indexing pipeline. Apply classification ceilings at ingest time so agents only ever see data they're permitted to retrieve.
Retrieval Gateway
Seven-step enforcement sequence at every RAG query: identity resolution, agent policy lookup, classification check, ceiling enforcement, retrieval, audit log, response release.
Time to Value
Four weeks to
board-ready compliance.
Week 1
Permission Risk Visibility
Full map of AI-accessible data vs. sensitivity labels. Immediate overprivilege alerts.
Week 2
Governed Indexing Live
Classification ceilings applied at ingest. New agent retrievals are policy-constrained from day one.
Week 3
First Agent Registered
Your highest-risk Copilot or custom agent enrolled. Retrieval gateway active. Audit trail running.
Week 4
Board-Ready Report
Week 4: CISO receives a PDF compliance report mapping every AI retrieval to the policy version and permission snapshot that governed it.
Ready to deploy
Govern your Microsoft 365
AI deployments.
We'll show you the exact enforcement record your auditor will ask for.