Audit your agent files — before the AI leaks your data
Addyo is asking a question that most teams aren't asking yet: what files are your AI agent actually reading? The post walks through a practical method for auditing which documents your LLMs have access to — the spreadsheets, the internal wikis, the customer emails. Because the moment you let an agent search your company files, it's reading more than you think.
The risk is real. Agents don't just see what you hand them — they see what's in the search index, what's been uploaded, what the permissions let them touch. If your sales docs are in the same bucket as your HR files, the agent can read them. If your customer PII is in the same index as your marketing copy, it's in there too. This is how data leaks happen quietly, without anyone turning on a firewall.
The fix is simple and often overlooked: list what the agent can see, then cut what it doesn't need. Don't give it broad file access. Don't dump everything into the knowledge base. Give it only what it needs for the job, and audit quarterly. The people building these tools know this already — the ones who sleep at night. The rest are still figuring out what they gave away.
Why this matters for us: Brown folks run side businesses and consultancies with one person handling everything — this is how you accidentally leak customer data without noticing until it's too late.