← The Journal

Microsoft Work IQ, explained for wealth managers: what it grounds, what it reaches, and what it doesn't restrict

If you run a wealth management firm or a family office, you have spent the last year being told Microsoft Copilot is the answer to AI. The story just got more interesting. Microsoft has opened up the intelligence layer that sits underneath Copilot, a system called Work IQ, and made it available to outside AI assistants like Claude and ChatGPT through a standard connection protocol. On paper that sounds like the last hard problem got solved. Point your AI of choice at Microsoft 365, and it instantly understands how your firm works.

It is an important development, and Work IQ is good at what it does. But for a firm with fiduciary obligations, it answers a question you were probably not asking, and it leaves the question you were asking mostly untouched. This post explains what Work IQ is, in plain terms, why it matters, and where the line falls between what it does well and what it was never built to do.

What Work IQ actually is

Start with the problem it solves. When an AI assistant connects to Microsoft 365 the naive way, it can retrieve documents. It can find a file, read an email, pull a calendar entry. What it cannot do is understand how those things relate. It does not know that "the Meridian deal" spans a particular set of memos, a Teams channel, six meetings, and four people. It retrieves. It does not comprehend.

Work IQ is Microsoft's answer to that gap. In Microsoft's own words, it is a workplace intelligence layer that lets agents access and reason over organizational data, context, and tools, continuously building a semantic understanding across Microsoft 365 and connected systems. Microsoft describes it as three layers. Data unifies the signals from files, emails, meetings, chats, and business systems. Memory builds a persistent understanding of how people and teams work. Inference connects that context to models and tools so an agent can reason and act on it.

The practical result is a shift from retrieving information to receiving understanding. Instead of your AI assistant getting back a pile of search results, it gets back context with the dots already connected. This document matters because of this project, which involves these people, who just had this meeting. For an analyst asking a nuanced question across a messy pile of firm content, that is a real improvement, and it is why Microsoft now calls Work IQ the recommended foundation for building agents on Microsoft 365 data.

The newer news is reach. Work IQ exposes itself through open protocols, including the Model Context Protocol (MCP), the same standard that lets assistants like Claude connect to outside tools. So the intelligence layer under Copilot is no longer Copilot-only. An AI assistant running outside Microsoft's own products can, with the right setup, tap the same grounded understanding of your tenant. If you have deliberately chosen a model-agnostic path, and we think most finance firms should, that is a meaningful door opening.

Why this matters for a wealth manager or family office

Here is the part worth slowing down on. Work IQ's design principle, stated repeatedly in Microsoft's documentation, is that access is permission-aware. The agent sees what the user is allowed to see, automatically trimmed against that person's existing rights across Microsoft 365. That is the right default for most of the working world. The AI cannot show a junior employee something their manager locked down. It respects the permission structure you already have.

And that is exactly where the problem starts for a firm like yours.

A permission-aware system answers one question very well. What can this user reach? It inherits the human's access and mirrors it to the agent. But in a wealth management firm or a family office, the people with their hands on the AI are often the partners, the principals, the senior advisors. Those people can reach almost everything. Estate planning documents. Compensation data. The deal pipeline. Client financials across every household. Decades of folder access nobody has audited since the firm was half its current size.

So when you point a permission-aware AI assistant at that environment, "the agent sees what the user can see" is not reassurance. It is the whole problem restated. The question a fiduciary actually needs answered is a different one.

Not what can this user reach? The question is what should this agent reach?

Those are not the same question, and no amount of permission-mirroring turns one into the other. A managing partner is entitled to open the estate file. That does not mean an AI agent, answering a routine portfolio question, should pull from it, surface it in a summary, or cite it in a draft. The entitlement belongs to the person and their judgment. The agent has neither.

This is the gap permission-aware design leaves open by construction. Not through any flaw in Work IQ, but because scoping an agent below the level of its operator's own access was never the job the layer set out to do.

What Work IQ doesn't restrict, and the honest caveats

A few boundaries are worth stating plainly, because the marketing around any new Microsoft capability tends to blur them.

Work IQ scopes to the user, not to the task. Its reach spans mail, calendar, files, people, chat, and sites, and that breadth is a feature. But it means an agent grounded in Work IQ can draw on signals from across a person's entire Microsoft 365 footprint. If your concern is "this agent should only ever touch this body of content, no matter who is driving it," permission-trimming does not give you that boundary. It gives you the operator's boundary, which is a different and usually much larger thing.

It is new, and it is moving fast. Several of the per-application Work IQ connectors are in preview, and Microsoft notes that availability and capabilities may change. That is normal for a capability this young. It also means anything you build against it today should be built by someone tracking the changes, not set and forgotten.

The licensing picture is unsettled in practice. Microsoft's documentation says Work IQ API access is independent of a Microsoft 365 Copilot license and billed by usage on Copilot Credits. In the field, teams have reported authenticating fine and then hitting "Forbidden" errors when a user lacks Copilot licensing. That gap between the documented model and the observed behavior is the kind of thing that turns a two-week pilot into a two-month one if you find it late. Budget for licensing reality, not licensing theory.

None of this is a knock on the product. It is the difference between a firm's data intelligence layer and a firm's access-control layer. Two different jobs. Work IQ is very good at the first. It does not claim to be the second.

The pattern that closes the gap: enforce below the model

If permission-mirroring cannot answer "what should this agent reach," what can? The answer is an old idea in a new place. Put the enforcement below the model, in a layer the agent cannot argue with.

In practice that means a policy checkpoint between the AI assistant and the data, a gateway every request passes through. Instead of inheriting the operator's sprawling permissions, the agent gets a deliberately scoped set of resources. This library, these strategies, this classification and no higher. The rules are simple and finance-shaped.

Scope the agent, not the user. The operator's own access is irrelevant to what the agent may retrieve. Policy defines the agent's reach, mapped to the firm's security groups, rather than borrowing it from whoever happens to be typing.

Deny by default. Anything not explicitly permitted is withheld. New content that shows up unclassified stays invisible to the agent until someone classifies it, instead of being exposed until someone remembers to lock it down.

Log every decision. Every permit and every denial is an audit event, with the caller, the resource, the classification, and the outcome. That is the evidence a compliance review or an examiner will ask for, and "the AI just knew not to" is not an acceptable answer.

Enforce where the model cannot reach it. Because the agent never receives withheld content, no clever prompt can extract it. Filtering through an instruction, "please don't reveal the estate file," is the exact anti-pattern this design replaces. What the model never sees, it cannot leak.

If this sounds familiar to anyone who has worked in a regulated firm, it should. It is the AI-era version of an information barrier. The concept your compliance team already understands, walls between functions and need-to-know access with documented enforcement, applied to an agent instead of a person. Work IQ can be the intelligence layer feeding a well-governed agent. The governance itself has to live somewhere the agent's operator, however senior, cannot casually widen.

Where this leaves you

Work IQ is a real step forward, and if your firm builds on Microsoft 365, it belongs in the conversation. It makes AI assistants, Microsoft's own and increasingly model-agnostic ones like Claude, smarter about how your firm actually works. That is worth having.

But do not mistake a smarter assistant for a governed one. Permission-aware grounding answers what a user can reach. A fiduciary has to answer what an agent should reach, and that takes an enforcement layer scoped to the agent, denying by default, logging every decision, sitting below the model where no prompt can get to it. Work IQ does not provide that layer, and it is not something to improvise. Design it deliberately, against your real tenant, with your real permission history and your real compliance obligations in view.

That deliberate, finance-native design is the work we do. We build permission-aware AI systems for wealth managers and family offices, connected to the tools your firm already runs on, with the secure data connectivity finance demands, and with governance that holds up to scrutiny rather than hoping the model behaves.


Wondering what your AI assistant can actually reach inside your tenant, and what it should? We would welcome a 20 to 30 minute conversation to walk through where AI creates real value for your firm and how to scope it safely. No commitment, just a practical look at what secure, governed AI adoption looks like at your stage. Request a demo to get started.

West Stack — weststack.io

Microsoft Work IQ for Wealth Managers, Explained | WestStack