HR leaders and People leads at M365 organizations where candidate screening, performance reviews, and headcount conversations live in Teams and Outlook, and where Scout Autopilot goes live in the tenant without a consent or data access policy in place.
Microsoft Scout launches with read and action access across Teams, Outlook, OneDrive, SharePoint, and contacts by default.
The same week, Microsoft announced MAI-Transcribe-1.5, a multilingual transcription model now inside M365, and Project Solara, an always-on agent device platform already being explored by major retailers.
HR conversations do not live in a separate protected system. They live in the same channels Scout is built to read and act on.
Relve rates this 78/100, a high signal for HR leaders and People leads at M365 organizations where Scout becomes active in the tenant and where no consent or data access policy currently covers autonomous agent access to HR data.
The data access question is not theoretical. Scout reads by default. The Intune policy is the only mechanism that creates a boundary. Without it, there is no boundary.
Scout’s default access to HR data is one of three infrastructure shifts that pushed founders and CTOs into simultaneous decisions this quarter. The series also covers Engineering, Operations, and Marketing.
Scout Has Read Access to Your Candidate Threads, Performance Reviews, and Headcount Calls
Every AI governance conversation in HR has assumed a clear boundary: AI tools assist with specific tasks, and sensitive HR data lives in protected systems behind named access controls. Scout breaks that assumption.
Scout holds its own Entra identity in the organizational directory. Its read access covers Teams chats, Outlook email, OneDrive, SharePoint, calendar, and contacts by default.1
That is the same data footprint as a fully onboarded human employee with standard M365 access.
The candidate screening thread in Teams. The performance review prep in a manager’s Outlook drafts folder. The headcount discussion in a leadership group channel.
Scout has read access to all three unless the Intune policy explicitly excludes those channels and folders.
The hiring decision trail that HR teams have been building toward with meeting intelligence tools is now native to M365. The difference is that Scout acts on that data, not just records it.
Project Solara, announced at Microsoft Build 2026, takes the agent device question into physical workplaces.2 Best Buy, CVS, Target, and Levi Strauss are already exploring adoption.
The r/Engadget community’s reaction captured the immediate tension between the productivity framing and the workplace monitoring implications.
Posts from the r/Engadget community on Reddit
The community reaction reflects a genuine gap. Microsoft framed Solara as an enterprise productivity platform. The immediate question from the audience was about consent, monitoring, and what employees would know about what the device was capturing.
HR has no written answer to that question yet.
Scout holds its own directory identity. It is not a human employee but it carries equivalent read access. That distinction matters for how HR writes the access policy, not just whether it writes one.
The People Function Has Three New Data Access Problems and No Policies for Any of Them
A People lead is preparing for a sensitive performance review. The conversation happens in a Teams call. The follow-up lands in Outlook. The headcount decision gets discussed in a leadership group channel.

Scout has read access to all three by default and will surface them as context when preparing materials for the next meeting involving anyone in that thread.
No malicious intent. No breach. Just an agent doing exactly what it was built to do with data it was given permission to read.
The governance decision is not whether to use Scout. It is what boundary to set before it activates. The Intune policy is the only mechanism that creates that boundary.
| Dimension | Before Scout | After Scout |
|---|---|---|
| HR conversation data access | Teams and Outlook readable only by named participants | Scout has read access across Teams, Outlook, and contacts by default unless Intune policy excludes channels |
| Interview transcription | Manual notes or third-party tools with a separate consent flow | MAI-Transcribe-1.5 available inside M365 by default; candidate consent protocol needed before first use |
| Employee-facing agent devices | No always-on agent devices in workplace environments | Project Solara: major retailers exploring; agent devices running continuously with access to organizational data |
| HR policy requirements | Standard data governance covering human participant access | New written policy needed for agent identity access, transcription consent, and device monitoring scope |
The Intune Policy Is the Only Boundary Between Scout and Your HR Data
Scout requires Frontier enrollment, Intune policy configuration, and opt-in attestation before any user can access it.1 The Intune policy defines Scout’s data access scope.
Without a configured policy, Scout’s access defaults to everything it can technically reach.
HR channels, threads, and folders that need explicit exclusion include: candidate evaluation threads and channels, performance review prep emails and calendar invites, headcount and compensation discussions, and outplacement or termination correspondence.
The Intune policy works. It only works if configured before Scout activates in the tenant, not after.
Retrofitting access boundaries once an agent has been reading data is harder than setting them upfront. The audit trail of what Scout accessed before the policy was configured becomes a compliance question with no clean answer.
BIPA exposure is active from the moment MAI-Transcribe-1.5 is used in a hiring or performance conversation without documented candidate consent. Illinois, Texas, and Washington each have biometric data laws that require prior written consent before capturing voice-derived identifiers. Template consent language needs legal review before the first use, not after the first complaint.
MAI-Transcribe-1.5 Started a Consent Clock HR Did Not Know Was Running
MAI-Transcribe-1.5 is now available inside M365 as a multilingual transcription model.4 There is no separate tool to install and no separate consent flow unless HR builds one. The transcription capability is simply available in the environment HR already operates in.
Candidate consent before any interview or performance conversation is transcribed must be documented and retrievable, not verbal.
The consent protocol needs to define what happens when a candidate declines transcription, how the consent record is stored, and who owns the consent audit trail.
The risk is not that Microsoft will misuse the transcription data.
The risk is that HR deploys a transcription capability inside a familiar tool without treating it as a separate consent event, because it does not look like a separate tool.
Project Solara and the Workplace Agent Device Question
Project Solara is an Android-based platform for always-on agent devices, announced at Microsoft Build 2026.2 Best Buy, CVS, Target, and Levi Strauss are among the retailers already exploring it.
Microsoft demonstrated it running on a smart display and a smart key badge at the Build keynote.
For HR leaders at organizations with physical retail or distributed workforces, agent devices raise questions that existing monitoring policies have not been written to cover.
What does the device capture continuously? Where is that data stored? What employee notice is required before deployment?
Most HR monitoring policies were written for software tools with clearly bounded functions. An always-on agent device with access to organizational data and the ability to act on behalf of a user is a different class of workplace technology.
The policy gap is not a legal technicality. It is a genuine absence of written rules for a scenario now moving from concept to pilot.
Scout Landed in the HR Data Layer and Most People Teams Are Still Waiting for IT to Handle It.
Most Build 2026 analysis focused on Scout’s productivity gains for scheduling and coordination, MAI-Code-1-Flash for engineering teams, and the compute infrastructure announcements. HR barely appeared in the coverage.
That is the honest admission here: the data access scope of Scout is a People function problem first because HR data lives in the same channels as everything else.
It is not siloed. It is not separately permissioned by default. It is readable by any actor with standard M365 access, including Scout.
Most analyses focus on what Scout can do for scheduling and coordination. The more useful read for HR leaders is what Scout has access to by default, and what consent obligations that creates before it goes live.
The second thing most coverage missed is the category precedent. Scout is Autopilot number one.
HR’s consent and access policies written for Scout will need to extend to every subsequent Autopilot Microsoft ships. Writing a thorough policy now costs a fraction of retrofitting it across three or four agents running simultaneously in the tenant.
The expansion of AI governance into critical infrastructure AI is the broader context HR leaders are operating in.
Scout is not a frontier model deployment. But the consent and data access questions it raises are structurally the same ones that governance frameworks are being built to address at scale.
Three HR Policies That Need to Exist Before Scout Goes Live
The Intune policy configuration is the only mechanism that creates a data access boundary for Scout.1 HR needs to give IT a specific, written list of channels, folders, and threads to exclude before the policy is configured.
- Candidate evaluation threads and channels by name
- Performance review prep emails and related calendar invites
- Headcount, compensation, and salary discussion threads
- Sensitive termination and outplacement correspondence folders
This list does not require a legal review. It requires HR and IT to sit together for 60 minutes and map the data before the policy goes live.
MAI-Transcribe-1.5 is available now inside M365.4 Candidate and employee consent must be obtained and documented before any interview or performance conversation is transcribed.
- Written consent required before any interview or performance conversation is transcribed
- Consent must be documented and retrievable, not verbal
- BIPA-specific language required for Illinois, Texas, Washington, and any equivalent jurisdiction
- Template consent language needs legal review before first use
- Define what happens when a candidate declines transcription
Project Solara is moving from concept to pilot at major retailers.2 HR policy needs to exist before any pilot begins in your organization, not after the first employee raises a monitoring objection.
- What data does the agent device capture continuously in a workplace environment
- Where is that data stored and for how long
- What employee notice and consent is required before deployment
- What the HR escalation path is if an employee raises a monitoring objection
- Who owns the policy: HR, Legal, or IT
Where This Leaves HR Leaders
Three new data access problems arrived in the HR environment in the same week, each through a different door. Scout through the M365 directory. MAI-Transcribe-1.5 through the productivity suite. Project Solara through the workplace device layer.
None of them require a new tool procurement decision. All of them require a written policy before they go live.
HR leaders who map the Scout exclusion list this week, build the transcription consent protocol this month, and write the Solara device policy before any pilot begins will hold the policy foundation that makes every subsequent Autopilot easier to govern.
Those who wait will write each policy reactively, under pressure, after the event that made it unavoidable.
References
1 Microsoft Build Live, “Microsoft Build 2026 Live Blog,” June 2-3, 2026.
2 Memeburn, “Microsoft Build 2026: 7 Biggest AI Announcements You Need to Know,” June 5, 2026.
3 Digital Applied, “Microsoft Scout: The Personal AI Agent Goes Mainstream,” June 2, 2026.
4 Microsoft Blog, “Microsoft Build 2026: Be yourself at work,” June 2, 2026.
