All insights

What do you need to fix before turning on Copilot?

5 min readBy Brendon Whiting, Founder · 10 July 2026

Fix your file permissions. Microsoft 365 Copilot answers from whatever each person can already open, so years of quiet over-sharing become instantly searchable the day it is switched on. Tidy access across SharePoint, OneDrive and Teams first, agree who owns sensitive locations, and only then deploy.

This is the single most common way a Copilot rollout goes wrong, and it is worth being precise about why, because the instinct is to blame the tool. Copilot does not break permissions or leak anything. It respects your existing access controls exactly. What it removes is obscurity: the salary spreadsheet in a forgotten folder was always readable by half the company, but nobody could find it. Ask a natural-language question and the same file surfaces in seconds.

Over-sharing accumulates innocently, which is why almost every tenant has some. Someone shares a folder with everyone in the organisation to unblock a deadline. A Teams site is created for a project, filled with sensitive material and never cleaned up. An anyone-with-the-link file is emailed to a contractor in 2023 and the link still works. A departing employee's OneDrive is opened up so their replacement can find things. Each was reasonable at the time and none was ever revisited.

So the pre-rollout work is an access audit, and it is more decision than technology. Start where the damage would be worst rather than trying to tidy everything: payroll and HR, finance, executive and board material, legal and contracts, and anything covered by client confidentiality. For each, establish who should have access, compare it against who actually does, and fix the gap. Then sweep the structural patterns: sites shared organisation-wide, sharing links with no expiry, and guest accounts still active long after the project ended.

Two Microsoft-specific habits are worth adopting at the same time. Sensitivity labels let you mark and restrict genuinely confidential material, which gives Copilot and everything else a signal it can respect. And site ownership matters more than people expect: every SharePoint site should have a named owner accountable for who can reach it, because unowned sites are where permissions drift, and drift is the thing you are trying to stop repeating.

There is a second, quieter prerequisite: data hygiene. Copilot draws on what it finds, so a tenant full of duplicate contracts, three versions of the same policy and a decade of superseded price lists will produce confidently wrong answers assembled from stale sources. You do not need a perfect archive, but the current version of important documents should be findable and the obviously dead material should be gone. This is unglamorous work that improves the business whether or not Copilot ever arrives.

None of this is an argument against Copilot, and it is worth saying plainly. The permissions problem existed before anyone mentioned AI, and it was a real risk the whole time: a curious or departing employee could always go looking. What a rollout does is convert a latent problem into an immediate one, which is uncomfortable and also useful, because the tidy-up is overdue in most businesses and rarely gets funded on its own merits.

Design the pilot to find problems rather than to confirm a decision. Include someone from a part of the business with genuinely sensitive material, HR or finance, because they will recognise an answer that should not have surfaced, whereas a pilot group drawn entirely from the keenest early adopters will report only that it is impressive. Ask them explicitly to go looking: what can you find about salaries, about the acquisition, about a colleague. An hour of that is worth more than a month of ordinary use, and anything it surfaces is a permission to fix rather than a reason to abandon the rollout.

The practical sequence, then. Audit access in the high-risk locations. Fix what you find and name owners. Apply sensitivity labels where they matter. Pilot Copilot with a small group and ask them to try to surface something they should not see, which is a far better test than any policy document. Then roll out by role, with the licensing decided separately. Treat the whole exercise as permission hygiene that was owed anyway, and Copilot becomes the reason it finally got done rather than the thing that went wrong. If you want the audit run properly before you switch anything on, call 1800 456 567.

Tidy permissions before the rollout

We audit who can reach what across SharePoint, OneDrive and Teams, fix the over-sharing, then deploy Copilot on ground that will hold.

Frequently asked questions

No, and that is precisely the problem. Copilot respects every permission you have set; it simply makes their consequences visible at conversational speed. Files that were technically reachable but practically buried become findable by asking a question. Nothing changed except how easy it is to notice what was already true.

Microsoft 365 admin tooling reports sharing links and site permissions, and the patterns to hunt are anyone-with-the-link files, sites shared with everyone in the organisation, and guest accounts that outlived their project. Start with HR, finance and executive locations rather than trying to boil the whole tenant, because that is where exposure costs most.

For a typical small business, days rather than months, and the work is more decision than technology: someone has to say who should be able to see payroll. Sites created ad hoc over years are the slow part. Doing it before a rollout is far cheaper than doing it after somebody asks Copilot a question and gets an answer they should not have.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.