What do you need to fix before turning on Copilot?
Fix your file permissions. Microsoft 365 Copilot answers from whatever each person can already open, so years of quiet over-sharing become instantly searchable the day it is switched on. Tidy access across SharePoint, OneDrive and Teams first, agree who owns sensitive locations, and only then deploy.
This is the single most common way a Copilot rollout goes wrong, and it is worth being precise about why, because the instinct is to blame the tool. Copilot does not break permissions or leak anything. It respects your existing access controls exactly. What it removes is obscurity: the salary spreadsheet in a forgotten folder was always readable by half the company, but nobody could find it. Ask a natural-language question and the same file surfaces in seconds.
Over-sharing accumulates innocently, which is why almost every tenant has some. Someone shares a folder with everyone in the organisation to unblock a deadline. A Teams site is created for a project, filled with sensitive material and never cleaned up. An anyone-with-the-link file is emailed to a contractor in 2023 and the link still works. A departing employee's OneDrive is opened up so their replacement can find things. Each was reasonable at the time and none was ever revisited.
So the pre-rollout work is an access audit, and it is more decision than technology. Start where the damage would be worst rather than trying to tidy everything: payroll and HR, finance, executive and board material, legal and contracts, and anything covered by client confidentiality. For each, establish who should have access, compare it against who actually does, and fix the gap. Then sweep the structural patterns: sites shared organisation-wide, sharing links with no expiry, and guest accounts still active long after the project ended.
Two Microsoft-specific habits are worth adopting at the same time. Sensitivity labels let you mark and restrict genuinely confidential material, which gives Copilot and everything else a signal it can respect. And site ownership matters more than people expect: every SharePoint site should have a named owner accountable for who can reach it, because unowned sites are where permissions drift, and drift is the thing you are trying to stop repeating.
There is a second, quieter prerequisite: data hygiene. Copilot draws on what it finds, so a tenant full of duplicate contracts, three versions of the same policy and a decade of superseded price lists will produce confidently wrong answers assembled from stale sources. You do not need a perfect archive, but the current version of important documents should be findable and the obviously dead material should be gone. This is unglamorous work that improves the business whether or not Copilot ever arrives.
None of this is an argument against Copilot, and it is worth saying plainly. The permissions problem existed before anyone mentioned AI, and it was a real risk the whole time: a curious or departing employee could always go looking. What a rollout does is convert a latent problem into an immediate one, which is uncomfortable and also useful, because the tidy-up is overdue in most businesses and rarely gets funded on its own merits.
Design the pilot to find problems rather than to confirm a decision. Include someone from a part of the business with genuinely sensitive material, HR or finance, because they will recognise an answer that should not have surfaced, whereas a pilot group drawn entirely from the keenest early adopters will report only that it is impressive. Ask them explicitly to go looking: what can you find about salaries, about the acquisition, about a colleague. An hour of that is worth more than a month of ordinary use, and anything it surfaces is a permission to fix rather than a reason to abandon the rollout.
The practical sequence, then. Audit access in the high-risk locations. Fix what you find and name owners. Apply sensitivity labels where they matter. Pilot Copilot with a small group and ask them to try to surface something they should not see, which is a far better test than any policy document. Then roll out by role, with the licensing decided separately. Treat the whole exercise as permission hygiene that was owed anyway, and Copilot becomes the reason it finally got done rather than the thing that went wrong. If you want the audit run properly before you switch anything on, call 1800 456 567.
Tidy permissions before the rollout
We audit who can reach what across SharePoint, OneDrive and Teams, fix the over-sharing, then deploy Copilot on ground that will hold.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business