Before you switch on Copilot: the oversharing problem
Copilot respects the permissions you already have, which is good news and bad news. How to find what is overshared in your tenant before an assistant does.
Microsoft's own documentation is clear on two points about Copilot in Microsoft 365: prompts, responses and the data it retrieves through Microsoft Graph are not used to train the underlying models, and it only surfaces content a user already has at least view permission to. Both are reassuring. The second one is also the catch.
The catch
Copilot does not create access. It uses the access you already granted, including the access you granted by accident. Every SharePoint site with "Everyone except external users" on it, every Teams channel that was made public for convenience, every folder someone shared with the whole company in 2019 and forgot: an assistant will search all of it, on behalf of whoever asks.
Before Copilot, an overshared file was a needle in a haystack; someone would have to know it existed. After Copilot, the haystack is searchable by meaning. "What are the partners paid?" is now a reasonable question to type.
What to check before the licence
- Site and group permissions. Which sites are open to everyone in the organisation, and should they be? This is the single biggest source of surprise.
- Sharing defaults. What happens when someone clicks "share" on a document: a link anyone in the company can open, or a link scoped to specific people?
- Sensitivity labels. Copilot honours the usage rights attached to labelled and encrypted content. Labels on the documents that matter (client files, HR, finance) are the strongest control you have, and most small tenants have none.
- Stale access. Leavers still in groups. Contractors from finished projects. Shared mailboxes with a dozen members nobody can name.
- Restricted search. Microsoft provides controls to exclude specific sites from Copilot and enterprise search while you tidy up. Use them as a bridge, not a destination.
What Copilot is good for, once the tenant is tidy
Document and email assistance inside the tenant boundary: summarising a thread, drafting from your own files, finding the meeting where something was decided. For that job it is often the right answer, and we will say so. Where it stops is at the tenant edge: workflows across other systems, data outside Microsoft 365, models you want to choose yourself, or environments you want to control. That is a different architecture, and a different conversation.
The order of operations
Tidy the estate, label what matters, restrict what you cannot tidy yet, pilot with a small group, then roll out. Reversing that order is how a productivity licence becomes a data incident.
Want help with this in your business?
Talk to Foundry — we’ll talk through your situation, no obligation.