Skip to main content
foundry

Before you switch on Copilot: the oversharing problem

Copilot respects the permissions you already have, which is good news and bad news. How to find what is overshared in your tenant before an assistant does.

Foundry Team

Microsoft's own documentation is clear on two points about Copilot in Microsoft 365: prompts, responses and the data it retrieves through Microsoft Graph are not used to train the underlying models, and it only surfaces content a user already has at least view permission to. Both are reassuring. The second one is also the catch.

The catch

Copilot does not create access. It uses the access you already granted, including the access you granted by accident. Every SharePoint site with "Everyone except external users" on it, every Teams channel that was made public for convenience, every folder someone shared with the whole company in 2019 and forgot: an assistant will search all of it, on behalf of whoever asks.

Before Copilot, an overshared file was a needle in a haystack; someone would have to know it existed. After Copilot, the haystack is searchable by meaning. "What are the partners paid?" is now a reasonable question to type.

What to check before the licence

  1. Site and group permissions. Which sites are open to everyone in the organisation, and should they be? This is the single biggest source of surprise.
  2. Sharing defaults. What happens when someone clicks "share" on a document: a link anyone in the company can open, or a link scoped to specific people?
  3. Sensitivity labels. Copilot honours the usage rights attached to labelled and encrypted content. Labels on the documents that matter (client files, HR, finance) are the strongest control you have, and most small tenants have none.
  4. Stale access. Leavers still in groups. Contractors from finished projects. Shared mailboxes with a dozen members nobody can name.
  5. Restricted search. Microsoft provides controls to exclude specific sites from Copilot and enterprise search while you tidy up. Use them as a bridge, not a destination.

What Copilot is good for, once the tenant is tidy

Document and email assistance inside the tenant boundary: summarising a thread, drafting from your own files, finding the meeting where something was decided. For that job it is often the right answer, and we will say so. Where it stops is at the tenant edge: workflows across other systems, data outside Microsoft 365, models you want to choose yourself, or environments you want to control. That is a different architecture, and a different conversation.

The order of operations

Tidy the estate, label what matters, restrict what you cannot tidy yet, pilot with a small group, then roll out. Reversing that order is how a productivity licence becomes a data incident.

Want help with this in your business?

Talk to Foundry — we’ll talk through your situation, no obligation.

Keep reading

Shadow AI: someone in your firm is already pasting client data into a chatbot

Consumer AI tools have different terms from business ones. If you haven't given people a sanctioned option, they've found their own. What to do this month.
Foundry Team

Prompt injection: the security problem every AI workflow inherits

If an AI system reads untrusted text and can act, someone will put instructions in the text. What prompt injection is and how to design around it.
Foundry Team

Zero trust for a business without a security team

Zero trust sounds like an enterprise programme. For a 30-person firm it is six controls, most already in your Microsoft 365 licence. The practical version.
Foundry Team

Remote-first / UK-wide / one team

Ready for a technology team that can build?

Thirty minutes with an engineer, not a salesperson: what you run today, what’s at risk, what should be automated, and what we’d build or wouldn’t.

30 min call / no pitch / no obligation