Skip to content

Playbook · 9 minute read

Review permissions before Copilot can surface them

Use the pilot as a reason to find oversharing, stale access, and unclear content ownership.

Copilot follows existing access

Microsoft states that Copilot only accesses organizational data a user is authorized to access. That protection depends on the quality of the permissions already in Microsoft 365.

A technically allowed file can still be broader than the organization intended. Review sensitive and high-value locations before inviting a pilot group to search and summarize across them.

Start with high-risk collections

Inventory sites and libraries containing donor, participant, human resources, legal, financial, safeguarding, credential, or board-confidential material. Assign an owner and document who needs access now.

Fix access at the source

Remove stale memberships, overly broad sharing, obsolete public links, and duplicate sensitive files through normal governance. Do not rely on a prompt rule to correct a permission problem.

Primary sources

Check Microsoft before acting.