Copilot readiness and deployment — permissions audited first, then a measured pilot, then rollout to the people who will genuinely use it.
Start with permissions, not licences
The single most important thing to understand about Copilot is that it does not grant anyone new access. It makes existing access usable.
Every SharePoint site, every OneDrive file, every mailbox item a person can already reach is available to Copilot when it answers their questions. In theory that changes nothing. In practice it changes a great deal, because the protection most tenants have been relying on is obscurity — the document was technically accessible, but you would have had to know it existed and go looking.
Ask Copilot a plausible question and it goes looking on your behalf, thoroughly, across everything.
What the audit finds
Consistently, in almost every tenant we assess:
- SharePoint sites shared with “everyone in the organisation” during a project years ago and never tightened
- A folder of salary or performance material with permissions that were correct when it was created and are not now
- Sites belonging to departed staff, still populated, still accessible
- Documents shared via links that never expired
- Broad permissions granted to a group whose membership has quietly expanded
None of this is unusual and none of it reflects negligence. It reflects the fact that permissions drift and nobody has a reason to review them.
Copilot is the reason. And the remediation work is worth doing whether or not you proceed — it is a straightforward governance improvement that was overdue.
Pilot before you commit
Copilot is a per-seat recurring cost and its value varies enormously by role.
People who live in email, meetings and long documents — managers, business development, anyone who spends their week reading and writing — commonly find real time savings. People working inside a line-of-business application all day generally find very little, because that is not where Copilot operates.
A pilot across a handful of different roles, with a defined view of what would count as useful, gives you an actual answer for your business in a few weeks. It costs a fraction of a full rollout and it is the difference between a deployment and a stack of unused licences.
Be straight with staff about what it gets wrong
Copilot fabricates. Fluently and confidently, particularly with numbers, dates and references. It will summarise a twelve-page document accurately, then present a total that appears nowhere in the source.
Staff need to hold two things at once: it is genuinely useful for drafting, summarising and finding, and its output is a draft that requires checking. The failure mode is trusting it because it sounds authoritative, which is exactly what it is optimised to sound like.
A short usage policy — where it may be used, what may be pasted into it, what must be verified before it leaves the business — is worth writing before rollout rather than after an incident. That sits alongside broader AI policy and governance work if you are deploying AI more widely.