ResourcesA shield over a network
Governance

Before You Switch Copilot On

10 September 2026 · 5 min read · By Amit Jaitly

Microsoft 365 Copilot can read everything the user can read. That single sentence is the whole of it, and it is why a Copilot rollout in a regulated firm is a permissions job before it is a training job. Copilot does not open a new door into your files. It walks through the doors that are already open, and it summarises what it finds behind them in a sentence rather than after twenty minutes of clicking. Microsoft is straightforward about this in its own documentation: Copilot surfaces only the content a user already has access to. The difficulty is that in most small firms, nobody has looked at what that access actually is for several years.

We do this work for firms that hold client money, client health data or privileged files, and the same five checks come up every time. None of them is hard. All are far cheaper before the licences go live than after somebody reads a summary of a file they were never meant to see.

Check One: Sharing Links Set To Everyone

The most common finding is also the least dramatic. Somebody needed to send a document to a colleague in a hurry, the sharing dialogue offered a link that anyone in the organisation could open, and they took it. Over four or five years a firm accumulates thousands of these, and each one quietly widens the circle around a file.

Before Copilot, that hardly mattered, because finding those files meant knowing they existed. Copilot changes the economics of the search. Ask it a plausible question about a matter or a client, and it will happily assemble an answer from anything the organisation-wide links have made reachable. Your SharePoint admin reporting will tell you how many of these links exist and where. Start there, because it is usually the largest single exposure and the quickest to reduce.

Check Two: Old SharePoint Sites Nobody Owns

Every firm has them. A site set up for a matter that closed in 2022, a site for an office move, a site somebody built for a project that never started. The person who created it has left, and nobody has opened it in years, so nobody has noticed that its permissions were set loosely on day one and never tightened.

These sites are invisible in daily work and entirely visible to Copilot. Before you switch anything on, list every site, find the ones with no active owner, and make a decision on each: assign an owner, restrict it, or archive it. It is dull work. It is also the difference between a search tool that respects your boundaries and one that does not know you have any.

Check Three: Sensitivity Labels

Labels are how you tell Microsoft 365 which documents are more sensitive than others, and they are how you stop the more sensitive ones being summarised, extracted or forwarded casually. Most small firms we meet either have no labels at all, or have a label scheme that was configured once, explained to nobody, and applied to nothing.

You do not need an elaborate scheme. A handful of labels that map to categories the team already recognises, applied by default where the content is predictable, gets most of the value. What you cannot do is skip the question. Once Copilot is generating new documents from old ones, an unlabelled estate means the sensitivity of the source never travels with the output.

Check Four: Guest Access

Look at who is a guest in your tenant. In a professional firm this list is usually longer than anyone expects: counsel on a matter that settled, an accountant from a previous audit, a contractor from a website build, a client contact who has since moved firms. Each of them was invited for a reason, and the reason has usually expired.

Guests are limited to what has been shared with them, so this is not the biggest of the five risks. It is the one most likely to embarrass you, because an external person retaining access to a live workspace is exactly the finding a regulator or a client's own auditor will write down. Review the list, remove the expired, and set a review date so the list does not grow back.

Check Five: A Written Record Of Who Can See What

The first four checks change your configuration. This one changes your position. When a client, an insurer or a regulator asks how you decided that an AI assistant could be pointed at your files, the answer needs to be a document, not a recollection.

It does not have to be long. What was assessed, what was found, what was changed, who signed it off, and when it will be reviewed. Write it as you do the work, not afterwards: the details that matter are the ones you forget within a fortnight. A firm that can produce that record is in a different conversation from one that cannot.

What To Do This Week

Two things, in order.

First, pull the sharing report for your tenant and count the organisation-wide links. You are not fixing them yet. You are finding out the size of the problem, and that number will tell you whether this is a two-week piece of work or a two-month one.

Second, list your SharePoint sites and mark the ones with no active owner. Unowned sites are a live problem in their own right, and clearing them is the single change that most improves what happens on the day you do switch Copilot on.

None of this is a reason to avoid Copilot. It is a good tool, and firms that adopt it deliberately get real value from it. It is a reason to spend a fortnight on permissions first, so that what the tool can see is what you decided it should see.

Sources

Amit Jaitly

Amit Jaitly is the founder of JMC Solutions, an AI training and implementation firm for UK SMEs.

Not Sure Where You Stand?

If you would like a second pair of eyes on how your firm uses AI, we'd be glad to talk it through. No pitch, just a conversation about what would work for you.

Schedule A Discovery Call