Interest in Microsoft Copilot and similar assistants is high among the businesses we support, and the technology is worth exploring. But the most common outcome of switching it on without preparation is not productivity — it is a staff member discovering a salary spreadsheet they were never meant to see. AI tools respect permissions precisely; they do not fix them.
1. Clean up permissions and sharing
Over years, SharePoint and OneDrive accumulate "Anyone with the link" shares, orphaned sites and groups with everyone in them. Before any assistant is enabled, audit what is shared with whom, close the over-broad shares, and set a sensible default for new sharing. This alone is usually a small project, and it pays off whether or not Copilot follows.
2. Get identity in order
Multi-factor authentication everywhere, no shared accounts, a clean process for leavers, and conditional-access policies that limit where and how people sign in. AI features are powerful precisely because they act with the user's full access — so the user's access needs to be right.
3. Decide where data may and may not go
Enterprise Microsoft 365 AI tools keep your data inside your tenant under your policies — that is one of their advantages over consumer tools staff may already be using. Set the policy explicitly: which tools are approved, what may not be pasted into public assistants, and how sensitive documents are labelled. Sensitivity labels and data-loss prevention are the mechanisms; a short written policy is the starting point.
Then pilot, with real tasks
Start with ten people who have real, repetitive work — summarising meetings, drafting responses, digging through long email threads — and measure what changes over a month. That produces a decision based on your business rather than on a demo.
If you are considering Copilot, we can run a readiness check on your tenant — permissions, identity, licensing — and tell you what needs fixing first. It is delivered by the same team that manages your environment, under the same accountability.

