Copilot reads what the user is allowed to read. In most organisations that turns out to be far more than expected — and it is the real work before rollout.
Open shares, “anyone in the organisation” links, orphaned sites, libraries inherited from a closed project. Copilot does not create this problem, it surfaces it in one query.
Sensitivity labels applied where they matter, and retention policies consistent with your actual obligations.
A pilot group chosen for usefulness, not enthusiasm. Expansion follows usage measurement, not the calendar.
Who uses it, on what, and who stopped after three weeks. That last figure is the most instructive and almost never collected.
What an ordinary user can reach today. The report is often uncomfortable; it is also the best argument for funding the clean-up.
Across the perimeter that matters, not the whole tenant. A complete clean-up never ends; a targeted one is delivered.
Short training, concrete use cases per function, and a feedback loop that leads to real changes.
Progressive, with usage measurement as the criterion. A wave that is not used is not followed by another.
The benefit goes beyond Copilot: it counts for data leakage, audit and compliance.
You know who uses what. That makes licence renewal a decision rather than a default.
Who decides access, how a new site is classified, and who answers when sensitive data appears where it should not.
The exposure assessment happens before the licences are bought. That is when it costs least.
See your external surface →