Skip to content
Govern Copilot 44 checkpoints

Copilot Readiness Governance Checklist

Microsoft 365 Copilot answers from everything a user can already open. Before you switch it on: find the oversharing, contain it, classify what matters. That's how Copilot stays an assistant instead of a leak.

Last reviewed May 16, 2026 · 7 pages in print

Before you start

Copilot mirrors your permissions

Microsoft 365 Copilot does not open new holes in your security. It reflects the ones already there. It answers a question from any file the person asking can already open. A document that was overshared but buried was safe by obscurity; Copilot removes the obscurity and reads it aloud. So readiness is not a Copilot setting. It is permission cleanup, containment, and classification, done before the first licence is assigned. This checklist runs that work in order.

What to know before you begin
ItemWhat it means
Permission-trimmed Copilot only returns content the person prompting it already has at least view access to. Nothing more, nothing less.
Oversurfacing The risk is not new access. It is discovery. Copilot finds and summarizes the overshared files nobody knew were reachable.
“Everyone except
external users”
The most common oversharing claim. It reaches your whole organization, and so does Copilot on its behalf.
Sensitivity labels Copilot honors a label’s encryption. A user who can only view a labelled file cannot have Copilot extract from it.
The tooling The oversharing reports and controls used here are included once the tenant has one Microsoft 365 Copilot licence.
E5 markers A few checkpoints need Microsoft 365 E5 or the E5 Compliance add-on. They are marked. Everything else works on Business Premium.

The eight stages

  1. 1Understand the exposure and confirm licensing5 checkpoints
  2. 2Map the oversharing6 checkpoints
  3. 3Apply the interim safety valve5 checkpoints
  4. 4Remediate permissions6 checkpoints
  5. 5Build the sensitivity-label foundation5 checkpoints
  6. 6Classify and protect the back-catalogue6 checkpoints
  7. 7Configure Copilot’s own controls6 checkpoints
  8. 8Make governance ongoing5 checkpoints

Stage one · Understand

Understand the exposure and confirm licensing

5 checkpoints

  • Accept the premise: Copilot returns anything the person prompting it can already open. The work is fixing permissions, not Copilot.
  • Count your Microsoft 365 Copilot licences and confirm SharePoint Advanced Management is active. It ships with the first Copilot licence.
  • Identify your tenant’s licence tier. Most of this checklist works on Business Premium; the items marked E5 need Microsoft 365 E5.
  • Choose the pilot group: a small set of users who get Copilot first, while the rest of the cleanup runs.
  • Brief leadership that “find the oversharing” comes before “turn on Copilot”, and that the work takes real time.

Stage two · Find

Map the oversharing

6 checkpoints

  • Turn on Data Access Governance data collection in the SharePoint admin centre.
  • Run the organization-wide site permissions report. This is your baseline of who can reach what.
  • Run the “Everyone except external users” report. It is the single biggest oversharing vector.
  • Run the sharing-links report. Find “Anyone” links and organization-wide links.
  • Flag ownerless and inactive sites. Nobody is watching what they expose.
  • Rank every site by exposure against content sensitivity. Produce a high-risk list.

Stage three · Contain

Apply the interim safety valve

5 checkpoints

  • Decide your valve: Restricted Content Discovery per site, or Restricted SharePoint Search tenant-wide.
  • Apply Restricted Content Discovery to the high-risk sites. It hides them from Copilot and search without changing permissions.
  • If oversharing is pervasive, enable Restricted SharePoint Search with a curated allow-list of up to 100 sites. Set an exit date; it is temporary.
  • Use Restricted Access Control to lock a critical site to a single security group.
  • Verify, after about an hour, that Copilot no longer surfaces the excluded content.

Stage four · Remediate

Remediate permissions

6 checkpoints

  • Delegate site access reviews to site owners. They can see the item-level detail an admin cannot.
  • Remove or replace “Everyone except external users” on the sites the reports flagged.
  • Expire or revoke stale “Anyone” and organization-wide sharing links.
  • Fix broken permission inheritance where it is not deliberate.
  • Set the tenant default sharing link to “Specific people”. Set link expiry.
  • Re-run the reports on the high-risk sites. Confirm the exposure is actually down.

Stage five · Classify

Build the sensitivity-label foundation

5 checkpoints

  • Define a short label taxonomy: four or five labels such as Public, Internal, Confidential, Highly Confidential.
  • Enable sensitivity labels for files in SharePoint and OneDrive. Without this, labels do not protect content at rest.
  • Publish the labels to users with a default label and, where appropriate, mandatory labelling.
  • Apply container labels to sensitive sites. This controls privacy, external sharing, and device access at the site level.
  • On encrypted labels, grant the view and extract rights Copilot needs only to the people who should have them.

Stage six · Protect

Classify and protect the back-catalogue

6 checkpoints

  • Prioritize the high-value sites for labelling first. You will not label everything at once.
  • E5 Build service-side auto-labelling policies to classify the back-catalogue of unlabelled content.
  • E5 Run every auto-labelling policy in simulation first. Review the matches before enforcing.
  • On Business Premium, label the high-value sites by hand and rely on tight permissions for the rest.
  • E5 Add a Purview DLP policy for the Copilot location to keep labelled files out of Copilot’s answers.
  • Confirm Copilot-generated content inherits the most restrictive label of whatever it cites.

Stage seven · Control

Configure Copilot’s own controls

6 checkpoints

  • Roll out Copilot licences to the pilot group first. Expand by adoption, not all at once.
  • Decide whether Copilot may use web search. Set the policy through the Cloud Policy service.
  • Govern Copilot agents: review which are enabled, and who may build or install them.
  • Confirm Copilot prompts and responses are captured in the Microsoft Purview audit log.
  • Confirm eDiscovery and retention cover Copilot interactions, the same way they cover email and chat.
  • E5 Add a Communication Compliance policy for Copilot prompts and responses if the organization is regulated.

Stage eight · Sustain

Make governance ongoing

5 checkpoints

  • Put the Data Access Governance reports on a recurring schedule. Oversharing comes back.
  • Set an access-review cadence: site owners re-attest their membership each quarter.
  • Track the exit date for Restricted SharePoint Search. Decommission it once permissions are validated.
  • Run a site lifecycle policy: archive inactive and ownerless sites so Copilot is not grounding on stale content.
  • Review the label taxonomy and Copilot usage reports each quarter, then tune.

If readiness is a bigger job than it looked

The reports always find more than the org expected.

Stage two has a way of returning numbers nobody wants to see: hundreds of sites shared with everyone, links that never expired, sites whose owner left years ago. Copilot is worth turning on, but only once that list is worked down. If the cleanup is more than your team can take on before go-live, that is the work TenantCraft does: oversharing remediation, labelling, and a Copilot rollout that does not leak. A discovery call is free, 25 minutes, and ends with a written scope, not a sales pitch.

Web
tenantcraft.ca
Email
hello@tenantcraft.ca
Discovery call
Free · 25 minutes

Checklist last reviewed May 16, 2026. Microsoft 365 Copilot surfaces content using each user’s existing permissions. The readiness work above should be complete (or consciously deferred) before the first Copilot licence is assigned.

The background reading

Next in the sequence

TWENTY MINUTES, NO PITCH

Tell me what is stuck. I will tell you what it takes.

Same consultant from the first email to the last cutover. If I am not the right fit, I will refer you to someone who is.

Sneak peek

Document preview

100%

Loading the document…