Insights & News
Copilot Data Governance: What to Do Before You Turn It On
- October 2, 2026
Microsoft 365 Copilot does not break your permissions, it exposes them. It can surface anything a user already has access to, which in most SME tenants is considerably more than anyone realised. The data governance work before a Copilot rollout is mostly permission clean-up, sensitivity labelling and sorting out oversharing in SharePoint, and it is the difference between Copilot being useful and Copilot quietly handing the payroll file to whoever asks the right question.
Key facts
- Copilot respects existing permissions. It does not grant new access, and it does not bypass anything, which is exactly why oversharing becomes visible the moment it is switched on.
- The common failure is not a Copilot flaw. It is a SharePoint site shared with Everyone, a legacy "anyone with the link" URL, or a Teams site nobody tidied after a project ended.
- Search finds a file when you know what to look for. Copilot summarises and reasons across everything a user can reach, so latent access becomes active discovery.
- Sensitivity labels are the durable control, because they travel with the file and can govern what Copilot does with the content.
- Copilot activity should be in your AI register like any other AI system, with a named owner and a review date.
- Doing the clean-up first is cheaper than doing it after the first awkward question, and it improves the output, because Copilot grounded in tidy data gives better answers.
What should you do before switching Copilot on?
- Find the oversharing. Site and file level sharing reports, anything shared with Everyone or Everyone Except External Users, and every live anyone-with-the-link URL. This is where the surprises are.
- Fix the inherited mess. Broken inheritance, orphaned Teams sites from finished projects, personal OneDrive folders holding shared business data.
- Deal with the obvious crown jewels. Payroll, HR files, board papers, legal matters, the pricing file. Move them to properly restricted locations rather than relying on obscurity.
- Apply sensitivity labels to the categories that matter, so protection travels with the content.
- Decide who gets a licence first. A pilot group inside a scoped set of sites beats a tenant-wide rollout.
- Write the rules down. What Copilot may be used for, what still needs human review, and how output is checked before it reaches a client.
Why does Copilot make oversharing urgent?
Because it collapses the effort required to find things. Access that was technically available but practically buried becomes a one-sentence question. Nobody was going to browse eleven thousand files looking for a salary spreadsheet. Everybody can ask what the team's salaries are.
In practice, a 2019 project site opened to the whole business for convenience, then forgotten, is the shape of the problem. The permission was always wrong. Copilot is simply the first tool that acts on it at speed.
What about data leaving the tenant?
This is where Copilot is genuinely stronger than the free consumer tools your staff would otherwise use. Microsoft 365 Copilot operates inside your tenant's compliance boundary, and your prompts and organisational data are not used to train the foundation models. That is the central argument for giving people a sanctioned tool: the alternative is the same work happening in a consumer chatbot on a personal account with none of that.
It is not an argument for skipping governance. Your own obligations still apply to whatever Copilot surfaces or produces, and the Privacy Act does not care which vendor processed the information.
How does this fit the rest of your AI governance?
Copilot is one entry in the AI register, one line in the acceptable use policy and one scope decision in the rollout plan. Treat it as a special case and you end up with a Copilot process disconnected from everything else, which falls apart the moment the second AI tool arrives. The permission clean-up, though, is genuinely Copilot-specific work and it is the part that cannot be skipped or deferred.
Frequently asked questions
Can Copilot see files a user cannot access?
No. It operates within the user's existing permissions and does not grant new access. The risk is not that it breaks permissions, it is that it makes existing over-permissive access trivially easy to exploit, usually by accident.
Does Microsoft train its models on our Copilot data?
Microsoft's position is that Microsoft 365 Copilot prompts, responses and organisational data accessed through Microsoft Graph are not used to train the foundation models. Confirm the current terms for your licensing before relying on it in a client answer, because vendor terms change and that is exactly the claim a client will test.
How long does the pre-Copilot clean-up take?
For a 20 to 50 person tenant that has never been audited, allow two to four weeks for discovery and remediation of the worst oversharing, running alongside the pilot rather than blocking it. Older tenants with years of project sites take longer, and the age of the tenant predicts the effort better than the headcount does.
Should we label everything before turning Copilot on?
No, and attempting it is how labelling projects die. Label the categories that matter, usually client confidential, HR and finance, then extend. A small labelling scheme that is actually applied beats a comprehensive one that stalls at design.
Do we need an AI policy just for Copilot?
No, one AI acceptable use policy covering all approved tools is better. Copilot gets named in the approved list with the account type, and the rules about data, output checking and disclosure apply to it the same as to anything else.
If Copilot licences are already bought and nobody has looked at the sharing position yet, that is the job to do first. We run the discovery, show you what it would surface, and fix the worst of it before anyone types a prompt.
About the author
Brett Muscio is the Director of 4iT Support Pty Ltd, a managed services provider based in Castle Hill, NSW. He works with SME clients across Sydney, Melbourne, and Brisbane on Microsoft 365 environments, including Copilot rollouts, Purview governance, AI governance and conditional access, with on-site support across the Sydney metro area and remote delivery nationally. Connect on LinkedIn.
Recent Posts
-
Copilot Data Governance: What to Do Before You Turn It On -
How to Write an AI Acceptable Use Policy -
AI Regulation in Australia: Where It Stands -
What Goes in an AI Governance Framework -
ISO 42001 Explained for Australian SMEs -
How to Write a Data Loss Prevention Policy -
Microsoft Purview DLP for Australian SMEs -
What Is Data Loss Prevention (DLP)? -
Has the Privacy Act small business exemption been removed? -
Microsoft Authenticator Setup for Business







