Copilot does not break your permissions. It respects them perfectly, and that is the problem. Files that were safe because nobody could find them become findable by anyone who already had access. Twelve questions on whether the unglamorous groundwork is done. Five minutes. Nothing you answer leaves your browser, and there is no form at the end.
1 of 12
Do you know how many SharePoint sites and Teams you have, and who owns each one?
A list you could produce this week, not a number someone remembers.
2 of 12
Can an ordinary member of staff create a link that works for everyone in the organisation?
Often called “People in your organisation” or “Everyone except external users”.
3 of 12
Have you ever run a report of content shared organisation-wide?
Not whether you could. Whether anyone has looked at the output.
4 of 12
Are there sites or Teams with no owner, or an owner who has left?
If you do not know, the honest answer is the last one.
5 of 12
Is genuinely sensitive content labelled in a way a tool can read?
HR files, payroll, legal advice, client-confidential work. Labels a machine can act on, not a folder name.
6 of 12
If a file is labelled confidential, does anything actually stop an assistant using it to answer a question?
A label that carries no enforcement is a description, not a control.
7 of 12
Does anything get deleted on a schedule, or does everything stay forever?
Stale content does not just create risk. It makes the answers worse.
8 of 12
Do you know which of your people already use AI tools with company information?
Asking people to confess is not a method. Knowing is.
9 of 12
Has anyone decided who may build and publish an AI agent?
An agent acts rather than answers, and holds standing access.
10 of 12
If the person who built an agent leaves, is there a process that catches it?
The same question as the shared administrator account, and it ends the same way.
11 of 12
Are AI prompts and responses retained and searchable if you were asked for them?
A regulator, an insurer or a court may ask. They are records.
12 of 12
Has anyone written down what staff may and may not put into an AI tool?
A policy protects the employee as much as the organisation.
Why this is not really about AI
Almost nothing on this page is an AI control. Permissions, ownership, labelling and retention are things that were already supposed to be true, and were tolerable while they were not because finding a badly-shared file required knowing it existed. A natural-language assistant removes that protection entirely, and it does so without breaking a single rule.
Which means the work is unglamorous and mostly already on somebody’s list. The value of doing it now is that you have a deadline you can name and a benefit somebody actually wants.
Where we stand on this
We assess and we document. We will not be the ones cleaning up your SharePoint permissions and also the ones telling you whether they are clean. That work belongs to you or your IT provider. Our part is the gap analysis, the governance, the plan, and saying plainly when a supplier describes a legal obligation that does not exist.
Copilot readiness is one part of a wider question. How we assess AI governance as a whole, and what an engagement covers.
What to read next
If this produced a list you did not expect, two things on this site are worth ten minutes each. What actually governs AI in Canada sets out what genuinely binds you — there is no Canadian AI Act, whatever you have been told — and the AI acceptable use policy template is free and is the first document most organisations are missing.
Current at 29 August 2026. Product features in this area are renamed and repackaged frequently; the questions are written to survive that, but if you are reading this long afterwards, check before relying on it.