Microsoft 365 Copilot does not have special access to your data. It has exactly the access the person asking has. That is the reassuring sentence in every vendor briefing, and it is true.
It is also the entire problem.
Why “it only sees what you can see” is not comforting
In theory, a user could always open any document they had permission to open. In practice, nobody browses a document library hoping to stumble across something interesting. Over-sharing has been safe for years because finding things was hard.
Copilot removes the effort. Ask a plain question and it searches everything the user is permitted to read, summarises it, and presents it with confidence. Permission sprawl that accumulated invisibly over several years becomes discoverable in a sentence.
The businesses that have an uncomfortable fortnight after switching Copilot on are not the ones with bad security. They are the ones whose permissions never quite reflected their intentions — which is most.
Where the sprawl comes from
Nothing dramatic. The default sharing link set to “anyone in the organisation”, so every quick share granted company-wide access. Inheritance broken to give one person access to one folder, three hundred times over several years. Teams created freely, each with a SharePoint site, several now ownerless. Old content that was never archived because deleting things feels risky.
Each decision was sensible. The cumulative effect is an estate where nobody can say who can see what.
Before you switch Copilot on
Tick what you could confirm today. The unticked ones are the work.
The second problem: confidently wrong
Less discussed and arguably more annoying in daily use.
Copilot cannot tell that a document is out of date. If your SharePoint holds the current pricing and three superseded versions, it may summarise from any of them — and it will do so in the same assured tone either way.
This is a content hygiene problem rather than a security one, but it lands the same way: someone quotes a four-year-old figure to a customer because the assistant said so. Retention policies and a habit of archiving rather than accumulating are the fix.
What to do before rollout
Three things, in order.
Audit sharing. Find out what your default link type is and change it if it grants organisation-wide access. Run a report on externally shared content. Look for sites with no owner.
Protect the obvious. HR, finance, legal and anything commercially sensitive should sit behind deliberate permissions and, ideally, sensitivity labels — which are the mechanism for keeping content out of Copilot responses entirely.
Test as a real user. Pick an ordinary member of staff, sit with them, and ask the awkward questions: what are the salary bands, what is in the redundancy plan, what did we pay for that contract. Whatever comes back is what would have come back on day one of rollout.
None of this is an argument against Copilot
It is genuinely useful, and the businesses getting value from it are seeing real time savings on summarising, drafting and finding things.
The point is narrower: Copilot is not a security risk so much as a disclosure of your existing permissions. If those are sound, it is a productivity tool. If they are not, it is an audit you did not schedule, conducted by your own staff, at speed.
Doing the permissions work first is the same work you would have to do afterwards, minus the awkward conversations. If you would like that reviewed before you roll it out, it is a well-defined piece of work and we do it regularly.





