Copilot licences are bought or about to be, and SharePoint and OneDrive access is wider than anyone intended.

Fix the oversharing before Copilot starts surfacing it.

Copilot Permission Remediation & Pilot

Oversharing is corrected across the agreed scope, access guardrails are configured, a pilot group runs real work through Copilot, and the go, defer or expand decision is made from that pilot’s evidence.

Price

Fixed price confirmed before work begins

Delivery window

The fixed proposal contains the delivery calendar and the completion date.

The price is agreed in writing before any work begins and before any access is granted. Nothing is billed for the scoping conversation that sets it. What moves the number:

  • · Number of SharePoint sites, Teams and OneDrive locations in scope
  • · Volume of company-wide and guest sharing to unwind
  • · Whether sensitivity labelling is configured as part of the work
  • · Size of the pilot population and the number of use cases tested
  • · Whether the tenant licensing supports the guardrails in the design

No tenant access, credentials, or sensitive files are requested through this website.

Bounded location list, agreed up frontPurview labelling only where licensedClient owns the pilot users

What happened

Copilot does not break permissions — it exposes them. It surfaces what the signed-in person is already allowed to open, which is a problem precisely because a file shared company-wide in 2021 by someone who has since left is still, technically, something they are allowed to open. Microsoft’s own deployment guidance puts remediating oversharing and setting guardrails before broad rollout, not after it.

Sources: Microsoft: secure and govern data for Microsoft 365 Copilot

Copilot licences are bought or sitting on the order, so what is left to settle is the state of the content it would be pointed at. The sharing across SharePoint, OneDrive and Teams was built up one request at a time and has not been reviewed since: links created to get a single document in front of a meeting are still company-wide, guests added for finished projects are still in the groups, and the default sharing behaviour that produced all of it is unchanged. Nobody can currently answer, for one named employee, which files that account is already able to open.

What happens if it is left as it is

  • Copilot works inside the permissions that already exist, so an over-broad share stays exactly as wide as it was, and content sitting across many of those locations can be drawn into a single answer for anyone that share already covers.
  • Where a payroll or HR file was saved into a location shared company-wide, any account in the business can already open it, and nothing in the tenant brings that to anyone's attention until somebody goes looking.
  • A Copilot subscription runs from the date it starts, so sharing unwound after the purchase is unwound on time the business is already paying for.
  • Microsoft's deployment guidance places oversharing remediation ahead of broad rollout, so a tenant switched on before that work has to be corrected while people are already using it, and an access change made then can land on work somebody is in the middle of.

What changes in production

Not findings. These are the things that are different afterwards.

  1. 1The sites and locations in the agreed scope are ranked by exposure, and the high-risk ones are reviewed against what sharing was actually intended.
  2. 2The agreed oversharing fixes are made: company-wide links retired, orphaned guest access removed, over-broad group permissions narrowed to the people who need them.
  3. 3Access guardrails are configured — restricted access where the design calls for it, sensitivity labelling where it is licensed and agreed, and default sharing behaviour changed so the same problem does not rebuild.
  4. 4A pilot group runs Copilot against real work, and what it surfaces is checked person by person against what those people were already entitled to see.
  5. 5The go, defer or expand decision is made from the pilot evidence, with the remaining exceptions recorded and owned.

Definition of done

The engagement ends when all of these are true and demonstrable.

  • Every location in the agreed scope has been reviewed and carries a decision
  • The agreed oversharing fixes are made and verified against real accounts
  • The access and guardrail configuration is applied and tested
  • The pilot group has completed the agreed use cases and what Copilot surfaced has been checked against entitlement
  • A go, defer or expand decision is recorded with the evidence behind it, and every remaining exception has an owner

What you provide

Named up front, because these are the things that stall an engagement when nobody owns them.

  • Nominate someone who can confirm which sharing was intentional
  • Approve the location list before remediation begins
  • Provide the pilot users and their real use cases
  • Own end-user communications and support through the pilot
  • Provide the licensing the agreed guardrails require

What moves the price

The figure comes from what is actually in the environment. Headcount is one input among several, and rarely the one that matters most.

  • Number of SharePoint sites, Teams and OneDrive locations in scope
  • Volume of company-wide and guest sharing to unwind
  • Whether sensitivity labelling is configured as part of the work
  • Size of the pilot population and the number of use cases tested
  • Whether the tenant licensing supports the guardrails in the design

Not included

Stated so the scope means the same thing to both parties on the last day as it did on the first.

  • Copilot licence procurement
  • Site-by-site permission reconstruction outside the agreed location list
  • A full Purview classification or DLP programme
  • Content migration or information-architecture redesign — that is SharePoint & Teams Cleanup
  • Any guarantee about what Copilot returns, which depends on tenant content that keeps changing

How change is staged and reversed

Production work carries risk. This is the method, not a reassurance.

  • Sharing is narrowed in batches with a hold period, so an access change that breaks someone’s work is caught and reversed inside the same week rather than discovered a quarter later.
  • Every batch is verified from a real account in the affected group, not from the admin console alone.
  • The pilot runs on the corrected scope only; Copilot is not enabled beyond it until the pilot evidence supports it.

Evidence and handover

Yours to keep whatever happens next, including handing it to your own team or another provider. The documents are what prove the work happened; they are not the thing being bought.

  • The exposure ranking across the locations in scope, before and after
  • Every permission and sharing change made, with the reason
  • Per-person access examples drawn from real groups in the tenant
  • The guardrail configuration as applied
  • The pilot record and the written go, defer or expand decision

Is this another report, with the real work quoted afterwards?

It may sound like a consultant will inspect the environment, hand over a document, and then quote a second project. That is not the default here. Where the outcome can be scoped safely from a short working call, the implementation is sold directly, as this page does. Separate paid planning is used only where genuine complexity prevents a responsible fixed price, and where it is used the page says so plainly.

Plan the Copilot Pilot

Describe what is happening, what has to be working differently, and any deadline behind it. A reply comes within one business day with the most direct next step, or a clear answer that AZ Innovations is not the right fit.

Plan the Copilot Pilot →