Diagnostic
Copilot & Shadow AI Exposure Report
See what Copilot and other AI tools can reach before you roll them out, including the AI nobody approved.
"We want to switch Copilot on, but nobody can tell us what it would let people see, and we have no idea which AI tools our staff already signed up for."
Starts at
$3,450A smaller Compact scope (from $2,500) covers eligible bounded environments, confirmed before you pay.
5.0out of 5
Top Rated on Upwork · 100% Job Success · on every client-rated engagement, scored by Upwork. Delivered work →
What moves the number: tenants, sign-in, how many apps sign in through Microsoft 365, mail, Azure and endpoints. Headcount is only one of them. The scope-fit check tells you where you land →
What you walk away with
What you keep when this is done
You keep a written record of what is broken, what it is costing you, and what it costs to fix, in a form your leadership can act on. It also sets the fixed price of the fix, so nothing after this is open ended.
- A heat map of where your sensitive files sit and who can already open them, ranked by how exposed each area is.
- The files and sites Copilot would surface first, and how each one got shared that wide: a link anyone in the company can open, or a guest from outside it.
- The AI tools, apps and connectors found plugged into your Microsoft 365, ranked by risk and by how much they are used, with a recommendation to allow, watch or block each one.
- Examples using real people and groups from your own company: for each one, the list of what they can open today.
- A straight verdict on Copilot: go ahead, go ahead with limits, or wait until the sharing is fixed, plus the list of fixes to close first.
An illustrative view of the heat map: the sensitive areas of your Microsoft 365, how each one is exposed today, and the Copilot verdict that follows.
How the diagnostic works
01Read-only inspection
Your live environment is inspected directly, read-only. Nothing changes and nothing breaks.
02Findings, scored and priced
You see what is actually risky, what it is costing you, and a fixed quote to fix what matters. Ranked in plain language.
03Your plan, either way
The remediation plan is yours to keep. Take the fix at the quoted price, or hand the plan to your own team or another vendor.
This is for you if
- You have a real decision or risk on the line: an audit, a renewal, a migration, a board question, or an AI rollout.
- You want findings at the sample report's level of specificity: named roles, quantified waste, tested assumptions.
- You want the price fixed in writing before the work starts.
It is not for you if
- You need a quick checkbox scan rather than findings you plan to act on.
- You are looking for open-ended staff augmentation with no defined finish line.
After the diagnostic
Remediation is scoped from the evidence
Remediation is quoted as a fixed scope rather than open-ended hours. The diagnostic shows exactly which of these you need, and what it should cost.
Stabilize
Close the urgent gaps the evidence surfaced, on a fixed scope, before they become an incident.
Control
Stand up the controls and operating model the environment was missing, in staged, measurable releases.
Oversee
Fractional Architecture Oversight once the foundation is in place: scheduled senior review on a defined monthly cadence, offered as a follow-on. Implementation is separately scoped.
Delivery, access, and scope boundaries
Typical delivery
10 business days, elapsed. The window begins after the scope is confirmed, the kickoff is complete, required access works, and requested exports and documentation have been provided. Client, licensing, or third-party delays pause the timeline.
Access needed
Read-only access to SharePoint, OneDrive and Teams permissions, app-consent reporting, and available Purview, Defender or Cloud Apps reporting. Client-provided exports may substitute where appropriate. Access is time-limited, protected with MFA, and read-only wherever the platform allows. Credentials should never be submitted through the website.
Not included
No review of document contents unless separately authorized, and no Copilot deployment, license procurement, employee surveillance, legal review, or remediation.
Every assessment includes one kickoff and one findings review; extra workshops or revision rounds are a change order. Unless the signed statement of work says otherwise, no assessment includes production changes, remediation, implementation, emergency incident response, 24/7 availability, software or licensing costs, legal attestation, or third-party vendor fees. The signed statement of work controls if it differs from this page.
Other diagnostics
See all →Microsoft Estate Risk Ledger
Find the risk, waste, and missing ownership across Microsoft 365, Azure, identity, licensing, and infrastructure.
Identity & Insurance Evidence Pack
Prove your access controls before an audit, insurance renewal, or incident forces the question.
Migration & Cutover Plan
Plan the migration, rollback, and reconciliation before anything moves: mailboxes, tenants, SharePoint, Teams, Slack, Azure.
$3,450
Copilot & Shadow AI Exposure Report