Microsoft 365 Copilot respects your existing permissions. It does not add new ones. That sounds reassuring until you consider what your existing permissions actually are after a decade of quick shares, inherited sites and a SharePoint migration nobody wanted to redo.
Copilot does not create that exposure. It makes it searchable in plain language, which is a very different thing from technically accessible. Here is the checklist to work through before the licences go on.
1. Find the oversharing
Start with the files and sites open to everyone in the organisation, including the ones shared with "anyone with the link". The usual finds are a payroll spreadsheet in a folder that was opened up for one project, and a site whose owner left two years ago.
Ask a blunt question: if someone typed "what is everyone paid" into a search box, what would come back? That is the test Copilot applies on day one.
2. Get sensitivity labelling in place
Labelling tells Microsoft 365 what is confidential, and labels can carry protection with the file when it moves. Without them, everything is equally available to anything with access to the tenant.
Labelling everything perfectly is not the goal, and attempting it stalls projects. Label what would genuinely hurt: contracts, payroll, board material, customer records, and anything covered by an obligation.
3. Tighten identity before you add capability
An AI assistant makes a compromised account far more productive for the attacker holding it. Multi-factor authentication everywhere, conditional access matched to risk, and privileged accounts separated from everyday ones are prerequisites rather than improvements.
These are the same controls the Essential Eight asks for, so the work counts twice.
4. Clean up what nobody owns
Stale Teams, abandoned SharePoint sites and duplicated document sets are not only clutter. They are content Copilot will read and quote confidently, including the superseded version of a policy or a price list.
Wrong answers from an assistant are usually old answers from your own tenant.
5. Write the acceptable use position down
Who may use it, for what, and what happens to the output. This matters more than it sounds, because staff are already using something. If there is no approved tool with a policy around it, company information is being pasted into whatever people found themselves.
Keep it short enough that people read it, and cover the two questions that come up: can I paste client information in, and do I have to say when something was drafted with it.
6. Pilot with real work, and measure it
Choose a small group whose work genuinely suits it: people who live in documents, email and meetings. Give them real tasks, and measure whether it saves time rather than whether they enjoyed it.
The honest finding is often that Copilot is excellent for some roles and close to useless for others. Someone inside a line-of-business application all day gets far less from it than a manager who writes and reads all day. Licensing everyone is the most common way the return disappears.
7. Decide who actually gets a licence
Use the pilot to allocate deliberately. It is easier to add licences for people asking for one than to justify a tenant-wide spend that half the business never opens.
The order matters
Almost every rollout that goes badly does so because licences were enabled first and the permissions review happened afterwards, usually prompted by something embarrassing surfacing in a search.
REDD runs this as a Copilot readiness assessment: we scan the tenant for oversharing and permission sprawl, review identity and labelling, and give you a findings report that stands on its own whether or not you proceed. It sits inside our wider AI enablement work, and if you want to see what an assistant could reach in your tenant right now, ask us to look.