That is the whole risk in one sentence. Copilot inherits each person's existing permissions, so a decade of over-shared SharePoint sites and open Teams files becomes instantly searchable in plain language. A readiness assessment fixes that before the licences go on, not after someone asks it about salaries.
What we check
Which files are open to the whole organisation, which sites have lost their owner, and what a plain-language question would surface today.
Sensitivity labelling and retention, so confidential material is classified before an assistant starts quoting it.
Multi-factor authentication, privileged access and conditional access, because an AI assistant makes a compromised account far more productive.
Who may use it, for what, and what happens to the output. Written down, because staff are already using something whether you approved it or not.
How it runs
Week 1
We scan the tenant for oversharing, stale sites and permission sprawl, and review identity and labelling. You get a findings report that stands on its own.
Weeks 2 to 4
The oversharing is closed and labelling applied, in priority order. This is the bulk of the work and the reason rushed Copilot rollouts go badly.
Pilot
A small, well-chosen pilot with real tasks, measured on whether it saves time rather than whether people enjoyed it.
Rollout
Policy, training and monitoring in place, then licences to the people whose work it genuinely suits.
The honest version
Copilot pays for itself in roles that produce and digest a lot of documents and email. It does far less for roles that live in a line of business application all day, and buying it for everyone is the most common way the return disappears.
We would rather tell you that during the assessment than sell you a tenant-wide rollout. The same applies to the security work: if your permissions are already tight, the remediation stage is short and we will say so.
The same foundations decide whether any AI tool is safe to adopt, including the ones your staff are already pasting company data into.
A pilot with real tasks and a before and after, so the business case is evidence rather than enthusiasm.
Around it
The wider program: where AI actually fits in your operations, and the secure foundation under it.
See AI enablement →Identity and access controls are the same ones that decide how much damage a compromised account can do.
See Essential Eight →Licensing, tenant configuration and the ongoing administration once it is live.
See managed technology →Common questions
A review of your Microsoft 365 tenant before Copilot licences are enabled: file and site permissions, oversharing, sensitivity labelling, identity controls and governance. The output is a findings report and a remediation plan, and it is useful whether or not you proceed.
Copilot respects existing permissions, it does not add new ones. The problem is that most organisations have years of over-permissive sharing that nobody noticed, because nobody was searching for it in plain language. Copilot makes that history immediately accessible.
The assessment takes about a week. Remediation depends entirely on how much oversharing exists, commonly two to four weeks. Tenants that have been tidy for years move faster, and we will tell you if that is you.
It depends on the roles. It is strongest for people working across documents, email and meetings all day, and weakest for those inside a single line of business system. A measured pilot answers this for your organisation far better than any vendor material.
A readiness assessment shows you exactly what an assistant could reach inside your tenant right now, and what it takes to close the gaps.
Get in touch
Send the basics and a REDD engineer will come back to you within one business day. Prefer to talk? Call 1300 697 333.