Free IT check
Copilot Permissions: The Problem Your Rollout Will Expose
Two weeks after switching on an AI assistant, a company we know had an awkward moment. An employee asked it a routine question about salary bands, purely out of curiosity, and got a detailed answer. The document it quoted had been sitting in a SharePoint site since 2021, shared with a group that had quietly grown to include most of the company.
Nothing was hacked. Nobody broke a rule. The file had always been readable by that person, and for five years nobody found it because nobody thought to look. That is the uncomfortable truth about Copilot permissions: the assistant does not open new doors, it just walks through the ones you left unlocked.
Search used to hide your mistakes
For twenty years, bad file permissions were protected by bad search. Traditional search needs the right filename or a phrase you already know. If a sensitive document lived in a badly named folder, it was effectively invisible.
Microsoft 365 Copilot does not work that way. It reasons over meaning. Ask about redundancy plans and it will find the file called “Q3 planning v4 FINAL” even though the word redundancy appears nowhere in the title. Every document a user can technically reach becomes genuinely findable, often for the first time.
That is a feature. It is also why Copilot permissions turn into a governance question about a month into any rollout.
What a Copilot permissions audit typically finds
When we review an environment before a rollout, the same things surface again and again:
- A general company site where “everyone” was given edit rights during a rushed migration
- HR or finance documents stored in a departmental folder that half the business can open
- Old project sites belonging to people who left years ago, still shared with the whole organisation
- Sharing links set to “anyone in the company” because it was faster than picking names
- OneDrive folders shared with a colleague once, then forgotten and inherited by whoever took over the account
None of this is negligence. It is the residue of ordinary work under ordinary time pressure. SharePoint permissions accumulate, and almost nobody reviews them, because until now there was no consequence.
Oversharing is the real diagnosis
The industry word for this is oversharing, and it is worth being precise about what it means. Your data is not leaking outside the company. The problem is internal: people can reach far more than their role requires.
The risk that follows is not really about curiosity. It is about what happens when one account is compromised. If a single stolen password gives an attacker conversational access to everything that employee could theoretically read, the blast radius of a phishing email changes completely.
Put differently, Copilot permissions are not a new problem introduced by AI. They are your existing access model, finally visible.
Fixing your Copilot permissions before you switch it on
The good news is that the work is finite and it improves your security whether or not you ever deploy an assistant.
Find your worst offenders first. Identify the sites and folders shared with everyone, and the ones with the largest audiences. That handful of locations usually accounts for most of the exposure.
Deal with the obvious sensitive material. Salary data, contracts, board documents, personal records. Move them somewhere with a deliberate, small group of people who need them.
Fix the default sharing setting. If new links default to company-wide access, every future share adds to the pile. Change it once and the problem stops growing.
Clean up sites without an owner. Anything belonging to someone who left needs either a new owner or an archive.
Then start small. Roll out to one department, watch what people find, and expand from there. A pilot surfaces surprises while they are still cheap.
Do not confuse this with a licence problem
A common misunderstanding: people assume buying the right licence solves this. It does not. Licences give you tooling for data governance, including sensitivity labels and reporting on oversharing, but no tool decides who should be able to read your salary review. That judgement is yours, and it is why Copilot permissions cannot be outsourced to a product feature.
Equally, do not let this stop you. An assistant that surfaces an uncomfortable document in week two has arguably done you a favour, because the alternative was discovering the same exposure during an incident.
Let us clean this up before your rollout
Reviewing permissions across an entire tenant is exactly the kind of job that never reaches the top of anyone’s list. It is detailed, it is slow, and it requires knowing which settings actually matter.
That is where we come in. At EvolvingDesk we review your Copilot permissions before any AI rollout: we map who can reach what, flag the sites shared far too widely, put the sensitive material behind proper access control, and set defaults that stop the mess returning. Then we help you roll out in stages, so nothing lands as a surprise.
You get an assistant your team can trust, and an access model that finally reflects how your business is actually organised. No awkward moments in week two.
Thinking about Copilot? Plan a call and we will start by showing you what it would be able to find today.
Read more
- What is Microsoft Copilot and how can your business use it
- The IT foundation you need before adopting AI
- What happens to your data when an employee leaves
Background reading: Microsoft on how Copilot handles your data and the SharePoint guidance on preparing content for Copilot.
Did this article spark some ideas?
Find out what we can do for you, schedule a call today.
About EvolvingDesk: Making IT Effortless
We turn complex IT into simple, effective solutions for your business. Whether it’s cloud services, custom applications, or network management, EvolvingDesk combines the latest technology with personal service, so your business stays secure, connected, and ready for growth. IT made simple, just the way it should be.
What do we do?
At EvolvingDesk, we provide practical IT solutions that fit the way your business works. From tailored software and reliable business WiFi to smart surveillance and hands-on support, we make sure your technology runs smoothly, so you can stay focused on your goals.