# Copilot Readiness Governance Checklist

> Microsoft 365 Copilot answers from everything a user can already open. Before you switch it on: find the oversharing, contain it, classify what matters. That's how Copilot stays an assistant instead of a leak.

1.  [Home](https://tenantcraft.ca/)
2.   [Insights](https://tenantcraft.ca/insights)
3.   Copilot Readiness Governance Checklist

Govern Copilot 44 checkpoints

Last reviewed May 16, 2026 · 7 pages in print

Before you start

## Copilot mirrors your permissions

Microsoft 365 Copilot does not open new holes in your security. It reflects the ones already there. It answers a question from any file the person asking can already open. A document that was overshared but buried was safe by obscurity; Copilot removes the obscurity and reads it aloud. So readiness is not a Copilot setting. It is permission cleanup, containment, and classification, done before the first licence is assigned. This checklist runs that work in order.

What to know before you begin
| Item | What it means |
| --- | --- |
| Permission-trimmed | Copilot only returns content the person prompting it already has at least view access to. Nothing more, nothing less. |
| Oversurfacing | The risk is not new access. It is discovery. Copilot finds and summarizes the overshared files nobody knew were reachable. |
| “Everyone except
external users” | The most common oversharing claim. It reaches your whole organization, and so does Copilot on its behalf. |
| Sensitivity labels | Copilot honors a label’s encryption. A user who can only view a labelled file cannot have Copilot extract from it. |
| The tooling | The oversharing reports and controls used here are included once the tenant has one Microsoft 365 Copilot licence. |
| E5 markers | A few checkpoints need Microsoft 365 E5 or the E5 Compliance add-on. They are marked. Everything else works on Business Premium. |

The eight stages

1.  1Understand the exposure and confirm licensing5 checkpoints
2.  2Map the oversharing6 checkpoints
3.  3Apply the interim safety valve5 checkpoints
4.  4Remediate permissions6 checkpoints
5.  5Build the sensitivity-label foundation5 checkpoints
6.  6Classify and protect the back-catalogue6 checkpoints
7.  7Configure Copilot’s own controls6 checkpoints
8.  8Make governance ongoing5 checkpoints

Stage one · Understand

## Understand the exposure and confirm licensing

5 checkpoints

-   Accept the premise: Copilot returns **anything the person prompting it can already open**. The work is fixing permissions, not Copilot.
-   Count your **Microsoft 365 Copilot licences** and confirm SharePoint Advanced Management is active. It ships with the first Copilot licence.
-   Identify your tenant’s **licence tier**. Most of this checklist works on Business Premium; the items marked E5 need Microsoft 365 E5.
-   Choose the **pilot group**: a small set of users who get Copilot first, while the rest of the cleanup runs.
-   Brief leadership that **“find the oversharing” comes before “turn on Copilot”**, and that the work takes real time.

Stage two · Find

## Map the oversharing

6 checkpoints

-   Turn on **Data Access Governance data collection** in the SharePoint admin centre.
-   Run the **organization-wide site permissions report**. This is your baseline of who can reach what.
-   Run the **“Everyone except external users” report**. It is the single biggest oversharing vector.
-   Run the **sharing-links report**. Find “Anyone” links and organization-wide links.
-   Flag **ownerless and inactive sites**. Nobody is watching what they expose.
-   Rank every site by **exposure against content sensitivity**. Produce a high-risk list.

Stage three · Contain

## Apply the interim safety valve

5 checkpoints

-   Decide your valve: **Restricted Content Discovery** per site, or **Restricted SharePoint Search** tenant-wide.
-   Apply **Restricted Content Discovery** to the high-risk sites. It hides them from Copilot and search without changing permissions.
-   If oversharing is pervasive, enable **Restricted SharePoint Search** with a curated allow-list of up to 100 sites. Set an exit date; it is temporary.
-   Use **Restricted Access Control** to lock a critical site to a single security group.
-   Verify, after about an hour, that **Copilot no longer surfaces** the excluded content.

Stage four · Remediate

## Remediate permissions

6 checkpoints

-   Delegate **site access reviews** to site owners. They can see the item-level detail an admin cannot.
-   Remove or replace **“Everyone except external users”** on the sites the reports flagged.
-   Expire or revoke **stale “Anyone” and organization-wide sharing links**.
-   Fix **broken permission inheritance** where it is not deliberate.
-   Set the tenant **default sharing link to “Specific people”**. Set link expiry.
-   Re-run the reports on the high-risk sites. **Confirm the exposure is actually down**.

Stage five · Classify

## Build the sensitivity-label foundation

5 checkpoints

-   Define a short **label taxonomy**: four or five labels such as Public, Internal, Confidential, Highly Confidential.
-   Enable **sensitivity labels for files** in SharePoint and OneDrive. Without this, labels do not protect content at rest.
-   Publish the labels to users with a **default label** and, where appropriate, mandatory labelling.
-   Apply **container labels** to sensitive sites. This controls privacy, external sharing, and device access at the site level.
-   On encrypted labels, grant the **view and extract rights** Copilot needs only to the people who should have them.

Stage six · Protect

## Classify and protect the back-catalogue

6 checkpoints

-   **Prioritize the high-value sites** for labelling first. You will not label everything at once.
-   E5 Build **service-side auto-labelling policies** to classify the back-catalogue of unlabelled content.
-   E5 Run every auto-labelling policy **in simulation first**. Review the matches before enforcing.
-   On Business Premium, **label the high-value sites by hand** and rely on tight permissions for the rest.
-   E5 Add a **Purview DLP policy for the Copilot location** to keep labelled files out of Copilot’s answers.
-   Confirm **Copilot-generated content inherits** the most restrictive label of whatever it cites.

Stage seven · Control

## Configure Copilot’s own controls

6 checkpoints

-   Roll out Copilot licences to the **pilot group first**. Expand by adoption, not all at once.
-   Decide whether Copilot may use **web search**. Set the policy through the Cloud Policy service.
-   **Govern Copilot agents**: review which are enabled, and who may build or install them.
-   Confirm Copilot prompts and responses are **captured in the Microsoft Purview audit log**.
-   Confirm **eDiscovery and retention cover Copilot interactions**, the same way they cover email and chat.
-   E5 Add a **Communication Compliance policy** for Copilot prompts and responses if the organization is regulated.

Stage eight · Sustain

## Make governance ongoing

5 checkpoints

-   Put the **Data Access Governance reports on a recurring schedule**. Oversharing comes back.
-   Set an **access-review cadence**: site owners re-attest their membership each quarter.
-   Track the **exit date for Restricted SharePoint Search**. Decommission it once permissions are validated.
-   Run a **site lifecycle policy**: archive inactive and ownerless sites so Copilot is not grounding on stale content.
-   Review the **label taxonomy and Copilot usage reports** each quarter, then tune.

If readiness is a bigger job than it looked

## The reports always find more than the org expected.

Stage two has a way of returning numbers nobody wants to see: hundreds of sites shared with everyone, links that never expired, sites whose owner left years ago. Copilot is worth turning on, but only once that list is worked down. If the cleanup is more than your team can take on before go-live, that is the work TenantCraft does: oversharing remediation, labelling, and a Copilot rollout that does not leak. A discovery call is free, 25 minutes, and ends with a written scope, not a sales pitch.

Web

tenantcraft.ca

Email

hello@tenantcraft.ca

Discovery call

Free · 25 minutes

Checklist last reviewed May 16, 2026. Microsoft 365 Copilot surfaces content using each user’s existing permissions. The readiness work above should be complete (or consciously deferred) before the first Copilot licence is assigned.

In this guide

1.  01 [Understand the exposure and confirm licensing](#understand-the-exposure-and-confirm-licensing)
2.  02 [Map the oversharing](#map-the-oversharing)
3.  03 [Apply the interim safety valve](#apply-the-interim-safety-valve)
4.  04 [Remediate permissions](#remediate-permissions)
5.  05 [Build the sensitivity-label foundation](#build-the-sensitivity-label-foundation)
6.  06 [Classify and protect the back-catalogue](#classify-and-protect-the-back-catalogue)
7.  07 [Configure Copilot&rsquo;s own controls](#configure-copilot-rsquo-s-own-controls)
8.  08 [Make governance ongoing](#make-governance-ongoing)

Printable copy

The whole guide is on this page already. If you'd rather work from paper, or hand it to someone who will, the PDF is the same document laid out for printing.

Email me the PDF

One email with the link. No drip sequence, no upsell. Unsubscribe any time.

Thanks, the PDF is on its way to your inbox.

Sneak peek, read it now [Download the PDF](https://tenantcraft.ca/downloads/copilot-readiness-governance.pdf)

Something went wrong. Email [hello@tenantcraft.ca](mailto:hello@tenantcraft.ca) and I'll send it manually.

The background reading

-   [Copilot readiness on Business Premium, without the reports everyone tells you to run](https://tenantcraft.ca/insights/copilot-readiness-business-premium-no-sam)

    Every Copilot oversharing guide tells you to run the Content Management Assessment and work the Data Access Governance reports. Those live in SharePoint Advanced Management, and SAM's prerequisites page does not list Microsoft 365 Business Premium as an eligible base subscription. Here is the same work, done by hand, with the commands and the hours.

-   [Turn on Copilot without leaking your HR folder](https://tenantcraft.ca/insights/copilot-without-leaking-hr)

    Microsoft 365 Copilot only shows users what they could already open, so a salary sheet shared to 'everyone' in 2019 isn't a Copilot leak, it's an oversharing leak Copilot finally made findable. Here's what to fix before you flip the switch.

-   [Purview can now archive files on a retention policy, and the storage saving is not the point](https://tenantcraft.ca/insights/purview-archive-retention-copilot)

    Retention policies and labels got an archive action this summer. Every write-up sells it on 75 percent cheaper storage. For most organisations under 500 users that saving is exactly zero, and the feature is still worth turning on, for a different reason.

-   [Restricted Content Discovery: the Copilot safety switch you shouldn't flip everywhere](https://tenantcraft.ca/insights/restricted-content-discovery-copilot)

    Restricted Content Discovery hides a sensitive site from Microsoft 365 Copilot and org-wide search. It's a genuinely useful brake, but Microsoft warns that overusing it degrades search and Copilot, so it pays to be picky about which sites get it.

-   [Restricted SharePoint Search is retiring, and the cheap Copilot fix just became a project](https://tenantcraft.ca/insights/restricted-sharepoint-search-retirement)

    Microsoft blocked new enablement of Restricted SharePoint Search on July 31, 2026. If you switched it on to make Copilot safe, you now own an unwinding project, and Microsoft has published the order to do it in.

-   [SharePoint agents without Copilot licences: what they cost, and the four ways to switch them off](https://tenantcraft.ca/insights/sharepoint-agents-without-copilot-licences)

    Agents in SharePoint were never something you turn on, and people without a Copilot licence can use them for about 12 cents a question. Here are the numbers, what an agent can actually see, and the four ways to switch it off, including the one that does not work the way admins expect.

-   [Your Teams retention policy stops covering Copilot in late October](https://tenantcraft.ca/insights/teams-retention-policy-copilot-interactions)

    If your Copilot prompts are retained by an old Teams chats policy, that stops between late October and mid-November 2026. Microsoft will treat those policies as Teams-only. Here is how to tell whether you are affected, and the one policy to add before the rollout reaches you.

Next in the sequence

-   [InfoPath Forms Decision Tree](https://tenantcraft.ca/resources/guides/infopath-forms-decision-tree)

    Plan · InfoPath

-   [SharePoint Migration Cost & Scoping Guide](https://tenantcraft.ca/resources/guides/migration-cost-scoping-guide)

    Discover · Migration

-   [We Missed the SharePoint 2026 Deadline, Now What](https://tenantcraft.ca/resources/guides/missed-deadline-recovery-guide)

    Discover · Migration

TWENTY MINUTES, NO PITCH

## Tell me what is stuck. I will tell you what it takes.

Same consultant from the first email to the last cutover. If I am not the right fit, I will refer you to someone who is.

[Book a 20-min call](https://tenantcraft.ca/contact) [See published rates](https://tenantcraft.ca/pricing)

---

_Canonical HTML: https://tenantcraft.ca/resources/guides/copilot-readiness-governance · Agent guide: https://tenantcraft.ca/llms.txt · Site map: https://tenantcraft.ca/sitemap-index.xml_
