Skip to content
airlark
Menu

The fair question

A licence is not an implementation.

Microsoft 365 Copilot may be exactly the right product. Buying it still leaves your business to decide which information is ready, whether existing access is appropriate, what people should use it for and how the rollout will be governed.

What the product provides

Start with what is already true.

Microsoft states that Microsoft 365 Copilot works with information a user is already permitted to access through Microsoft Graph. It also states that prompts, responses and data accessed through Microsoft Graph are not used to train foundation models.

Microsoft also provides administrative, reporting and audit capabilities, although the available controls depend on the relevant subscription and configuration. Those are material reasons to choose the product, not footnotes to dismiss.

Microsoft: data, privacy and security for Microsoft 365 Copilot
Microsoft: enterprise data protection for Copilot

Existing access

Copilot respects permissions. That makes the permissions important.

If someone can already access a document, Copilot may be able to use that access when responding to them. A broad sharing link, an ownerless SharePoint site or years of inherited access can therefore become part of the rollout question.

Microsoft’s own deployment guidance recommends assessing content, identifying potentially overshared material, reviewing inactive or ownerless sites and adjusting SharePoint and OneDrive access where required before wider use.

Microsoft: prepare SharePoint for Copilot and agents

The point is not that Copilot ignores access controls.

The point is that the quality of the result depends partly on the access model and company information it inherits.

The work after licensing

Six decisions remain.

  1. Who starts first? Choose the people and responsibilities that justify access before assigning seats broadly.
  2. Which information is ready? Identify useful, current and properly owned sources instead of treating every shared location as equally trustworthy.
  3. Are existing permissions appropriate? Review access and sharing where the chosen workflow touches sensitive or widely shared information.
  4. What should change? Name one recurring workflow and the result people need, rather than measuring success by chat activity alone.
  5. What should be logged and retained? Match audit access, prompt visibility and retention to the organisation’s responsibilities and available licensing.
  6. Who owns the rollout? Give adoption, support, policy questions and review of results to named people.

These are implementation decisions. Some are product configuration, some are information management, and some are ordinary operational ownership.

Three sensible choices

Use the smallest suitable boundary.

Use Microsoft 365 Copilot

Choose it when Microsoft 365 is already the centre of the work and its access, data handling, controls and integration shape fit the workflow.

Use a hybrid approach

Keep company information or workflow components inside a customer-controlled environment while using approved hosted model services where their terms and controls fit.

Use a different customer-controlled system

Consider this when the workflow needs a different provider, deployment boundary, integration or ownership model. The added complexity must be justified by the actual requirement.

Airlark is not paid to reject Copilot. A review can recommend using it.

Company AI Control Review

Make the decision before the rollout.

For €1,000, Airlark reviews one workflow, the company information involved and the available tools. Within five business days, you receive a written plan recommending Copilot, another existing service, a bounded customer-controlled implementation or no project.

The review includes one 60-minute workshop and a 30-minute readout. It does not require credentials or live system access.