Roll out Microsoft 365 Copilot without exposing every file an employee can already reach.
Copilot inherits your SharePoint and OneDrive permissions as they are. In most tenants they have drifted for years. We fix that first, label what is confidential in Purview, then roll out by cohort with the EU AI Act Article 50 documentation ready before go-live.
At a glance
- Investment
- Scoped per project
- Duration
- Project-specific
- Format
- Remote-first, on-site for design
- Markets served
- DACH and Benelux
Who it's for
- The board wants Copilot live, and your security team has not signed off because no one has checked what it can reach across SharePoint and OneDrive.
- You bought the licenses and adoption is flat. A pilot went out, usage stalled, and no one owns measuring what it actually changed.
- You are a regulated entity, and Copilot becomes an AI system under EU AI Act Article 50 the moment it is switched on. You need the transparency notices and the GDPR Article 30 record before that, not after.
- Permissions have drifted for years, and you want the oversharing found and fixed before Copilot turns it into a plain-language search result.
- A specific workflow, answering from a policy library or drafting from approved templates, needs a purpose-built agent, and you want it built on a governed foundation rather than as a shadow tool.
Scope and format
What you get
Copilot data-exposure assessment
How content is shared across SharePoint and OneDrive, with the overshared sites and the files Copilot would surface named and ranked by sensitivity. Assessed against your real permissions, not a generic maturity score.
Oversharing remediation and sensitivity labeling
The permissions that expose confidential content tightened, Purview sensitivity labels applied to what is classified, and Restricted SharePoint Search configured where the estate is not yet ready, so Copilot respects the classification instead of ignoring it.
Licensing and prerequisite readiness report
What is in place and what is missing before Copilot can run cleanly, assessed against Microsoft’s published Copilot prerequisites rather than a generic checklist.
Staged rollout and measured pilot
Copilot enabled for a first cohort, with the prompts and workflows that fit their work and adoption measured per cohort, so the next cohort is a decision backed by data.
Governance documentation
EU AI Act Article 50 transparency notices for the employees using Copilot, a GDPR Article 30 record of processing activities, and the audit trail configured in Microsoft Purview Audit, all produced as deliverables before go-live.
Copilot Studio agent, where scoped
One purpose-built agent for a named workflow, built in Copilot Studio on the same identity and data boundary as the rollout, or a documented pattern your team can reuse to build the next one.
Handover and adoption runbook
How to extend Copilot to the next cohort and keep the labeling current after we leave, written so your team runs it without us.
Pricing
Credit from a prior assessment
If you ran a Cloud Security & Identity Review or a Microsoft Landscape Assessment with us in the last eight weeks, that fee comes off this engagement.
Where your data sits
Governance & compliance
- What Copilot can surface checked against real SharePoint and OneDrive permissions before the first user is enabled.
- Purview sensitivity labels applied to confidential content so Copilot respects the classification.
- EU AI Act Article 50 transparency notices written for the employees who will use Copilot.
- GDPR Article 30 record of processing activities produced as a deliverable, before go-live.
- Audit trail configured in Microsoft Purview Audit so Copilot activity is reviewable.
Includes EU AI Act positioning and how we classify AI systems.
Read our governance approach