Skip to main content

Roll out Microsoft 365 Copilot without exposing every file an employee can already reach.

Copilot inherits your SharePoint and OneDrive permissions as they are. In most tenants they have drifted for years. We fix that first, label what is confidential in Purview, then roll out by cohort with the EU AI Act Article 50 documentation ready before go-live.

At a glance

Investment
Scoped per project
Duration
Project-specific
Format
Remote-first, on-site for design
Markets served
DACH and Benelux

Who it's for

  • The board wants Copilot live, and your security team has not signed off because no one has checked what it can reach across SharePoint and OneDrive.
  • You bought the licenses and adoption is flat. A pilot went out, usage stalled, and no one owns measuring what it actually changed.
  • You are a regulated entity, and Copilot becomes an AI system under EU AI Act Article 50 the moment it is switched on. You need the transparency notices and the GDPR Article 30 record before that, not after.
  • Permissions have drifted for years, and you want the oversharing found and fixed before Copilot turns it into a plain-language search result.
  • A specific workflow, answering from a policy library or drafting from approved templates, needs a purpose-built agent, and you want it built on a governed foundation rather than as a shadow tool.

Scope and format

Remote-first, with on-site sessions for the design phase. The length depends on the size of your Microsoft 365 estate, how much remediation the permissions need, and whether a Copilot Studio agent is in scope, and we fix the timeline with you before kickoff. The engagement runs in phases. First, readiness and data security: we audit how content is shared across SharePoint and OneDrive, identify the overshared sites and the files Copilot would surface to whom, and assess your Purview sensitivity labeling, DLP posture, and Copilot licensing and prerequisites against Microsoft’s published requirements. Second, remediation and labeling: we tighten the permissions that matter, apply Purview sensitivity labels to what is confidential, and configure Restricted SharePoint Search where the estate is not yet ready, so Copilot answers only from what a user should be able to reach. Third, rollout and adoption: Copilot is enabled for a first cohort, with prompt and workflow enablement for the people in it and adoption measured per cohort rather than assumed. Fourth, governance: the EU AI Act Article 50 transparency notices, the GDPR Article 30 record of processing, and the audit trail in Microsoft Purview Audit. Where a named workflow needs more than the general assistant, we design and build one agent in Copilot Studio on the same identity and data boundary. You give us tenant access, the people who own the workflows, and your security team as a checkpoint at each phase boundary.

What you get

Copilot data-exposure assessment

How content is shared across SharePoint and OneDrive, with the overshared sites and the files Copilot would surface named and ranked by sensitivity. Assessed against your real permissions, not a generic maturity score.

Oversharing remediation and sensitivity labeling

The permissions that expose confidential content tightened, Purview sensitivity labels applied to what is classified, and Restricted SharePoint Search configured where the estate is not yet ready, so Copilot respects the classification instead of ignoring it.

Licensing and prerequisite readiness report

What is in place and what is missing before Copilot can run cleanly, assessed against Microsoft’s published Copilot prerequisites rather than a generic checklist.

Staged rollout and measured pilot

Copilot enabled for a first cohort, with the prompts and workflows that fit their work and adoption measured per cohort, so the next cohort is a decision backed by data.

Governance documentation

EU AI Act Article 50 transparency notices for the employees using Copilot, a GDPR Article 30 record of processing activities, and the audit trail configured in Microsoft Purview Audit, all produced as deliverables before go-live.

Copilot Studio agent, where scoped

One purpose-built agent for a named workflow, built in Copilot Studio on the same identity and data boundary as the rollout, or a documented pattern your team can reuse to build the next one.

Handover and adoption runbook

How to extend Copilot to the next cohort and keep the labeling current after we leave, written so your team runs it without us.

Pricing

Value-based and scoped per project. We price against the state of your Microsoft 365 permissions, the size of the rollout, and whether a Copilot Studio agent is in scope, and fix the figure before we start. There is no per-seat markup on your Microsoft licensing.

Credit from a prior assessment

If you ran a Cloud Security & Identity Review or a Microsoft Landscape Assessment with us in the last eight weeks, that fee comes off this engagement.

Where your data sits

We work in your tenant with least-privilege access scoped to each phase. The sensitivity labels, DLP policies, and Restricted Search controls we configure stay in your tenant and your Azure region. Where data residency is an obligation, we keep the workloads in the Germany West Central Azure region. We sign your data processing agreement before the first access and produce the GDPR Article 30 record as a deliverable.

Governance & compliance

  • What Copilot can surface checked against real SharePoint and OneDrive permissions before the first user is enabled.
  • Purview sensitivity labels applied to confidential content so Copilot respects the classification.
  • EU AI Act Article 50 transparency notices written for the employees who will use Copilot.
  • GDPR Article 30 record of processing activities produced as a deliverable, before go-live.
  • Audit trail configured in Microsoft Purview Audit so Copilot activity is reviewable.

Includes EU AI Act positioning and how we classify AI systems.

Read our governance approach

Common questions

Do we really need to fix oversharing before turning Copilot on?

Yes. Copilot returns answers from any file the user already has permission to open, and in most tenants that permission has drifted well past what anyone intended. Switching Copilot on without fixing it does not create the exposure, it makes the existing exposure searchable in plain language. The first phase finds it before that happens.

How is this different from just enabling Copilot in the admin center?

The switch itself takes minutes. The work is everything underneath it: which files Copilot can reach, which of them are confidential and unlabeled, and what your auditor sees afterward. This engagement does that work so the switch is the last step, not the first.

Is Microsoft 365 Copilot an AI system under the EU AI Act?

Copilot generates output that employees act on, so at minimum it sits under the Article 50 transparency obligations: the people using it need to be informed they are interacting with an AI system. The governance documentation we produce covers the Article 50 notices and the GDPR Article 30 processing record explicitly.

What is Restricted SharePoint Search, and would we need it?

It is a Microsoft control that limits Copilot and enterprise search to an approved set of SharePoint sites while wider remediation is still in progress. We use it as an interim measure where the estate is too large to fully remediate before the rollout has to start, then retire it as the permissions and labeling catch up.

What is the difference between Microsoft 365 Copilot and Copilot Studio?

Microsoft 365 Copilot is the general assistant across Teams, Outlook, Word, and the rest of Microsoft 365. Copilot Studio is where you build a purpose-built agent for a specific workflow, for example answering from a controlled policy library. Both are in scope here. Most rollouts are the general assistant first, with one Studio agent where a workflow genuinely needs it.

Our last Copilot pilot stalled. How is this different?

Adoption stalls when a pilot ships with no measurement and no enablement, so no one can say whether it helped. Here the rollout is staged by cohort, each cohort gets the prompts and workflows that fit their work, and usage is measured per cohort. The next cohort is a decision with data behind it, not a hope.

Do you handle the Copilot licensing, or only the configuration?

We check what licensing and prerequisites you already have and tell you exactly what is missing in the readiness report. We do not procure licenses or negotiate commercial terms with Microsoft; that stays with your Microsoft account team or reseller. Once the licensing is in place, we do the readiness, remediation, rollout, and governance work around it.

Who does the work, and what credential is behind it?

The identity, permissions, and Purview work is done in your tenant, and the credential behind it is AZ-500 for identity and security architecture. The EU AI Act documentation is written as an engineering deliverable rather than a policy template.

How is the price set?

Value-based and scoped per project. We scope the remediation, the rollout size, and any Copilot Studio agent with you, fix the figure before kickoff, and credit any Cloud Security & Identity Review or Microsoft Landscape Assessment fee from the last eight weeks against it.

Where is our data processed?

In your tenant, in the Azure region you are bound to. Where data residency is an obligation, we keep the workloads in the Germany West Central Azure region, and we sign your data processing agreement before the first access.

Do you stay on after the rollout?

The engagement ends with a handover session and an adoption runbook. If you want us to run the rollout across the rest of the organisation, keep the labeling current, or build further Copilot Studio agents, that is a separate engagement.

Request the Microsoft 365 Copilot engagement

Verifying your browser…