Gemini, Microsoft Copilot, Perplexity & the AI Tool LandscapeMicrosoft Copilot · Lesson 8 of 19

Grounding, permissions and governance for work copilots

Article · 16 min · 8 min lecture

Video lecture

Grounding, permissions and governance for work copilots

15 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 15

Grounding and governance

  • How copilots find information
  • Why oversharing surfaces
  • How to fix it

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

How work copilots find information

Microsoft 365 Copilot answers work questions by retrieving content through Microsoft Graph: emails, files in OneDrive and SharePoint, Teams chats and meetings, calendar items, and data from Copilot connectors (formerly Graph connectors) that bring in external systems. Crucially, it respects existing permissions: a user only gets answers grounded in content they can already open. Copilot does not grant new access.

That sounds safe, and it is, if permissions are right. The problem is that in most organisations they are not.

The oversharing problem

Over years, files get shared with "Everyone", "Everyone except external users", or entire departments by accident. Nobody noticed, because finding them required knowing where to look. A copilot changes that: a junior employee can ask "What are the bonus plans for the sales team?" and, if a spreadsheet was overshared, get a precise answer. The AI did not break security; it revealed a security problem that already existed.

A readiness checklist (Microsoft 365 example)

  1. Audit broadly shared content: identify sites, libraries and files shared with large groups, especially HR, finance, legal and executive material. Tools such as SharePoint Advanced Management reports help.
  2. Fix permissions at the source: remove "Everyone" access where not needed; use groups with owners; set site-level policies.
  3. Apply sensitivity labels and data loss prevention (DLP): Microsoft Purview labels can restrict access and control how Copilot handles labelled content; DLP policies can prevent sensitive data from being processed or shared inappropriately.
  4. Restrict discovery where needed: admins can limit which SharePoint sites are searchable by Copilot while clean-up continues.
  5. Pilot with red-team prompts: have pilot users try prompts designed to surface sensitive information ("show me salary data", "board minutes about redundancies", "customer passport scans"). Fix what they find.
  6. Train users: what Copilot can see, how to report inappropriate results, and how to handle sensitive output.
  7. Monitor: audit logs and usage reports; review incidents monthly.

Agents widen the reach

Every connector, plugin and agent extends what a copilot can reach and do. Apply least privilege (the minimum data and actions needed), require approval for actions that send, modify or delete, and keep an inventory of agents with owners. In 2026 Microsoft made Agent 365 generally available as a control plane for managing agents' inventory, permissions and activity across an organisation; Copilot Studio also offers governance controls for makers and admins.

What users should do

  • If you see content you should not (HR, salary, legal), stop, do not share it, and report it to IT or your manager.
  • Do not screenshot or forward sensitive results "to show someone".
  • Treat AI answers about policies and numbers as pointers to the source document, not as the source.

The same principle applies to Google Workspace and others

Gemini in Workspace, and any assistant with connectors, follows the same logic: it respects existing sharing. The governance playbook (audit sharing, labels, DLP, pilot with sensitive prompts, train, monitor) applies across vendors.

Worked example: pilot at a regional bank

A bank in the UAE pilots Copilot with 40 staff. In week one, a red-team prompt surfaces a legacy SharePoint site containing customer due-diligence files shared with a whole department. The pilot pauses for that site, permissions are corrected, sensitivity labels are applied to customer records, and discovery of legacy sites is restricted until review is complete. The pilot resumes; findings go into a monthly governance report to the risk committee.

Hands-on

List three types of sensitive information in your organisation. For each, write a red-team prompt a pilot should try and describe who should and should not be able to see results.

A 30-day readiness plan (illustrative)

WeekFocusOutput
1DiscoverReport of broadly shared sites and files; list of sensitive repositories
2RemediatePermissions fixed on top-risk sites; owners assigned
3ProtectSensitivity labels and DLP on sensitive content; restricted discovery for legacy sites
4Pilot20–50 users with red-team prompts; incident process tested; training delivered

Adapt the pace to your organisation's size; the order matters more than the dates.

Pitfalls

  • Treating copilot rollout as a licence purchase rather than a data-governance project.
  • Blaming the AI for oversharing instead of fixing permissions.
  • Adding agents and connectors without owners or approvals.
  • No user training on reporting sensitive results.

How to measure success

Red-team prompts stop surfacing sensitive data, oversharing reports trend down, every agent has an owner and least-privilege access, and users know how to report problems.

Key takeaways

  • Work copilots retrieve content through Microsoft Graph and connectors and respect existing permissions; they do not grant new access.
  • Overly broad sharing becomes visible when AI makes content easy to find: the oversharing problem.
  • Audit sharing, fix permissions, apply Purview labels and DLP, restrict discovery, red-team the pilot, train users and monitor.
  • Every connector or agent widens reach; use least privilege, approvals and an agent inventory with owners (for example Agent 365).

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. A copilot surfaces a salary spreadsheet to a junior employee. What is the most likely root cause?
  2. Which is a sound step before a company-wide copilot rollout?
  3. You see confidential HR information in a copilot answer that isn't relevant to your role. What should you do?

Put it into practice

List three types of sensitive information in your organisation. For each, write a test prompt a pilot should try and describe who should and shouldn't be able to see results.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.