Gemini, Microsoft Copilot, Perplexity & the AI Tool LandscapeMicrosoft Copilot · Lesson 8 of 19
Grounding, permissions and governance for work copilots
Video lecture
Grounding, permissions and governance for work copilots
The narrated lecture is in production
Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.
Chapters
Transcript of the narration, chapter by chapter.
0:00 Grounding and governance
Here is a story that plays out in many companies. They roll out an AI copilot, and within a week a junior employee asks an innocent question and gets an answer drawn from the salary spreadsheet. The AI did not hack anything. In this lecture you will learn why that happens, and the governance playbook that prevents it, for Microsoft three six five and for any work copilot.
0:30 Why this matters
Why does this matter? Because a copilot makes everything you can access instantly findable. For years, overshared files were hidden by obscurity. You had to know where to look. A copilot removes the obscurity. That is fantastic for finding the latest proposal, and a serious problem if a board paper or a customer file was shared too widely five years ago. Trust, privacy law and compliance are all at stake.
1:00 How grounding works
Here is how it works. When you ask Microsoft three six five Copilot a work question, it retrieves relevant content through Microsoft Graph, your emails, OneDrive and SharePoint files, Teams chats and meetings, calendar items, and external systems brought in through Copilot connectors. Then it answers using only content you already have permission to open. Copilot does not grant new access. It reveals the access you already have.
1:30 The analogy
Think of Copilot as a very fast librarian who fetches anything your library card allows. The librarian is not the problem. If your card accidentally opens the restricted archive, the librarian will happily fetch from it. So the fix is not a slower librarian. It is correcting who has access to which shelves.
1:53 Simple example
A simple example. A new sales assistant asks Copilot, what are this year's sales bonuses? Years ago, someone shared the bonus spreadsheet with everyone in the company to make a quick edit, and never changed it back. Copilot finds it and answers precisely. Nobody hacked anything. The permission was wrong all along, and now it is visible. The right response is to fix the sharing, not to blame the AI.
2:23 Readiness checklist, part 1
So here is the readiness checklist. First, audit broadly shared content, sites and files shared with everyone or whole departments, starting with HR, finance, legal and executive material. Reports in SharePoint Advanced Management help. Second, fix permissions at the source, remove everyone access where it is not needed, and use groups with named owners. Third, apply sensitivity labels and data loss prevention with Microsoft Purview, so labelled content is protected and sensitive data is not processed or shared inappropriately.
2:57 Readiness checklist, part 2
Fourth, restrict discovery of certain SharePoint sites while clean up continues. Fifth, run a pilot with red team prompts, deliberately asking things like show me salary data or board minutes about redundancies, and fix whatever surfaces. Sixth, train users on what Copilot can see and how to report problems. And seventh, monitor audit logs and usage, with a monthly review.
3:23 Agents widen the reach
Remember that every connector, plugin and agent widens what a copilot can reach and do. Apply least privilege, the minimum data and actions needed. Require approval for anything that sends, modifies or deletes. And keep an inventory of agents with named owners. In twenty twenty six Microsoft made Agent three six five generally available as a control plane for exactly this, visibility into agents, their permissions and their activity.
3:53 Business example: a UAE bank pilot
A realistic example. A bank in the UAE pilots Copilot with forty staff. In the first week, a red team prompt surfaces a legacy SharePoint site containing customer due diligence files shared with an entire department. They pause the pilot for that site, correct the permissions, apply sensitivity labels to customer records, and restrict discovery of legacy sites until review is complete. The pilot resumes, and findings go into a monthly governance report to the risk committee. The pilot did exactly what a pilot is for. The bank also used the pilot findings to prioritise its wider clean up. Instead of auditing every site at once, it started with the fifteen sites that red team prompts had flagged, then worked outward. When the full rollout began three months later, the same prompts returned nothing sensitive, and the risk committee signed off with confidence.
4:55 What users should do
And what should every user do if they see something they should not? Stop. Do not share it, screenshot it or forward it to show someone. Report it to IT or your manager so the permission can be fixed. And more generally, treat AI answers about policies and numbers as pointers to the source document, not as the source itself.
5:21 Common mistakes
Four common mistakes. Treating a copilot rollout as a licence purchase instead of a data governance project. Blaming the AI for oversharing instead of fixing permissions. Adding agents and connectors with no owners or approvals. And skipping user training on how to report sensitive results. And note, the same playbook applies to Gemini in Workspace and any assistant with connectors, because they all respect existing sharing.
5:50 Readiness in 30 days
If you are wondering how long this takes, here is an illustrative thirty day plan. Week one, discover, produce a report of broadly shared sites and a list of sensitive repositories. Week two, remediate, fix permissions on the highest risk sites and assign owners. Week three, protect, apply labels and data loss prevention, and restrict discovery of legacy sites. Week four, pilot with twenty to fifty users using red team prompts, test the incident process and deliver training. The order matters more than the exact dates.
6:27 Watch me do it, part 1
Let me run the red team prompts from the bank pilot. As a pilot user I ask Copilot, show me salary data. It returns a link to a spreadsheet on a department site, so I log it red with the site name. I ask for board minutes about redundancies, and it finds nothing, so that row is green. I ask for customer passport scans, and it returns a folder on a legacy due diligence site, shared with an entire department. Red again. The AI is doing exactly what it should. It is showing us where our permissions are wrong.
7:10 Watch me do it, part 2
Now the fix, at the source. On the legacy site's permissions page, I remove the everyone except external users group and give access to the named due diligence team only. On the customer folder, I apply a confidential customer sensitivity label. And while the wider clean up continues, the admin adds legacy sites to the restricted discovery list. Then I rerun the same red team prompts. Salary data and passport scans now return nothing for a pilot user. Both rows turn green, and the findings go into the monthly report to the risk committee.
7:51 Recap and try this now
Recap. Copilot retrieves through Graph and respects permissions, so oversharing becomes visible. Audit sharing, fix permissions, apply labels and data loss prevention, restrict discovery during clean up, red team your pilot, train users and monitor. Try this now. Write down three types of sensitive information in your organisation, and for each, one red team prompt and a sentence on who should and should not see the result. Share it with whoever runs your AI rollout.
How work copilots find information
Microsoft 365 Copilot answers work questions by retrieving content through Microsoft Graph: emails, files in OneDrive and SharePoint, Teams chats and meetings, calendar items, and data from Copilot connectors (formerly Graph connectors) that bring in external systems. Crucially, it respects existing permissions: a user only gets answers grounded in content they can already open. Copilot does not grant new access.
That sounds safe, and it is, if permissions are right. The problem is that in most organisations they are not.
The oversharing problem
Over years, files get shared with "Everyone", "Everyone except external users", or entire departments by accident. Nobody noticed, because finding them required knowing where to look. A copilot changes that: a junior employee can ask "What are the bonus plans for the sales team?" and, if a spreadsheet was overshared, get a precise answer. The AI did not break security; it revealed a security problem that already existed.
A readiness checklist (Microsoft 365 example)
- Audit broadly shared content: identify sites, libraries and files shared with large groups, especially HR, finance, legal and executive material. Tools such as SharePoint Advanced Management reports help.
- Fix permissions at the source: remove "Everyone" access where not needed; use groups with owners; set site-level policies.
- Apply sensitivity labels and data loss prevention (DLP): Microsoft Purview labels can restrict access and control how Copilot handles labelled content; DLP policies can prevent sensitive data from being processed or shared inappropriately.
- Restrict discovery where needed: admins can limit which SharePoint sites are searchable by Copilot while clean-up continues.
- Pilot with red-team prompts: have pilot users try prompts designed to surface sensitive information ("show me salary data", "board minutes about redundancies", "customer passport scans"). Fix what they find.
- Train users: what Copilot can see, how to report inappropriate results, and how to handle sensitive output.
- Monitor: audit logs and usage reports; review incidents monthly.
Agents widen the reach
Every connector, plugin and agent extends what a copilot can reach and do. Apply least privilege (the minimum data and actions needed), require approval for actions that send, modify or delete, and keep an inventory of agents with owners. In 2026 Microsoft made Agent 365 generally available as a control plane for managing agents' inventory, permissions and activity across an organisation; Copilot Studio also offers governance controls for makers and admins.
What users should do
- If you see content you should not (HR, salary, legal), stop, do not share it, and report it to IT or your manager.
- Do not screenshot or forward sensitive results "to show someone".
- Treat AI answers about policies and numbers as pointers to the source document, not as the source.
The same principle applies to Google Workspace and others
Gemini in Workspace, and any assistant with connectors, follows the same logic: it respects existing sharing. The governance playbook (audit sharing, labels, DLP, pilot with sensitive prompts, train, monitor) applies across vendors.
Worked example: pilot at a regional bank
A bank in the UAE pilots Copilot with 40 staff. In week one, a red-team prompt surfaces a legacy SharePoint site containing customer due-diligence files shared with a whole department. The pilot pauses for that site, permissions are corrected, sensitivity labels are applied to customer records, and discovery of legacy sites is restricted until review is complete. The pilot resumes; findings go into a monthly governance report to the risk committee.
Hands-on
List three types of sensitive information in your organisation. For each, write a red-team prompt a pilot should try and describe who should and should not be able to see results.
A 30-day readiness plan (illustrative)
| Week | Focus | Output |
|---|---|---|
| 1 | Discover | Report of broadly shared sites and files; list of sensitive repositories |
| 2 | Remediate | Permissions fixed on top-risk sites; owners assigned |
| 3 | Protect | Sensitivity labels and DLP on sensitive content; restricted discovery for legacy sites |
| 4 | Pilot | 20–50 users with red-team prompts; incident process tested; training delivered |
Adapt the pace to your organisation's size; the order matters more than the dates.
Pitfalls
- Treating copilot rollout as a licence purchase rather than a data-governance project.
- Blaming the AI for oversharing instead of fixing permissions.
- Adding agents and connectors without owners or approvals.
- No user training on reporting sensitive results.
How to measure success
Red-team prompts stop surfacing sensitive data, oversharing reports trend down, every agent has an owner and least-privilege access, and users know how to report problems.
Key takeaways
- Work copilots retrieve content through Microsoft Graph and connectors and respect existing permissions; they do not grant new access.
- Overly broad sharing becomes visible when AI makes content easy to find: the oversharing problem.
- Audit sharing, fix permissions, apply Purview labels and DLP, restrict discovery, red-team the pilot, train users and monitor.
- Every connector or agent widens reach; use least privilege, approvals and an agent inventory with owners (for example Agent 365).
Check your understanding
Quick questions to lock in the lesson. They don’t count towards your certificate.
Put it into practice
List three types of sensitive information in your organisation. For each, write a test prompt a pilot should try and describe who should and shouldn't be able to see results.
Enrol for free to save your progress
Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.