Copilot readiness assessment

Copilot will read what your users can reach. Check that first.

In a typical tenant an ordinary account can open hundreds of thousands of files, and dozens of sites hold card numbers, IDs or payroll data behind links anyone in the company can follow. Copilot honours every one of those permissions. 1Security scans your tenant read-only, ranks the sites Copilot would read by sensitive content and exposure, and stages the cleanup behind a review window - before the licenses go out.

The problem

The rollout is decided. Nobody can describe what Copilot will see.

The business wants Copilot this quarter, and security is asked to sign off on a tenant nobody has mapped: sites from projects that ended in 2022, sharing links from 2023, groups nested inside groups. Copilot does not break your permissions - it reads exactly what the signed-in user can already open. The permissions are the problem.

What we see on the first scan is consistent: a typical user can reach hundreds of thousands of files, most tenants hold several times more sites than IT believes they have, and 20-40% of the files with sensitive content carry no sensitivity label at all. Every one of those files is one plain prompt away from a summary on somebody's screen.

Assessing that by hand means months of per-site reviews that are stale before they finish. The assessment has to come from the tenant itself: what would Copilot read, where is the sensitive data concentrated, and which of it is exposed further than anyone intended.

In practice

From read-only consent to a go decision in four steps.

The whole assessment runs on read-only consent and standard licenses - first numbers the same day.

  1. 01

    Connect read-only and let the scan run

    One consent, no agent, nothing installed. The inventory of sites, files, users and groups starts filling the same day, and 1Security's own engine scans content for 300+ sensitive information types - no E5, no Purview deployment required. Sensitive Info shows what has been found and how many files, sites and users can reach each type.

  2. 02

    Rank the sites Copilot would read

    Open Sites, filter to Copilot enabled + with sensitive info, sort by detections. Every row shows storage, external users, sharing links and how many people can enter. In a mid-size tenant this list is typically 30-80 sites - the exact places an AI answer could go wrong, in order.

  3. 03

    Stage the cleanup before rollout

    Enable the suggested automations - block Copilot org-wide search on externally exposed sensitive sites and on abandoned sites, expire the anyone links on files with sensitive content - and 1Security stages a proposal per site behind a 72-hour review window, with owners able to object before anything changes.

  4. 04

    Keep the gate closed after rollout

    The prebuilt "Sensitive Data Exposure to Copilot" trend counts the exposed sensitive files week over week, and the Agents screen shows every Copilot agent employees build or install with its reach in files, sites, users and emails - so a readiness assessment does not expire the day after the go decision.

What makes it work

Three parts of the platform behind the assessment.

The assessment is not a separate product. Everything below keeps running after rollout.

  • Copilot security

    Every AI agent in the tenant, from every source, inventoried in one place, with its reach measured in files, sites, users and emails before employees start chatting with it.

    Explore the feature
  • SharePoint governance

    The Copilot-enabled flag, sensitive-info counts, external users and sharing links per site - the columns the readiness ranking is built from.

    Explore the feature
  • Access management

    Effective access resolved through groups, links and inheritance, so "what would Copilot read for this user" has an exact answer, not an estimate.

    Explore the feature

FAQ

Common questions.

Do we need E5 or Purview to run the assessment?

No. 1Security detects 300+ sensitive information types with its own engine, including OCR for scans and screenshots, on a Microsoft 365 Business Basic license upward. If you already run Purview, its detections and labels are synced in and shown right next to ours.

Does 1Security change how Copilot behaves?

Only where you tell it to. Blocking Copilot org-wide search per site and expiring sharing links are staged automations under the separately consented write module, each with a review window. Everything else is read-only measurement.

How long until we have numbers?

The same day. The site ranking, the reach counts and the label coverage gap update continuously as the scan proceeds. Large tenants keep scanning in stages for weeks, but the top of the list is usually right within hours.

How does this relate to SharePoint Advanced Management?

They work together. SharePoint Advanced Management gives you site-level reports and controls inside SharePoint. 1Security adds what is inside those sites, the people, apps and AI agents that can reach them, and stages the fix - on standard Microsoft 365 licenses.

Assess it on your tenant, not on a slide.

Connect read-only and see the sites Copilot would read ranked by sensitive content and exposure - the same day, before the licenses go out.

Or sign off on a permission state nobody can describe.