Before you switch Copilot on, someone should read what it can reach.
Microsoft already produces the reports. It does not read them for you, and in a company of your size nobody has a spare week to. We read them, rank what matters, fix the worst of it with you, and leave a dated record you can hand to a customer, an auditor or your own board.
Microsoft grants these the moment one person in your tenant holds a Copilot licence.
SharePoint Advanced Management arrives with the first Copilot seat, and the prerequisites page states that condition with no base-subscription qualifier on it. So the scan is not the scarce thing, and any vendor selling you one is selling a report your own administrator can generate this afternoon. What is scarce is somebody reading several thousand rows, ranking them, and writing down what was changed.
Sites, OneDrive sites and files. Who can reach what, tenant-wide.
Microsoft Learn
The two report families that surface most real oversharing.
Microsoft Learn
Delegate the reading of those reports to the owners of overshared sites.
Microsoft Learn
Repeatable test sets with expected responses and a pass rate, plus the golden-prompt methodology Microsoft publishes itself.
Microsoft Learn
Two things are worth knowing before you plan around them. The Purview data-risk assessments for AI need Microsoft 365 E5 or the Purview Suite, so most tenants of this size cannot reach them. And Restricted SharePoint Search, the allow-list many 2025 rollout plans leaned on, is retiring: Microsoft blocks new enablement from 31 July 2026.
One tenant. One week of elapsed time. Five things, in this order.
The order matters more than the list. Oversharing is triaged before anything else is discussed, because a tenant with open tenant-wide links does not have an adoption problem yet.
Anything outside this is quoted separately, and we will tell you on the call rather than in an invoice.
- You generate the SharePoint Advanced Management reports; we tell you exactly which ones and how.
- We read the exports and rank every finding by what a person could actually reach through Copilot.
- We fix the worst of it with you: the open tenant-wide links, the ownerless sites, the libraries shared with everyone.
- We write 30 to 50 questions worth failing with the people who know the answers, and run them in your own Copilot Studio evaluator.
- We hand over the finding list, the remediation order, a record of what changed, and the exports it was built from.
What you are left holding when we leave.
A workshop leaves you with a memory of a workshop. This is the test we hold the engagement to: can somebody who was not in the room read the output twelve months later and know what was true, and what was changed.
A ranked finding list
Ordered by reachability, not by report row count. The first ten items are the ones worth a morning.
A dated record of what changed
What was open, what was closed, when, and by whom. This is the part that survives being read by someone who was not there.
The exports and the question set
Yours, in your tenant. The next engineer re-runs the same checks without starting from zero.
It is written to be forwarded. Operators under DORA and NIS2 have to keep a register of their ICT third-party arrangements and answer supplier questionnaires about them, so whatever they take away has to survive being read by a compliance officer who will never visit this site. That is what the dated record is for. It is evidence that a check was made on a date; it is not a certification, and nobody should present it as one.
By default we connect to nothing.
Your administrator runs it
The reports are generated under your own entitlement, by your own SharePoint administrator, and exported. We read the exports.
If you want a direct read: two grants, named
Sites.Read.All and Files.Read.All. Never Sites.FullControl.All, which is what enumerating site permissions through Graph would require, and which permits full control of every site collection you own.
Counts, not contents
No document contents or titles, no URLs carrying project or person names, no user principal names, no email addresses. If a model helps write the report, it receives the aggregate findings, never your export.
A report that could not be generated, or that came back truncated, is reported as incomplete, never as clean. A partial read and a healthy tenant look identical in a summary, and the difference surfaces months later.
Three cases where the answer is no.
- You are on Microsoft 365 E5 or hold the Purview Suite. The data-risk assessments for AI that Microsoft builds are already yours; use those first.
- You have an in-house Microsoft 365 administrator with time to read the reports. They will do it better than we will, because they know your business.
- Your existing partner assessment already left you with a dated document you could hand to a customer. That was the deliverable; you have it.
We would rather say this on a page than discover it on a call you paid for.
Everything else here is scoped to you.
Some corpora should not be indexed into Microsoft 365 at all, and some answer paths need a private retrieval surface in your own cloud account. That is an implementation engagement, scoped and quoted after the audit. Not a product, not a connector catalogue, and not something this page will pretend already runs. Systems outside Microsoft 365, Confluence and Jira among them, are reached the same way: as engagement work, one at a time, priced when the source is understood.
Scope an implementationThe objections worth answering in writing.
Our Microsoft partner says the assessment is included. Why would we pay for this?
Often you should not, and we will say so. The difference is what you are left holding. A funded partner assessment is usually a workshop and a deck, delivered by the party that also sells you the licences. This is a fixed fee that does not move with your licence bill, delivered by someone outside your organisation, and it ends in a dated document you can hand to a customer, an auditor or your own board. If your existing assessment already left you with that, you do not need us.
What do you connect to, and is it read-only?
By default we connect to nothing. Your SharePoint administrator generates the reports Microsoft already grants you (permission state for sites, OneDrive and files, sharing links, and the "everyone except external users" insights) and exports them. We read the exports. If you would rather we read some of it directly, the app registration asks for Sites.Read.All and Files.Read.All and nothing else. We never ask for Sites.FullControl.All in your tenant, which is the grant that would be needed to enumerate site permissions through Graph, and which permits full control of every site collection you own.
Do we already have these reports?
Almost certainly yes. Microsoft grants SharePoint Advanced Management, including the Data Access Governance reports, as soon as one user in your tenant is assigned a Microsoft 365 Copilot licence, with no base-subscription qualifier on that condition. The reports are not the scarce thing. Somebody with the time and the background to read several thousand rows, rank them by what actually matters, and write down what was changed: that is the scarce thing.
What do you keep afterwards?
Counts, ratios, site-level classifications and finding codes. No document contents, no document titles, no URLs carrying project or person names, no user principal names, no email addresses. If a language model helps write the report it receives the aggregate findings, never your export. We hold the aggregate finding set for the engagement plus any re-score quarter you bought, and no longer.
What do we get, and how long does it take?
One week of elapsed time for one tenant. You get a ranked finding list with the remediation order, the worst items fixed inside the fixed scope, a written record of exactly what changed, and the exports the findings were built from. It is yours: the next engineer, or the next vendor, can re-read it without starting from zero.
Do you test the answers our agents actually give?
As a module of the audit, and inside your own tooling. Copilot Studio ships an evaluator that runs repeatable test sets with expected responses and returns a pass rate, and Microsoft publishes the methodology. We are not selling you a second one. What we do is sit with the people who know the answers and write 30 to 50 questions worth failing, then read the failures with you. Microsoft suggests a larger set for a full deployment, so treat ours as a scoped first pass. The question set stays in your tenant.
What happens if a report cannot be generated, or comes back incomplete?
It is reported as incomplete, never as clean. A truncated export and a healthy tenant look identical in a summary, and the difference surfaces months later in a room. A partial read produces a partial pack that says which sources were unreadable and why.
A scoping call is thirty minutes and costs nothing.
Bring your licence position and roughly how many SharePoint sites you have. You will leave the call knowing whether this is worth €1,990 to you, including if the answer is no.
Book a scoping callPrefer written scope first? Email us