Governance

Oversharing and Copilot in your intranet

Accelerator 365 intranet governance graphic highlighting the importance of reviewing and cleaning up access permissions before introducing AI tools such as Microsoft Copilot.
This post is part of our series on SharePoint intranet governance.

Microsoft 365 Copilot answers a question by reading content the person asking already has permission to open. Copilot in this post means the assistant itself rather than the license or the wider family of products. The governance decisions in this area are about access an organization has tolerated for years, which content is fit for an assistant to read out to somebody who never opened the page, and who answers when what comes back is wrong.

Whether to deal with oversharing before or after Copilot arrives

Permissions are the only mechanism an intranet team holds that does not depend on goodwill, since training, habit and a published rule all rely on people choosing to follow them. Copilot reads within those permissions, so a site thousands of people can open but nobody visits stops being dormant and starts producing answers.

The choice is whether to work through that access before people start asking Copilot questions, or to roll out and treat the answers people get as the thing that finally gets permissions looked at. Our (predictable) view is that dealing with it first is the safer default, and how firmly that holds depends on how much risk the organization will carry. A tenant where the worst case is somebody reading an announcement a week early is not the same as a tenant where the finance site is open to everybody.

Tenant-wide settings, and anything with a security or compliance consequence, sit with IT, which covers nearly everything below. Microsoft gathers most of it in SharePoint Advanced Management, and the reason it is worth knowing about now is that the tooling arrives once at least one person in the tenant holds a Microsoft 365 Copilot license, rather than needing a separate purchase.

Where you see who can reach what

The reporting that shows where oversharing sits is in the SharePoint admin center, in the data access governance reports. The snapshot reports cover permissions as they stand, including site permissions across the organization and which sites hold files carrying a given sensitivity label, and that last one requires E5 or G5. The activity reports cover the last 28 days of sharing links created and of content shared with everyone except external users.

The content management assessment hub sits in the same place and comes with the same licensing. It runs a guided assessment of content practices and returns recommendations, and Microsoft suggests rerunning it every 30 days. A report read once is a snapshot and read on a cycle it is oversight.

What the restriction controls do, and what they leave in place

Two site-level controls change what Copilot can reach. Restricted Content Discovery keeps a site out of organization-wide search and out of Copilot answers, including files somebody accessed recently, and it removes the AI entry points on the site itself, which are the Copilot button, the AI actions menus and creating pages with AI. Permissions are untouched and the content stays in the search index, so everybody who could open the site before still can. Using the setting requires a Microsoft 365 Copilot license, and a tenant setting can delegate it so site administrators manage it rather than only tenant administrators. 

Restricted Access Control does something closer to what people expect from a permissions change, limiting a site to the members of named security groups so content there is visible in Copilot only to that group. 

Sensitivity labels sit alongside these, managed through Microsoft Purview. A label applied to content in SharePoint or OneDrive is honored while Copilot is grounding an answer, and a response in Copilot Chat reflects the highest-priority label among the references used.

Who answers when Copilot gives out something wrong

When somebody asks Copilot a question and the answer comes back wrong out of an intranet page, the area that published that page is most likely answerable for this. The content was already there and already readable by the person who asked, although Copilot repeated it to somebody who would not necessarily have opened the page. Accountability for an area's authors sits with the area that publishes, and the intranet team keeps the right to require a page be corrected. 

Copilot in SharePoint carries the one native action pointed at this. It lists the inactive pages on a site and offers to demote them, which deprioritizes pages in search and in the results an agent returns, and adds a banner saying that the pages are not maintained. Using it requires a Microsoft 365 Copilot license. 

Where the mechanics stop short

The restriction controls reduce what Copilot can see. None of them settles why it could see the content, which is a question about who was given access and why nobody removed it. Microsoft cautions against heavy use of Restricted Content Discovery for that reason, since the setting takes content out of organization-wide search as well as out of Copilot answers. A site nobody can find in search is not a governed site. 

Nothing in the platform records who is answerable for a page either, so the correction that follows a wrong answer is one the organization has to chase rather than one SharePoint prompts anybody to make.

Common questions

Does Microsoft 365 Copilot respect SharePoint permissions?

Yes. Copilot surfaces only content the person asking has at least view permission on. So the oversharing an organization finds after a rollout was already there, and what changes is that content arrives in an answer rather than waiting to be found. 

Should you fix oversharing before rolling out Copilot?

Our view is that working through it first is the safer default, and how firmly that holds depends on what the content is. Restricted Content Discovery and Restricted Access Control both reduce what Copilot can reach on a site, and neither decides who should have had access. 

What is Restricted Content Discovery in SharePoint?

It is a site-level setting that keeps a site out of organization-wide search and out of Copilot answers and removes the AI entry points on the site itself. It changes no permissions, so anybody who could open the site can still open it, and it does not take the content out of the search index. Using it requires a Microsoft 365 Copilot license, and Microsoft cautions against using it heavily because content restricted this way leaves organization-wide search as well. 

What is Restricted Access Control in SharePoint?

It is a setting that limits a site to the members of named security groups, so people outside those groups cannot reach the site or its content even where they had permissions or a sharing link before. Content on a site restricted this way is visible in Copilot only to members of those groups, and organization-wide search results honor the same limit. It is part of SharePoint Advanced Management, so it arrives with a Microsoft 365 Copilot license. 

Series links

→ Next in the series: measuring intranet governance

→ Series hub: our guide to SharePoint intranet governance

Reading next

Accelerator 365 intranet governance graphic highlighting the importance of fixing underlying page structure and content rather than simply adding new navigation links.
Accelerator 365 intranet governance graphic highlighting the need to look beyond traffic and usage metrics to measure meaningful accountability and intranet performance.