You ask, we answer · 04 September 2026

Must we fix oversharing before turning on Copilot?

Our SharePoint permissions are a mess — Everyone and old sharing links everywhere. Leadership wants Copilot next month. Can we go live and clean up later?
oversharingsecuritycopilotwave-0

Grounded with: Microsoft Learn — Restricted Content Discovery; Copilot Control System security; SAM get-ready guidance

DIGITAL SKILL WORKS LTD / 12 PANES


You’re right to worry. Copilot doesn’t invent access — it retrieves and summarises across what users (and agents) can already see. Overshared sites become programme-scale visibility overnight.

Here’s what’s happening. Microsoft’s own readiness guidance puts remediating oversharing first: use SharePoint Advanced Management and Purview to find broad links, oversized audiences, ownerless or inactive sites, then apply interim controls while you fix permissions. Restricted Content Discovery can keep high-risk sites out of organisation-wide search and Copilot discovery without changing permissions — useful while owners clean up. Restricted SharePoint Search was a temporary allow-list approach and is retiring for new enablement; don’t build a long-term strategy on it. None of these discovery controls are a substitute for fixing ACL debt.

This is Third Law meets Steady before scale: convenience of “search everything” collides with how easily someone else (or everyone’s Copilot) can reach the same data. Pane 04 Security leads Wave 0 for a reason.

Options that actually work in practice:

  1. Cohort + hotspot list. Name the worst sites (severity × blast radius), assign business owners and dates, enable RCD on those sites, roll Copilot Premium to a cleared cohort only. Best balance for most organisations.
  2. Full tenant freeze until perfect. Theoretically clean; politically rare, and perfection isn’t required for Wave 0. Good enough is named hotspots, owners, and IR gaps — not spotless SharePoint.
  3. Go live for everyone, remediate later. Leadership likes the date. The downside is confidential content in chat answers, trust damage, and a harder cleanup under spotlight. I’d avoid this.

The caution: Discovery restrictions aren’t a security boundary. Users may still see content they own or recently opened. Fix permissions and labels; use Purview DLP for Copilot where licensed; keep Restricted Search only if you already depend on it and have an exit plan.

I’d suggest telling leadership: Copilot can land next month for a bounded cohort if Security’s hotspot list is live this week. Broad seat spray waits until Steady holds. That frames delay as risk control, not obstruction.

Good on you for raising it before the PO — you’ll have peace of mind when answers match what people were meant to see.

DIGITAL SKILL WORKS LTD / 12 PANES · You ask, we answer

All answers Ask a question