What a Copilot Readiness Check Covers
A readiness check is an inventory of what Copilot will be able to reach, plus a decision about what to fix before it can. Four areas: who can see what, how sensitive content is marked, what is out of date, and where Copilot gets switched on first.
Readiness is not adoption. User training, prompt libraries and use case selection all matter, and all of them belong after go-live. Putting them in the same assessment is why readiness projects run for months without producing a fix list.
The two jobs also have different owners. Readiness belongs to IT and compliance, adoption belongs to the business, and giving both to the same person is how the security work stops the week the pilot starts going well.
Nobody decides to skip it. The pilot has a launch date. The permission review rarely does, so it slips instead of blocking anything.
Microsoft's own preparation guidance for SharePoint splits the same way. Its five steps are all environment work: run the assessment, manage site lifecycle, close oversharing, use the admin agent, set up backup. None of them is about teaching anyone to write a prompt.
An AI Readiness Checklist You Can Run Before Turning Copilot On
Six checks, in the order that matters.
| Check | How to check it | Owner |
| Sites shared with everyone in the organization | Everyone except external users report | IT |
| Overall permission exposure across sites | Site permissions baseline report | IT |
| Link expiry and sharing defaults | Policies then Sharing, in the SharePoint admin center | IT |
| Sensitivity labels on regulated content | Sensitivity label snapshot report and Purview | Compliance |
| Sites nobody owns or has reviewed | Site ownership and inactive site policies | Content owners |
| Which group gets Copilot first | Microsoft 365 admin center | IT |
Microsoft bundles most of this into one place. The Content Management Assessment in the SharePoint admin center runs the reports and sorts the sites that need attention. Microsoft describes one of its purposes as defining Copilot readiness for the organization, and recommends rerunning it every thirty days while you remediate.
You probably already have the tooling. SharePoint Advanced Management switches on for your SharePoint administrators as soon as a single user in the tenant holds a Microsoft 365 Copilot license.
Restricted Content Discovery does the second one without changing a single permission. That is how you unblock a rollout that would otherwise wait behind a permissions project.
The obvious move is to lock everything down first and reopen on request. It breaks in week three.
You cannot tell which permissions people actually rely on, so every reopening request gets approved blind. Three months later the environment is back where it started, and IT is the department that blocked everyone for nothing.
Small tenants do not need any of this tooling. Twenty sites and two content owners is an afternoon with a spreadsheet, and buying a scanning tool for that adds admin work rather than reducing risk.
The pilot group I would pick is one department with ordinary content rather than the executive team. The findings come out the same, and nobody has to explain a surprise to the board.
Who Is Responsible When Copilot Returns the Wrong File
Microsoft owns the model, the hosting, the EU Data Boundary commitments, and the guarantee that your prompts, responses and Graph data are not used to train foundation models. You own who can see what and who approved the rollout scope. Whether that content is still correct sits with you as well.
Copilot returns a file the user had permission to open, so no control failed. The organization still has a problem, and no product closes that gap.
Site access reviews close it. SharePoint Advanced Management lets you hand a data access governance report to the site owners who created the exposure, which is the only version of this that scales past a few dozen sites.
That is also why a risk assessment for Copilot looks at the tenant rather than at Copilot. The questions are all about your configuration: which sites carry permissions nobody has reviewed since a migration, and which document sets still hold versions that should have been retired.
The question I would settle before go-live is who signs off on rollout scope. That is different from who runs the project. It is whoever puts their name on the decision that this group of people can now ask questions across this set of content.
Most organizations answer that question only after the first awkward result, in front of the people it affects. The answer ends up the same either way.
Timing Decides How Much of This Gets Fixed
Timing decides how much of this gets funded. While the Copilot business case is still open, permission cleanup is part of the project and has a budget line. After go-live, the same findings turn into a list of reasons someone should have checked earlier, and nobody wants to own that list.
Precio Fishbone runs that assessment across the Microsoft stack, from the permission layer underneath Copilot to the governance model above it. If you want to know what Copilot would surface in your tenant next week, talk to our team about an AI data and governance review.
Talk to our expertFrequently Asked Questions
What is a Copilot readiness assessment?
A structured review of what Copilot will be able to reach in your tenant, run before you enable it. It covers permission exposure, sensitivity labels, ownerless sites and rollout scope, and it ends in a fix list with named owners.
Do we need to fix SharePoint before enabling Copilot?
In most tenants, yes. Copilot surfaces whatever the signed-in user can already open, so inherited permissions and old sharing links become visible in the first week. The work is permission cleanup in SharePoint, not a Copilot setting.
How long does a Copilot readiness assessment take?
The number of SharePoint sites involved and the number of content owners who have to be consulted set the timeline, not the scanning. Consultation is almost always the slower half.
Is Microsoft 365 Copilot secure by default?
Copilot inherits your existing permissions rather than creating new ones, so it is as secure as your current configuration. That is why a Copilot risk assessment examines the tenant rather than the product.