Free live webinar · Oct 8 — Get your Microsoft 365 AI-ready before Copilot reads the wrong file. Reserve a seat →
Polaris Governance

Field note

Copilot can reach everything your users can. That's the whole problem.

Turning on Microsoft Copilot doesn't create new access — it makes existing access answerable. Why your oversharing surface is your AI-exposure surface, measured on a real tenant, and what to check before you flip it on.

Microsoft Copilot does not grant itself any new permissions. It answers prompts using exactly what the asking user can already reach — every SharePoint site, every file, every shared inbox they have access to, whether or not they’ve ever opened it. That’s the design, and it’s the right design. It’s also the entire risk.

Because most tenants have spent a decade accumulating access nobody remembers granting. A site shared with “Everyone except external users” in 2019. A folder a departed employee opened to the whole org. A “temporary” broad grant that outlived the project by four years. None of that mattered much when finding a file required knowing it existed and navigating to it. Copilot removes that friction entirely: now anything reachable is one plain-English question away from being surfaced, summarized, and quoted back with a citation.

Your oversharing surface and your AI-exposure surface are the same surface. The day you enable Copilot, they become the same problem.

The number that matters isn’t the file count

When we scanned a real tenant, the headline numbers were 235 sites and roughly 922,000 files. Impressive, and almost useless for a readiness decision. File count tells you how much content exists; it tells you nothing about who can reach it.

The number that matters is reach — the count of distinct principals who can effectively access a given site, resolved through group nesting and sharing links, not just the direct grants on the site itself. Reach is what Copilot inherits. A 40-file site reachable by the entire organization is a far bigger Copilot problem than a 100,000-file site locked to a team of six. Sort your estate by effective reach and the real exposure concentrates fast — usually a small number of high-reach sites carry most of the risk.

The sharp edge is a claim, not a user

The highest-reach grants in SharePoint usually aren’t users or even Azure AD groups. They’re claim principals — “Everyone” and “Everyone except external users” — special tokens SharePoint resolves at access time. They don’t appear in Azure AD, and they fail the user-resolution path that most inventory tools rely on, so those tools quietly under-count the single most dangerous grant in the tenant. If your readiness review resolves permissions to named users and stops there, the “Everyone” grants — the ones that make a site answerable by any prompt from any employee — are exactly what it misses.

Microsoft’s own Copilot oversharing guidance and SharePoint Advanced Management exist precisely because this is the number-one readiness blocker. Restricted Content Discovery, site access reviews, and Restricted SharePoint Search are all Microsoft telling you the same thing: reduce what Copilot can reach before you turn it on.

The list a security team actually acts on

“Overshared” alone is too big to action — plenty of broadly-shared content is harmless. The list worth a CISO’s attention is the intersection: sites that are overshared and carry sensitive-labeled content and feed an AI agent. Each condition is independent; stacked, the risk is multiplicative, not additive. One site that is reachable by Everyone, holds confidential material, and grounds a Copilot Studio agent is worth more of your attention than a hundred single-condition findings. That short, ranked, worst-first list is the difference between a report you file and a remediation you run.

And be honest about coverage while you build it. A scan that hit throttling on some sites and covered 520 of 650 should say “520 of 650,” not present a confident, complete-looking zero for the 130 it never reached. We’ve written about the confident zero elsewhere — it’s the fastest way to turn a governance tool into a liability.

What to check before you flip it on

  • Measure effective reach, not permissions on paper. Resolve group nesting and sharing links; the on-paper grant and the effective reach are rarely the same number.
  • Detect claim principals explicitly. If “Everyone” and “Everyone except external users” aren’t first-class in your inventory, your biggest exposure is invisible.
  • Rank by the intersection. Overshared × sensitive × agent-reachable, worst-first — not an alphabetical list of everything.
  • Fix reversibly. Removing a grant should be previewable and undoable. A remediation you’re afraid to run because you can’t take it back is a report, not a control.
  • Report coverage, not just findings. Say what you couldn’t see as loudly as what you found.

Enabling Copilot is not the risk. Enabling it without knowing what it can reach is. The good news: reach is measurable, the worst offenders are few, and the fixes are reversible — if you look before you flip the switch.


Polaris Governance Hub runs inside your own Microsoft 365 tenant and scores exactly this — effective reach per site, the “Everyone” claims most tools miss, the overshared-and-sensitive-and-agent-reachable intersection, and a reversible one-click fix. We’re taking a small number of design partners. See what Copilot can reach in your estate.

More field notes · Full archive · RSS · How the product works