Delivery · scoped from the review
Copilot readiness: the assistant is easy, the permissions underneath it are not.
Buying Copilot licenses is the easy part. The assistant answers with whatever the person asking can open, so years of drifted file permissions become an AI risk the week you switch it on. So we work in that order: settle the permissions, label what matters, pilot one group, then check whether the licenses earn their keep.
Sample client, month 4. Illustrative rollout plan.
In one sentence
Tidy up who can see which files before Copilot starts reading them.
- Advisory review
- Delivery
- Monthly watch
One engagement, in this order. You can start at the stage that fits you.
Delivery · scoped from the review
What this work involves
Buying Copilot licenses is the easy part. The hard part is that the assistant reads every file a person can already reach. That means years of drifted file permissions become an AI exposure the week you switch it on.
So the project runs in that order. Settle permissions and the files that are open too widely. Label the data that cannot travel freely. Choose one group to pilot. Agree how success will be measured before anyone gets a license. The rules come from the AI Use Policy, not from a vendor's slide deck.
Then we measure it: how many people actually use it each week against the licenses you bought, which tasks they hand over, and the cost per active user. If the licenses are not earning their keep, the next licensing review says so.
Who does what
You keep your team, and we take this part.
- You — Name the pilot group and agree what success looks like.
- Third Shift — Fix the exposure, label the data, and measure use.
- Your IT firm — Run the accounts, the computers, and user support.
- Microsoft — Supplies Copilot and bills the licenses.
Who it is for
A fit when
- Firms that have bought or are considering Copilot licenses
- Companies whose file and Teams permissions have never been reviewed
- Leadership that wants AI adoption measured, not assumed
Scope
What it is not
- Not a license sales pitch. The license decision follows the permission work
- Not a content migration. We clean what is there; moving it is a separate project
- Not a productivity promise. The measures are agreed before rollout and reported after it
Where this has run
Profiles using this work.
- Two Microsoft accounts, one renewal, and Copilot waiting.
Regional insurance agency · ~70 staff
Who buys this
Industries that start here.
- Legal, consulting, and agency firms — They asked for an automation, and the environment needed a written rule first.
- Medical, dental, and specialty practices — Patient letters drafted in an unapproved AI tool, and no rule to point to when someone asks.
- Insurance agencies and brokerages — Two systems of record, shared carrier logins, and a renewal calendar no one watches.
The order
Part of the sequence, not the whole of it.
This is the entry point for most engagements. The first conversation covers the setup and this work is scoped from what it finds.
This listing is part of the Microsoft 365 practice, which starts with a read of your Microsoft account and licenses rather than a purchase.
Questions
Questions about copilot readiness
Why does Copilot need a readiness project?
Copilot needs a readiness project because it answers with whatever the person asking can already open. If file permissions have drifted for years, through inherited folder access, stale sharing links, or three copies of the same document, the assistant surfaces all of it within a week of rollout. Readiness means fixing that exposure before the assistant arrives.
What are files that are open too widely, and why does it matter?
Oversharing means files that more people can open than anyone intended, usually because a folder above them was shared years ago. No one notices in normal use. The moment an AI assistant starts summarizing everything a person can reach, everyone notices. Closing it is the first step of Copilot readiness.
Does Copilot put our data into the public model?
No, Copilot does not put your data into the public model. It runs inside your Microsoft cloud account, against your own content, under Microsoft's data protection commitments for the service. The real exposure is not the model. It is the file permissions you already have, which is exactly what Copilot readiness measures and fixes.
How do you measure whether Copilot is working?
We agree the measures before Copilot rolls out. How many people use it each week against the licenses you bought. Which tasks they hand over. What the pilot group reports saving. And the cost per active user. The Microsoft 365 monthly watch reports the same numbers, so the license count gets reviewed rather than renewed on faith.
Start here
Start with the review.
The first conversation covers your environment, and this work is scoped from what it finds.