AI guardrails, set before Copilot reaches your data
A focused AI governance assessment for Microsoft 365. We show you what Copilot and your AI tools can reach today, then hand you a phased plan to lock it down.
Talk to an Expert →Copilot surfaces whatever a user can already reach
Microsoft 365 Copilot draws from the same permissions your people already have. It doesn't judge whether someone should open a file. It pulls from what they can open today. Years of broad sharing links, guest accounts nobody revoked, and sites that outlived their owners all become searchable the moment you turn on a seat.
Turning on Copilot makes that exposure discoverable in plain English, by anyone, in seconds.
Not ready for a full assessment? Start with a free, 45-minute AI Governance Quick-Check.
What the AI governance assessment examines
We run the assessment against evidence, not interviews. Every finding traces back to a report you can open yourself.
- CISA ScubaGear baseline across your Microsoft 365 workloads
- SharePoint Advanced Management permission and oversharing reports
- Microsoft's Content Management Assessment, covering inactive sites, ownerless sites, broken permission inheritance, organization-wide sharing, and unrestricted sharing links
- Microsoft Purview configuration, including sensitivity labels, DLP, retention, information barriers, and Data Security Posture Management for AI
- Inventories of sites, mailboxes, guests, and licenses
- Live tenant verification, so the report reflects your configuration on the day we hand it over
Background on the control-by-control work is in our guide to creating AI guardrails inside Microsoft Copilot.
What you get
For leadership
- Executive readout: a readiness verdict your CIO can take to the board, with a straight recommendation to hold at a pilot or expand.
- Data exposure posture: Copilot's reach today, broken out by area and rated.
For your IT team
- Findings register: every finding with its evidence, source, date verified, scope, fix, and phase. Severity runs Critical, High, Medium, and Positive.
- Phased remediation plan: task-level detail with effort sized Low, Medium, or High, and license-dependent work kept in its own backlog.
For policy and security
- Policy control mapping: your AI usage policy tied line by line to the control that enforces it.
- Third-party fit: the security tools you already own, mapped against Microsoft's controls.
- AI acceptable use policy and approved tools register: designed with your team. If a tool isn't on the register, it isn't approved.
Our take: fix permissions before you buy more seats
The most common mistake we see is rolling Copilot out over access that has drifted for years, then trying to clean up while people are already asking it questions. The second is mandating AI use without teaching people what's safe to put into it. Both cost less to prevent than to clean up.
We also record what you already have right. Positive findings stay in the register so nobody rips out a good control later. And if a re-test contradicts something we wrote, we withdraw the finding and record why. That keeps the register current enough for your team to trust it.
How it runs
- Scope call. Thirty minutes to confirm your tenant, your licenses, and what you're trying to turn on.
- Evidence collection. We run the reports and verify configuration live. The window depends on tenant size, and we tell you up front.
- Findings and readout. You get the register, the exposure posture, and the executive verdict.
- Remediation plan. Phased and sequenced so the highest-exposure work lands first.
- Your decision. Run the plan in-house or have us do it. Both are real options, and we'll tell you which one fits.
Once guardrails are in place, the rollout itself is covered by our Microsoft Copilot consulting, and agent governance by Microsoft Agent 365.
Who runs it
- Senior Microsoft engineers, not a junior analyst working from a template
- Azure Expert MSP, independently audited by Microsoft and held by fewer than 1% of partners
- Top 1% Microsoft Solutions Partner, with a Security designation
Comparing partners? Our 8 risks to review before choosing a Microsoft Copilot partner gives you the questions to ask us and everyone else.
Frequently asked questions about AI guardrails
What is an AI guardrails assessment?
It's a focused review of what Microsoft 365 Copilot and other AI tools can reach in your tenant, and which controls limit that reach. It covers permissions, sharing, sensitivity labels, DLP, retention, and audit logging, then delivers a findings register and a phased plan to close the gaps.
Is an AI guardrails assessment the same as an AI governance assessment?
Yes, for our purposes. People use AI governance assessment, AI readiness assessment, and AI guardrails assessment for the same work: finding out what AI can reach and setting the controls that limit it. We call ours the AI Guardrails Assessment because guardrails are what you walk away with.
Does Microsoft Copilot expose data users shouldn't see?
Copilot never grants new access. It surfaces content a user can already open. The risk is that most organizations can't say what that covers, because sharing links, guest access, and permission inheritance have drifted for years. Copilot makes that reach searchable in plain language.
Should we fix oversharing before or after we turn Copilot on?
Before. Fixing permissions after go-live means cleaning up while people are already querying the data. Doing the permission review, labeling, and DLP work ahead of the first seat is the difference between a rollout and an incident.
How long does an AI guardrails assessment take?
Evidence collection depends on tenant size. Microsoft notes that SharePoint Advanced Management reports alone can take between 2 and 72 hours to run. We give you the window at the scope call and hold to it.
What's the difference between this and the free AI Governance Quick-Check?
The Quick-Check is a free 45-minute working session that shows where public AI tools, Copilot, and shadow IT put data at risk. The AI Guardrails Assessment is the full evidence-based review, with a findings register and a remediation plan your team can execute.
Ready to see what Copilot can reach?
No slide decks. Senior Microsoft engineers, real findings, and a plan you can act on.
Talk to an Expert →