AI governance

Copilot governance in Microsoft 365: 10 best practices for IT teams

Ten practices that keep Microsoft Copilot and its agents under control once they are live: owners, oversharing, labels, agents, audit and training, with the Microsoft tools that help at each step.

6 min read Neptune Group

Navy illustration: a Microsoft Copilot window where the prompt "Show me the 2026 salary review" returns a file shared with everyone, flagged in coral, next to a glowing shield.

Copilot governance is the set of owners, rules and checks that decide what Microsoft Copilot (formerly Microsoft 365 Copilot) and its agents can reach, who is accountable for them and how you prove it. Copilot only shows people content they can already open, so most of the work is about permissions, labels and agents, not about Copilot itself.

Switching Copilot on is the easy part. The harder part starts the week after, when people find files they had forgotten existed, makers publish their first agents and someone in legal asks who approved all this. The ten practices below are the ones that make the difference once Copilot is live. If you are still preparing the roll-out, work through our Copilot readiness checklist first, and see our Copilot readiness approach.

1. Who owns Copilot governance?

Governance fails quietly when everyone assumes someone else is in charge. Write down, on one page:

  • Who can use Copilot, and who decides when a new group gets a licence
  • Which data is in scope, and which sites stay out for now
  • Who may build agents, and who approves sharing them widely
  • Who reads the reports, and how often

Put a name or a team next to each line, across IT, security, compliance and the business. A one-page scope that people actually read beats a long policy nobody opens.

2. Fix oversharing before people find it through Copilot

Copilot respects existing permissions. The catch is that it makes overshared content much easier to find. A finance spreadsheet shared with "Everyone except external users" three years ago is now one prompt away.

SharePoint Advanced Management is available once at least one user has a Microsoft Copilot licence. Its data access governance reports show where sites may be overshared, and can start a site access review with the site owner. Start with the sites that combine broad access and sensitive content.

While permissions are being fixed, Restricted Content Discovery keeps a site out of Copilot and organisation-wide search without changing who has access. Microsoft describes it as a temporary control, so plan the clean-up, not just the switch.

3. Keep access lean, and review it on a schedule

Least privilege is not a one-off project. People change roles, teams are created for a project and never closed, guests stay long after the work ends. Each of these quietly widens what Copilot can draw on.

  • Review access to sensitive sites on a schedule, with the site owner rather than IT alone
  • Archive or delete inactive teams and sites with a clear lifecycle rule
  • Watch for permission drift: a site that was private last month and is open today

4. Label sensitive content so protection follows the file

Sensitivity labels in Microsoft Purview travel with the document. When a label encrypts content, Copilot respects each user's usage rights, so someone who cannot open a file will not get it summarised either.

The usual gap is coverage: the labels exist, but most files have none. Pick a short list of labels people understand, set a default label on the libraries that matter, and track how much content within Copilot's reach is still unlabelled. Retention and data loss prevention policies in Purview complete the picture.

5. Treat agents as part of Copilot governance

Copilot is no longer only a chat assistant. People with a Copilot licence can create SharePoint agents from sites and files, and makers can build their own agents in Copilot Studio. An agent can exist without a named owner, an end date or a review, and that is where problems start.

Microsoft gives you the building blocks:

  • The Microsoft 365 admin center has an agent registry that lists the agents available in your organisation.
  • In the Power Platform admin center, data policies control which connectors and knowledge sources agents may use, and Managed Environments limit how widely agents are shared.
  • Microsoft Entra Agent ID gives each agent its own identity, so its access can be governed like any other account.

Our guide to Microsoft Agent 365 looks at the agent registry in more detail.

Use them to set a few simple rules. Every agent has an owner, a purpose and a review date. Agents grounded on public websites need approval. Agents shared with the whole organisation get a second look. Our AI governance page explains how we put these rules in place.

6. Give people clear prompt and data rules

Most leaks through an AI assistant are accidents. Someone pastes a customer list into a prompt, or forwards a Copilot summary without reading it first. Three short rules help more than a long policy:

  • Never paste passwords, health data or customer lists into a prompt
  • Read any Copilot draft before it goes to a customer or a regulator
  • If Copilot shows you something you should not see, report the file, not just the answer

The last one matters most. Each report points to an oversharing problem you can fix at the source.

7. Turn on audit, and actually read it

Copilot interactions are recorded in the Microsoft Purview audit log, including which files were used. That record matters the day someone asks what Copilot returned for a given user, or which sensitive files ended up in answers.

Microsoft Purview Data Security Posture Management (DSPM) adds a view of how AI apps and agents use sensitive data. Decide who reads these reports, how often, and what triggers an action. A report nobody opens is not a control.

8. Bring security and compliance in from the start

Copilot governance is not only an IT job. Security teams understand access risk, compliance teams know which records you must keep, and your data protection officer knows where GDPR applies. Processing through AI assistants belongs in your GDPR record of processing activities, and a data protection impact assessment may be needed where the risk is high.

Agree early on who signs off a new agent, a new data source or a wider roll-out. It is far easier than explaining after the fact.

9. Train people on what Copilot can and cannot do

Under the EU AI Act, organisations using AI are expected to take measures that support AI literacy among their staff. Good training does that and cuts mistakes at the same time. Cover four points: how Copilot finds content, why it only sees what the user can open, why its answers need checking, and how to report a problem.

Keep it short and repeat it. A brief session at go-live and a refresher when new features arrive work better than one long course.

10. Automate the checks you repeat

Manual reviews work for ten sites. They do not work for thousands of sites, millions of files and new agents every week. Automate the checks you run again and again: overshared sites, unlabelled content within Copilot's reach, agents without an owner, guests who never sign in.

The aim is not to take people out of the loop. A good rule finds the issue, asks the owner to confirm or fix it, and keeps a record of the decision. IT stays in control without doing every review itself.

Which Microsoft controls help with Copilot governance?

Microsoft provides the controls. A governance process decides how, when and by whom they are used.

Native Microsoft controls for Copilot governance

ControlWhat it doesWhat you still need to decide
SharePoint Advanced Management Data access governance reports show where sites may be overshared and can start a site access review. Available once one user has a Copilot licence. Which sites to review first, and how often.
Restricted Content Discovery Keeps a site out of Copilot and organisation-wide search without changing access. Microsoft presents it as temporary. When each restricted site is cleaned up and released.
Microsoft Purview Sensitivity labels, retention and data loss prevention, the audit log of Copilot interactions, and DSPM for AI apps and agents. Your label scheme, default labels and who reads the reports.
Agent registry and Power Platform admin center List agents, control connectors and knowledge sources with data policies, and limit sharing in Managed Environments. Who owns each agent, and when it is reviewed or retired.
Microsoft Entra ID Gives users and agents an identity, with Microsoft Entra Agent ID for agents. Access reviews, and what happens when an owner leaves.

Where does Neptune fit?

Neptune is an integrator. We select the governance tooling that fits your tenant, implement it with your team, train your admins and site owners, and support you once it runs. The goal is a Copilot roll-out your security and compliance teams are comfortable with, and rules that keep working after the project ends. See how we approach Microsoft 365 governance, or read our Microsoft 365 governance best practices for the rest of the tenant.

Governing Copilot and agents across the tenant? See our approach to Microsoft AI governance.

FAQ

Questions on this topic

What is Copilot governance?

It is the set of owners, rules and checks that control what Microsoft Copilot and its agents can reach, and how their use is recorded. Because Copilot only shows content a user can already open, it mostly comes down to permissions, sensitivity labels, agent rules and audit.

Does Copilot ignore SharePoint permissions?

No. Copilot only shows people content they can already open. The risk is that overshared content becomes much easier to find, which is why fixing oversharing comes first.

Which Microsoft tools help with Copilot governance?

SharePoint Advanced Management (data access governance reports and Restricted Content Discovery), Microsoft Purview (sensitivity labels, audit and Data Security Posture Management), the agent registry in the Microsoft 365 admin center, the Power Platform admin center and Microsoft Entra ID. A governance process decides how and when each one is used.

How do we govern Copilot Studio and SharePoint agents?

Give every agent an owner, a purpose and a review date. Use data policies and Managed Environments in the Power Platform admin center to control knowledge sources and sharing, and review first the agents that have no owner or are shared with the whole organisation.

Is Restricted Content Discovery enough on its own?

No. It keeps a site out of Copilot and organisation-wide search without changing access, and Microsoft describes it as a temporary control. Use it while you fix the permissions, then lift it.

Does the EU AI Act require Copilot governance?

The EU AI Act expects organisations using AI to take measures that support AI literacy among their staff. It does not require a formal AI inventory for tools like Copilot, but keeping one is the practical way to know which tools are used and who needs training. GDPR duties, such as the record of processing activities, apply as well.

Have a question about your own tenant?

Tell us what you are working on and we will tell you where we would start.