Microsoft · SharePoint

Five things to fix in SharePoint before Copilot

Copilot does not create exposure. It makes existing exposure easy to find, and it answers from whatever it finds.

Updated September 2026

The short version
  • Copilot inherits the permissions of the person asking. Anything overshared becomes searchable in plain language.
  • Duplicate and superseded documents are the most common cause of a confidently wrong answer.
  • Sites created for a project and never closed are where most stale content lives.
  • None of this is a Copilot problem. It is the estate, surfaced by a better search tool.

Copilot does not have its own view of your content. It answers from what the person asking is already permitted to reach, using search that is far better than the one people gave up on. That combination is why rollouts stall: nothing new is exposed, but a great deal becomes findable.

These are the five things worth fixing first, in the order that matters.

1. Oversharing

The common causes are familiar: links shared with “anyone in the organization” because it was quicker, sites where “Everyone except external users” was granted access at creation, permissions inherited from a parent nobody has looked at since, and files sitting in a personal OneDrive that were shared broadly years ago.

None of this was visible when the only way to find a document was to know it existed. Plain-language search changes that. The remediation is not complicated, but it is large, and it needs a decision about what “shared with the company” should actually mean here.

2. Duplicate and superseded content

This is the most common source of a confidently wrong answer. Three copies of an expense policy, two of them obsolete, none of them labelled. The assistant has no way to know which is current, so it answers from whichever reads best.

Fixing it means finding the duplicates, deciding which version is authoritative, and removing or archiving the rest. Where a document must be kept for retention reasons, it needs to be somewhere the assistant does not read.

3. Sites created and never closed

Most estates have hundreds of sites created for a project, a bid, or a team that no longer exists. They hold the oldest content, the loosest permissions and the least ownership.

A site that has had no activity for a year and no identifiable owner is a candidate for archive. Doing this before a rollout removes a large share of both the noise and the risk in one pass.

4. Structure and metadata

Search improves dramatically when content has something to be organized by — document type, business area, status, effective date. Most estates have almost none of this, because it was never enforced at upload.

You do not need a full taxonomy before a rollout. You need enough structure on the content people actually ask about that the assistant can distinguish a current procedure from a draft from a superseded revision.

5. Sensitive content that is not labelled

Personal information, commercially sensitive material, and anything under a contractual confidentiality obligation should be labelled so it can be treated differently — by people and by tooling. Where labelling has never been applied, everything is treated the same, which means the most sensitive material is as easy to surface as the least.

This is where Purview earns its place, and it is worth starting in a reporting mode rather than an enforcing one so you can see what would happen before anything blocks.

The honest summary

A rollout into a tenant with these problems does not fail loudly. It produces answers that are slightly wrong often enough that people stop trusting it, and an exposure conversation nobody planned for. The remediation is ordinary work — it is just work that has to happen first, and it is usually larger than the rollout itself.

Want to know what yours would surface?

A readiness review tells you whether you are running a rollout or a remediation project, and gives you the plan for whichever it is.