Copilot: what it can answer, and what it will expose
Copilot creates no new access. It makes existing access searchable in plain language, which is a bigger change than it sounds.
Updated September 2026
- Copilot answers within the permissions of the person asking. It cannot show them anything they could not already open.
- What changes is findability. Content that was theoretically reachable becomes practically reachable.
- It will answer from an out-of-date document as confidently as from a current one.
- The preparation is permissions, duplication and labelling — and it is usually larger than the rollout.
Two things are true at once, and holding both is the whole of a sensible Copilot decision. It cannot show anyone anything they were not already permitted to see. And it will surface a great deal that nobody knew was reachable.
What it can do well
Answer from documents the user can open. Policies, procedures, project material, past correspondence — summarized, with references back to the source.
Summarize and draft. Meetings, long threads, documents, first drafts of routine writing. This is where most day-to-day value sits, and it needs almost no preparation.
Find things by description. The significant shift. Previously, finding a document required knowing roughly what it was called or where it lived. Now a description is enough.
Work across the tenant. Mail, chat, documents and meetings together, which is what makes it more useful than searching each in turn.
What it cannot do
See what the user cannot. Permissions still apply, exactly as they did.
Know what is current. If three versions of a policy exist and none is labelled, it will answer from whichever looks most relevant. This is the most common source of a wrong answer and it is a content problem, not a product one.
Read what it has not been given. Content in systems outside the tenant, in file shares, or in formats it cannot process is invisible to it. That is frequently where the authoritative version lives.
Take actions on its own. Answering questions and doing work are different capabilities, and the second is a separate build.
What a rollout surfaces
Oversharing. Links shared with everyone in the organization for convenience, sites granted broad access at creation, permissions inherited from a parent nobody has reviewed. All of it previously invisible because nothing made it findable.
Content people forgot. Old drafts, superseded contracts, salary discussions in a document library, material from acquisitions and departures.
Personal storage doing organizational work. The current version of an important document living in one person’s OneDrive, shared broadly years ago.
None of this is created by Copilot. It is revealed, and the difference matters when explaining it to an executive team.
What the preparation actually involves
Four things, in order: close the oversharing, remove or archive duplicate and superseded content, decide which sites are in scope at all, and label the material that needs different treatment.
In most tenants this is larger than the rollout itself and it cannot be compressed by adding people. Starting it before the licences are bought is the difference between a launch and a pause.
The honest position
Copilot is worth having and the drafting and summarizing value arrives immediately. The grounded-answer value — the part that justifies the premium — depends entirely on the state of your content. A rollout into an unprepared tenant does not fail loudly; it produces answers that are wrong often enough that people stop trusting it, alongside an exposure conversation nobody scheduled.
Rollout or remediation?
The readiness review gives you a straight answer on which one you are running, and the plan for it.
