
AI Governance
40-item checklist to find and fix Copilot data oversharing risks before they cause compliance incidents. SharePoint permission cleanup, sensitivity label coverage, restricted-access patterns, and the audit-script library EPC Group runs pre-rollout.

Updated: April 25, 2026 · By: Errin O'Connor, Founder & Chief AI Architect, EPC Group · Reading time: 19 min
Microsoft Copilot grounds on everything the user can access. If your SharePoint permissions are loose, Copilot becomes a permission-amplification machine — surfacing content the user shouldn't have seen. EPC Group's first task on every Copilot rollout is the Data Oversharing Audit. This is our 40-item checklist.
Without Copilot, an employee wanting to find HR records would need to: (1) know the site exists, (2) navigate to it, (3) search, (4) skim. Copilot collapses all four steps. Ask "summarize our most recent compensation discussions" and Copilot returns oversharing-exposed HR documents in 2 seconds.
EPC Group has audited 80+ Fortune 500 tenants. 100% had at least one oversharing risk; the median had 47 distinct issues. Worst tenant we audited had 312 issues.
EPC Group's audit script library:
Output: 40-item finding spreadsheet ranked by risk score. Average remediation: 4-12 weeks.
EPC Group's typical findings remediation:
For a Fortune 500 tenant: 2-4 weeks for the audit + 4-12 weeks for remediation. Total 6-16 weeks.
For pilot users (50) yes. For broader rollout, wait until top-50 oversharing risks are remediated.
A Microsoft Copilot setting that excludes specific SharePoint sites from Copilot grounding. Use for highly-sensitive content where you want users to access via direct navigation only, not Copilot.
"Everyone except external users" with Edit permission on documents containing PII or financial data. EPC Group has seen this in HR sites, finance sites, M&A sites, and litigation hold sites.
Yes — Syntex auto-classification is the most efficient way to label tens of thousands of documents. Rule-based labeling alone cannot keep up with content velocity.
Yes — Copilot inherits the most restrictive label from grounded content and applies it to outputs. Configure tenant settings to enable this.
Same risk in Teams as SharePoint, since Teams uses SharePoint under the hood. Audit covers both.
Default-deny external sharing on sensitive sites. Use Microsoft Entra B2B with explicit guest accounts for required external collaboration. Avoid "Anyone with the link."
OneDrive default sharing is per-user; can be tightened tenant-wide. EPC Group's policy: external sharing from OneDrive blocked tenant-wide; users use Teams sites for external collaboration.
Quarterly for sensitive tenants. Annually for stable tenants.
Need a Copilot data oversharing audit before rollout? EPC Group's 4-week sprint includes the 40-item checklist + remediation roadmap. Schedule an audit or see our AI Governance services.
Founder & Chief AI Architect
29 years Microsoft consulting experience. 4-time Microsoft Press bestselling author.
View Full ProfileDay-by-day Microsoft 365 Copilot enterprise rollout. Pre-launch readiness, license-staging waves, governance guardrails, change-management cadence, and the 12 KPIs that prove ROI by Day 30.
AI GovernanceConcrete Copilot ROI math from 3 anonymized Fortune 500 deployments: healthcare ($4.2M Year 1 net savings), financial services ($6.8M), manufacturing ($3.1M). Plus our 12-workflow ROI calculator template.
AI GovernanceHow Fortune 500 firms stand up an AI Center of Excellence in 90 days. Charter, team structure, governance cadence, tooling stack, ROI metrics, and the 5 patterns that distinguish high-performing CoEs from administrative ones.
Our team of experts can help you implement enterprise-grade ai governance solutions tailored to your organization's needs.