Skip to content
Sunrise Digital Labs

Assessment

Copilot Readiness & Governance

Readiness is a question about your tenant, not about the product. Copilot answers using whatever a person is already allowed to open. The real question is therefore what each person can currently reach, and almost no organization has a precise answer to that.

Finding out after a rollout is the expensive version, because by then the answer arrives as a search result in front of somebody.

Why readiness is more than licensing

Nothing about a rollout grants anyone new access. The permissions were already there — what changes is that finding things stops depending on knowing where to look.

In most tenants the effective audience of a document is wider than the person who saved it believed. That is not a failure of anyone's administration; it is what happens to a permission model over a decade of reorganizations, departures and projects that needed access quickly.

The work is establishing what that model actually grants today, before a change makes it legible to everyone at once.

  • Licenses have been bought, or are being evaluated, and somebody has to decide when to switch them on
  • There is an executive mandate to roll it out and a date attached to it
  • A pilot started and stalled, and the reason is not obvious from inside it
  • The security team has raised oversharing before anyone has measured it
  • A consolidation left permissions nobody has reconciled since

What is evaluated

Prerequisites
Licensing position, tenant configuration and the service dependencies that have to be in place before a pilot can be switched on at all.
Identity and access
Who exists, what they are a member of, and which groups resolve to access nobody has reviewed since they were created.
SharePoint and OneDrive permissions
The permission model as it actually stands: inherited access, broken inheritance, and the sites where the effective audience is wider than the intended one.
Sharing and external exposure
Organization-wide links, guest access, and documents shared once for a reason that ended years ago.
Data protection posture
Sensitivity labeling, retention and Purview configuration where it is licensed — and what is unlabeled, which is usually most of it.
Pilot cohort readiness
Whether a specific group can be given access without that group reaching material the rest of the organization cannot.

What you receive

Exposure findings
Where the effective audience of content is wider than anyone intended, with the specific sites, groups and links that make it so.
Remediation priorities
What to change before a pilot, what can follow it, and what each change will be visible as to the people using the tenant.
Pilot cohort definition
A specific group that can be switched on with a known exposure position, rather than a department chosen because it volunteered.
Governance position
Labeling, retention and sharing defaults as they stand, and which of them a rollout depends on being different.
Deployment sequence
The order the remaining work has to happen in for access to widen deliberately rather than by default.

There is no score and no readiness rating. A number would compress the specifics into something nobody can act on. A verdict would be a judgment, where what is useful is a list of what to change and in what order.

What usually follows

Most of the remediation is permission and sharing work inside SharePoint, OneDrive and the identity model. It is the kind of thing an in-house team or an existing provider can carry out once it is written down and ordered.

Where it is wanted from Sunrise, it is scoped after the findings exist, because what it involves is not knowable before them.

How this supports the decision

The outcome is one of two things, and both are useful. Either a defined cohort that can be switched on now with a known exposure position, or a specific list of what has to change first and why.

Neither is a recommendation about whether to adopt Copilot. That decision belongs to the organization, and it is not a technical one.

What this is not

Not training or adoption
No usage guidance, no prompt coaching, no change program. What people do with it once it is on is not this engagement.
Not an AI strategy
This is about a Microsoft 365 tenant and what is reachable inside it. Nothing here evaluates whether Copilot is worth having.
Not licensing
The assessment is not a licensing transaction, and buying one buys no licenses. Whether they are already held or still being evaluated is a fact about the tenant.
Not a certification
No compliance outcome, no attestation, and nothing here is approved or certified by Microsoft.
Not elimination of exposure
Permissions can be reduced, understood and governed. A tenant with people in it always has access in it.

All Microsoft 365 work

Questions people ask before committing

Do we need to buy Copilot licenses before this?

No. The assessment reads the tenant, and the tenant is the same whether the licenses are held, trialed or still being priced.

Running it before the purchase is usually the better order, because what it finds changes when a sensible switch-on date is.

What if we have already turned it on?

Then it answers a question that has become urgent rather than theoretical. The work is unchanged — it still measures what each person can reach — but the findings arrive against a tenant where that reach is already being exercised.

This is the most common way the work starts. A pilot goes out, one search returns something it should not, and the question stops being about readiness and starts being about exposure.

Will this stop people using Copilot while it runs?

No. It reads the permission model and changes nothing, so anyone already using Copilot carries on as before.

Does this fix the oversharing, or only find it?

It finds it, names the specific sites, groups and links responsible, and puts them in the order they should be dealt with. The changing is separate work.

Most of it is permission and sharing work an in-house team or an existing provider can carry out from the findings. Where it is wanted from Sunrise it is scoped after the findings exist. What it involves is not knowable before them, which is why it is not quoted alongside the assessment.

What does Purview have to do with it?

Sensitivity labeling and retention decide what protection travels with a document once it is easy to find. Where Purview is licensed, the assessment reads how it is configured and what is unlabeled.

Where it is not licensed, that is recorded as the position rather than treated as a gap — labeling is one way to govern reach, not the only one.

Know what it can reach before you turn it on.

The permissions are already what they are. The only question is whether you find out on your own schedule or on somebody else's.