Copilot Permissions Audit

A Copilot permissions audit should answer what users can actually discover through AI, not only what a configuration export says. SCS validates tested identities, cited sources, likely access paths, and retest actions.

What this assessment answers

  • Which persona tiers can discover sensitive content through Copilot?
  • Which SharePoint, Teams, OneDrive, or connector sources appear in answers and citations?
  • Are stale groups or inherited permissions likely causes?
  • Do organization-wide links or broad groups create AI-discoverable exposure?
  • What should be fixed and retested first?

What we test

  • Role-based Copilot discovery
  • Stale Entra ID / AD groups
  • Inherited SharePoint permissions
  • Broad Teams membership
  • Organization-wide sharing links
  • Connector scope
  • Sensitivity label mismatches
  • Source and citation exposure

Evidence captured

  • Copilot output
  • Citation and source path evidence
  • Identity, role, and persona context
  • Optional inventory enrichment
  • Optional targeted access-path analysis
  • Role Exposure Matrix
  • Retest plan

Operator-led, evidence-first assessment.

The audit validates scoped roles and evidence, then uses inventory and access-path data to explain likely root cause where available.