Copilot Permissions Audit
A Copilot permissions audit should answer what users can actually discover through AI, not only what a configuration export says. SCS validates tested identities, cited sources, likely access paths, and retest actions.
What this assessment answers
- Which persona tiers can discover sensitive content through Copilot?
- Which SharePoint, Teams, OneDrive, or connector sources appear in answers and citations?
- Are stale groups or inherited permissions likely causes?
- Do organization-wide links or broad groups create AI-discoverable exposure?
- What should be fixed and retested first?
What we test
- Role-based Copilot discovery
- Stale Entra ID / AD groups
- Inherited SharePoint permissions
- Broad Teams membership
- Organization-wide sharing links
- Connector scope
- Sensitivity label mismatches
- Source and citation exposure
Evidence captured
- Copilot output
- Citation and source path evidence
- Identity, role, and persona context
- Optional inventory enrichment
- Optional targeted access-path analysis
- Role Exposure Matrix
- Retest plan
Operator-led, evidence-first assessment.
The audit validates scoped roles and evidence, then uses inventory and access-path data to explain likely root cause where available.