An organizational assistant whose access follows existing Microsoft 365 permissions, making data sharing hygiene especially relevant.
The central question for an organizational Copilot is often what information a user is already allowed to see. Making scattered information easy to retrieve can reveal overly broad sharing. Review the information environment and connected agents as part of adopting the assistant.
Microsoft says organizational Copilot surfaces data the user has permission to view. The documentation calls attention to the underlying Microsoft 365 permission model, including external collaboration.
Source: Microsoft · Data, privacy and security for Microsoft CopilotMicrosoft states that prompts, responses and Microsoft Graph data are not used to train foundation models in this organizational service. It also identifies additional considerations for agents and web queries.
Source: Microsoft · Data, privacy and security for Microsoft CopilotOur recommendation: audit broadly shared folders before rollout, and test whether an answer reveals information irrelevant to the user’s task. A document being technically accessible does not mean its sharing arrangement was thoughtfully designed.
A team member asks for onboarding notes and retrieves an old salary spreadsheet stored in a broadly shared folder. The useful fix is to correct the folder’s access and retention, then re-test the workflow; a better instruction to the assistant is only one possible layer.
These organizational commitments should not be generalized to consumer Copilot, GitHub Copilot or arbitrary third-party agents. This is not a tenant security audit.
How to read an AI safety evaluationThe sources behind this page, with a reason to open each one. Practical examples and recommendations are our editorial interpretation.
Covers organizational Microsoft 365 data and permissions. These commitments should not be generalized to every Copilot product.
Practical guidance on tool permissions, memory isolation, oversight and agent failure handling.
Sources reviewed 13 September 2026. Product documentation can change. How we use evidence