Copilot readiness | Perth + remote
Microsoft 365 Copilot readiness assessment for Australian SMBs
A fixed scope assessment for Australian SMBs that need to understand Microsoft 365 permissions and data exposure before enabling Copilot. We give an advisory recommendation on whether to proceed, with remediation priorities.
Describe the problem in a sentence or two. Please do not send credentials or sensitive records.
- Best fit
- One Microsoft 365 tenant before Copilot rollout
- Main deliverable
- A written report, recommendation and remediation order
- Client input
- Limited read only access and a Microsoft 365 owner
- Commercial model
- Fixed scope assessment quoted per tenant
- Scope
- Assess
- Implement
- Handover
The accountable team stays responsible for the specialist scope from assessment through handover. Boundaries, evidence and external dependencies are agreed before work starts.
Deliverables
What you get from the assessment
The written report records each area assessed, rates findings by severity and provides an advisory recommendation on whether to proceed. A “not yet” recommendation includes the conditions that should change before rollout.
The prioritised remediation list can be handed to an internal team or managed service provider. Findings needing ongoing policy work are separated for AI data loss prevention; broader security needs can continue into AI security.
Scope
What we assess
Existing access
- We check who can access what across Microsoft 365, including role assignments, group memberships and privileged accounts.
SharePoint and Teams oversharing
We find site, library and channel permissions that go further than the business needs.OneDrive sharing links
We flag links shared with the whole organisation or with anyone, since these can expose content too broadly.
Information protection
Sensitivity labels
We check whether sensitivity labels, the tags that classify how a file should be handled, are defined, published and used consistently across files, email and Teams.Data protection readiness
We review Purview, Microsoft's data protection controls, for gaps around financial, personal, health and other sensitive information.Label and retention coverage
We check for content with no label, or that is kept longer or shared wider than intended.
Rollout conditions
Licensing fit
We confirm which licences are assigned and which security, compliance and governance features they make available.Pilot group design
We help you choose a pilot group with a controlled level of data access, so early issues surface safely.Admin and governance controls
We review Copilot admin settings, plugin permissions and the ongoing rules that govern content.
Assessment process
From limited access to a rollout decision
Scope
Agree scope and access
We confirm the tenant, users, administrative roles, evidence handling and assessment boundaries before access is granted.Review
Review the tenant
We review permissions, sharing, labels, data protection readiness, licensing and pilot conditions using read only access.Report
Report findings
We provide a written report with severity, evidence and an advisory recommendation on whether to proceed.Plan
Plan remediation and pilot
We order the remediation work and document the conditions for a controlled pilot. Implementation is scoped separately unless included in the proposal.
How access works What Copilot changes about your data
Copilot uses content a user can already access. We assess SharePoint and Teams permission sprawl, sharing links, sensitivity labels, Purview data protection readiness, current licensing and pilot group design.
Microsoft 365 Copilot does not grant a user new file permissions. It makes files that user can already open easier to retrieve and summarise. Microsoft's Copilot security guidance confirms that Copilot operates within existing permissions and access controls.
That means old SharePoint memberships, links shared across the whole organisation and overly broad Teams access all deserve review before rollout. Microsoft also publishes current minimum deployment requirements. This assessment focuses on the tenant. Once controls are in order, Copilot training teaches staff how to use the product, while an AI readiness audit addresses broader organisational opportunities and governance.
Commercial boundary
Assessment first, implementation only when agreed
Tenant assessment and report
Remediation and rollout
Practical details
Questions about Copilot Readiness Assessment
It is a fixed scope review of your Microsoft 365 tenant, carried out before you enable Copilot for your organisation. We examine permission sprawl across SharePoint, Teams and OneDrive, check whether sensitivity labels are in place and Purview's data protection policies are configured, confirm your licensing covers the features you need, and design a pilot group plan. The output is a written report with an advisory recommendation on whether to proceed, and a prioritised remediation list.
Start here