The Parts of a Programme
That Actually Decide It
Longer-form pieces on the recurring failure modes of a Copilot programme. Each one comes from remediation work rather than from a vendor deck, which is why most of them are about permissions, ownership, and measurement rather than about models.
The Oversharing Report Is Not the Remediation Plan
Running the report is a morning's work. Acting on it is a quarter's, and the gap between those two numbers is where most Copilot pilots quietly lose their schedule.
The sequence is familiar. Someone runs the SharePoint Advanced Management oversharing report, or the data access governance report, and returns with a figure — a few thousand sites with organisation-wide links, a few hundred with "Everyone except external users" grants. The figure is circulated. It is agreed that this is significant. Then the programme proceeds to the licensing conversation, because the report was the deliverable and the report is done.
It was not the deliverable. A count of exposed sites is a measurement, and a measurement does not reduce exposure. What reduces exposure is a decision, taken per site, about whether the grant was intentional — and that decision needs an owner who knows what the content is. Most tenants cannot produce that owner on demand. The site was created four years ago by someone who has since left, the listed owner is a distribution group, and the content is a mixture of genuinely open material and three folders that should never have been broadly readable.
This is why the remediation estimate is nearly always wrong by a wide margin. The technical work — changing a permission, expiring a link, applying a label — takes seconds. The work that consumes the quarter is establishing who is entitled to decide, and getting them to decide. That is a change-management problem wearing a security problem's clothing, and it does not compress just because a renewal date is approaching.
Two things make the difference in practice. The first is ranking by sensitivity rather than by count: a hundred exposed team sites full of meeting notes matter less than one finance site, and a programme that works top-down by count will spend its first month on the wrong sites. The second is capturing the baseline before remediation starts, because the only way to evidence progress to a sponsor later is a before-figure taken while it was still uncomfortable.
The uncomfortable framing, and the accurate one: the report tells you what Copilot would surface if you switched it on this afternoon. Nothing about that changes until someone decides it should.
The readiness assessment weights data governance and oversharing control at 19%, the heaviest of the eight pillars, for this reason. Score your position, or read the Purview engagement.
Why Copilot Pilots Stall at Ninety Days
Not because the technology disappoints, and not because users dislike it. Because at ninety days someone asks what it returned, and nobody captured the thing that would answer.
A pilot begins with three hundred licences and a cohort chosen because they volunteered. Usage is strong for six weeks. Then the sponsor asks the only question that was ever going to be asked — what did this return — and the programme discovers that the question is unanswerable, because no measurement was taken before the pilot began.
The trap is that Copilot usage telemetry is genuinely good and genuinely useless for this purpose. It will tell you active users, prompts per user, and which apps are used. It will not tell you whether a report that took four hours now takes one, because nobody recorded that it took four hours. The baseline had to be captured while the tenant was still uncontaminated by the pilot, and that window closes on the first day of the rollout and never reopens.
The second failure is cohort selection. Volunteers are the worst possible pilot group for a value case, because they are the population most inclined to find a way to make it work. They produce excellent adoption figures and a case study that does not generalise. A cohort chosen by persona — the people whose week actually contains the tasks Copilot is good at — produces weaker enthusiasm and a far more defensible number.
What a ninety-day review should contain is unglamorous and specific: three to five tasks named before the pilot started, timed before and after, attached to a named role and a recurring frequency. "Monthly board pack preparation, finance analyst, previously six hours, now two, twelve times a year" is a sentence a CFO can act on. "Sixty-eight per cent weekly active usage" is not, and the difference between those two sentences is usually the difference between a renewal and a wind-down.
None of this requires new tooling. It requires the measurement to be taken two weeks earlier than anyone wants to take it.
Adoption, change and value measurement is the pillar that gates tier 3 in the assessment, and the one most often scored generously. Take the assessment to see where it places you.
An Agent Without an Owner Is an Incident With a Delay
Copilot Studio made agent creation a business-user activity. Very little else in the operating model moved to match, and the gap is now measured in agents nobody can account for.
The first question to ask a tenant that has had Copilot Studio available for a year is how many agents exist. The answer is usually a guess, and the guess is usually low. The second question — who owns each one — tends to end the conversation, because ownership was never a field anyone was required to complete.
This matters more than an unused agent sitting idle would suggest, because agents are not documents. An agent has an identity, a set of connections, and a data reach, and each of those outlives the enthusiasm of the person who built it. The builder moves teams. The connection remains authorised. The agent continues answering, against content whose permissions have drifted, for an audience that has grown.
The remedy is not to restrict creation. Restricting creation is how organisations end up with an unofficial agent estate they cannot see at all, which is worse. The remedy is an inventory with five fields — owner, purpose, identity, data reach, review date — and a review that actually occurs. A quarterly review that lapses is indistinguishable, from an auditor's position, from never having had one.
The regulatory direction makes this less optional than it was. EU AI Act transparency obligations became enforceable in August 2026, and they assume an organisation can say what is running and disclose when a user is interacting with it. An estate that cannot produce its own agent inventory cannot satisfy that, and the deadline for the next tranche of obligations is already set.
The useful test is simple, and it takes a week to fail: ask for the list. Not the policy that says a list should exist — the list.
The AI governance overview sets out the operating model, the four ownerships, and what the inventory has to contain.
Where Does Your Tenant Actually Stand
Forty capabilities across eight weighted pillars, returning a tier, the gate holding the next one closed, and a ninety-day plan sequenced from the blocking pillar.