Copilot working only on data your users are actually allowed to read.
Copilot reads everything a user can reach, which is the whole problem when a user can reach far more than anyone intended. We do not simply enable it. We fix the data first. Sensitivity labels are set to match how you classify things. Sharing is pulled back to what was meant. Retention is written for what you must keep and what you must bin. If you still run on-site file shares or SharePoint Server, they get the same treatment. Copilot can also be confidently wrong, so getting the data right lowers the risk but does not remove the need for people to check its output. The rollout follows once the data is in order.
Buying licences is not a deployment.
You may be coming to us with a pilot that has already surfaced something it should not: a salary spreadsheet quoted back in a summary, a board paper shown to a junior employee, or a file nobody realised was shared across the whole company. Or your data may already be in good order and you simply want Copilot rolled out properly, to a standard you can defend to a regulator.
The goal is data you control before the model ever sees it. Copilot simply reads faster than any person could, so years of oversharing and forgotten files stop being theoretical and start appearing in answers. Get the data right and Copilot earns its licence. Skip that step and you have automated a problem you did not know you had.
Making the data safe for Copilot to read.
What this covers depends on the state we find you in. Where Purview, Conditional Access or Intune are already partly configured, we build on what is there rather than start again. The four areas below cover the core of the work.
Labels and retention that match how your business actually classifies information.
A Purview Information Protection scheme built around the way your business really classifies things, not the four-tier template every tenant ships with. We publish the labels, draft auto-labelling against your live content and tune it so false positives stay manageable for your people. Retention set alongside it, so what you are obliged to keep is kept and what should have been deleted years ago is removed before the model can quote it.
Sharing restricted to who was meant to see it.
Years of over-broad sharing across SharePoint and OneDrive reviewed and reined in. We identify what is open more widely than its owner intended and refer each case back to that owner to confirm or revoke, so the business decides what stays reachable. Where the cleanup would otherwise run past your go-live date, we use Restricted SharePoint Search to contain the risk until it is complete.
Who reaches Copilot, and from what device.
Conditional Access set so confidential company information cannot be put into Copilot from an unmanaged personal device. We gate access on device compliance, location and risk, keep it off unmanaged devices, and confirm the Microsoft 365 audit log is running and retained, so there is a defensible record of who asked what. If you run SharePoint Server or on-site file shares, that content is labelled and reviewed too, rather than left unaddressed.
A rollout that earns its licence with your people.
We start with the teams where Copilot pays off quickest, rather than wherever demand is loudest. They get real prompts that suit their work, a plain written rule on what should and should not go into a chat, and a feedback loop that tells you what is landing. If you later build your own agents in Copilot Studio, they run on the same governed data rather than bypassing it.
What a safe deployment looks like in practice.
Safe means a finance director can ask for last quarter's variance and get a clean summary drawn only from what she is allowed to open. It means an HR manager can work through a long policy without a salary file shared into a Teams chat years ago surfacing alongside it. It means a confidential client matter is not quietly served up to a colleague who was never meant to see it. And it means that when a regulator asks who can reach what, you have a documented answer.
The checks on the right are how we get you there. The list is not the whole job, and we adapt it to each tenant. It is the standard your data must meet before any further users are added.
What we check
- Labels validated against your real files. Auto-labelling tested against a representative sample of your documents, with errors measured and corrected before it goes live.
- Content shared more widely than intended. Sites and folders open wider than the owner intended, listed clearly and referred back to that owner to confirm or close.
- Access locked to managed devices. Conditional Access, device compliance and app protection confirmed, so Copilot is not accessible from devices you do not control.
- Retention set to your actual legal obligations. Policies written around your actual obligations to keep and to delete, rather than the tenant defaults.
When clients tend to bring us in.
Most clients arrive in one of three situations.
The pilot has already shown someone something they should not see.
HR or finance content appeared in a summary it should not have, the licences are still being paid for, and confidence in the rollout has stalled. We correct the labelling and the sharing, then put the same users back on the same prompts so the business can see the difference for itself.
The licences are bought and you want the data in order before they go live.
The decision is made or all but made. We carry out the data work alongside procurement, so the day the licences go live is not the day the gaps appear. Your first users land in a tenant we have assessed properly, rather than one assumed to be fine.
It is already live, and compliance now needs answers.
Your DPO or auditor has asked what Copilot can disclose and to whom, and at present nobody can answer. We work through it worst case first, close the gaps, and give you a documented position you can stand behind.
Find out what your data exposes.
What you get
- A clear assessment of your labels, oversharing, retention and who can reach Copilot, taken from the live tenant rather than estimated.
- A plan that addresses the highest exposure first, sized to your timeline and the pace of change your organisation can absorb.
- A short paper your board or DPO can read and act on without further explanation.
One of our engineers assesses your tenant as Copilot would see it.
We go through your Purview labelling, your SharePoint and OneDrive sharing, retention, Conditional Access and the audit settings, and your on-site shares too if you have them. You get a clear findings paper, with the fixes ordered by risk, so the go-live date you have in mind becomes one you can hold to.
- Duration
- Agreed on the first call, based on your tenant size and current state.
- Deliverables
- The findings, the plan to fix them in order, and a short paper for the board.
- Continuity
- The senior engineer who assesses your data carries out the work that follows. No handover to another team.
Copilot surfaces whatever your permissions allow. Factor1 checks identity and data exposure first.
Copilot is one piece. We look after the whole.
Under one agreement, the estate is watched, maintained and documented as a single thing, by the team behind this page.
…and everything between.
Show us your data as it stands.
A short call with an engineer who can plan the work. Tell us what you want Copilot to do, where you think the data is weakest, and how firm your deadline is. From there you can engage a named engineer, hand the whole programme to us to run, set it up as a fixed-fee project, or call on us as needed.
