The short answer

Copilot shows staff what they could already open. Fix who can open what first.

Microsoft 365 Copilot gives no one new access: it answers each person only from what that person is already allowed to open. In most small firms that is far more than anyone meant, because file access built up over the years and nobody cleaned it up. Copilot makes those files easy to find. So before you turn it on, review who can open what, fix the obvious problems, and write down what you did. For a firm of ten to twenty-five people that takes days, not months.

Most managing partners ask us one question about Microsoft 365 Copilot: is it safe to turn on? A better question is what each person on your staff can open today. That is the whole answer.

What Copilot actually does

Copilot answers each person using only what that person is already allowed to open. It does not give anyone new access. It follows your firm's access settings exactly as they are.

That sounds safe. The catch is how access gets set up in a small firm: usually nobody set it up on purpose. It built up over the years.

Copilot does not create a new leak. It makes an old one easy to find.

Take a partner compensation spreadsheet saved in a shared folder. Eleven people could open it. Nobody ever did, because nobody knew it was there. Being hard to find was doing the job the access settings should have done.

Copilot takes away "hard to find." Someone asks a plain question, and the answer comes back from that spreadsheet. The person was always allowed to open it. They were just never expected to find it.

Nothing broke. That is what makes it hard to explain afterward.

Where the extra access came from

In firms of ten to twenty-five people, four habits cause almost all of it. None of them is anyone being careless.

The move to the cloud. Someone moved the old file server into SharePoint or OneDrive over a weekend. The folders came across as they were. The restrictions often did not, because keeping them was nobody's job.

"Anyone with the link" sharing. If this default was never tightened, every link shared in the last four years still works for whoever has it, and nobody has a list of them.

Whole-folder access. Someone needed one document, so they were given the whole folder. Then the folder kept growing.

Too many administrators. Not everyone on staff holds administrator rights. But everyone who was ever senior, ever set up a laptop, or ever fixed something on a Sunday in filing season does.

Give Copilot licenses to a firm like that and something will come up. The only questions are what comes up first, and who is in the room when it does.

Five checks before you turn it on

This is a review, not a project. For a firm your size it takes days, not months, and you do not need to buy anything.

1. Match access to who works here now. Check who can open what against this week's staff list, not the org chart. People who have left are the usual find: their accounts were kept for handover and never lost any access.

2. Find the "anyone with the link" shares. Set an expiry date on each one, or remove it. Then change the default so the next four years do not repeat the last four.

3. Lock down the files that should never be open to everyone. Payroll and pay. Partner and firm finances. Anything under its own confidentiality agreement. HR matters. In most firms these sit in the same place as everything else, separated only by a folder name.

4. Limit administrator rights to the people who need them. Some people hold admin rights their job does not need. Taking them back is unpopular. It is also the one thing an insurer and an examiner both ask about, in different words.

5. Decide what Copilot is allowed to read. A general assistant that can search everything a person can open is a different risk from a focused one that reads a single document library, one shared set of files. Make that choice when you set Copilot up. It is much harder to change once staff have built habits around it.

Do the first four before anyone gets a license. The review is uncomfortable to run once staff are already using Copilot and finding things.

Which Copilot your staff are using

Several products are called Copilot, and they do not come with the same promises.

The business version is Microsoft 365 Copilot on a commercial license in your firm's Microsoft 365. It comes with Microsoft's enterprise data protection commitments: contract terms set out in the Microsoft Data Protection Addendum and the Product Terms. The consumer versions do not. Microsoft Copilot on a personal account is the free one. Microsoft no longer sells Copilot Pro, and points its subscribers to Microsoft 365 Premium.

They look almost the same on screen. For a firm holding client tax returns, the contract behind them is very different.

So your staff could be "using Copilot" in three places at once, under three different sets of terms, with no record of which is which. Start with a list of which Copilot each person uses. It usually takes an afternoon.

Write the review down

This is the part that matters most later.

Fixing the access is the easy half. The half that pays off is keeping a record: what you checked, on what date, which role did it, what you found, and what you changed. Do the same for the list of Copilot versions and for the decision about what Copilot may read.

For a firm holding customer information, two things here are part of the FTC Safeguards Rule, at 16 CFR 314.4(c). One is controlling who can get to that information. The other is reviewing that access from time to time. In June 2026 the IRS Office of Professional Responsibility asked firms to document their AI procedures. Correct settings alone cannot show either one: that access is controlled and reviewed, or that AI procedures are documented. Correct settings with a dated record of the last review can.

A firm that fixed its access and kept no record has done the work and kept none of the value. It will do the work again the next time someone asks.

The house rule · Claremont Security

Turn Copilot on after the review, not before, and write the review down while you do it. In that order it costs a few days, once. The other way round it costs the same days later, with people watching.

Does Microsoft 365 Copilot widen access to firm data?+

No. It answers each person only from what that person is already allowed to open. What changes is that things become easy to find. A document eleven people could open, and nobody could find, now comes back from a plain question.

Where does the extra access come from?+

In firms of ten to twenty-five people, four habits cause most of it. None of them is carelessness. First, a file server moved into SharePoint or OneDrive over a weekend: the folders came across, the restrictions often did not. Second, "anyone with the link" sharing that was never tightened, so every link shared in the last four years still works. Third, a whole folder given to someone who needed one document. Fourth, administrator rights held by everyone who was ever senior, set up a laptop, or fixed something on a Sunday.

What should a firm check before giving staff Copilot licenses?+

Five things. Match access to this week's staff list. Find every "anyone with the link" share and set an expiry or remove it, then change the default. Lock down payroll and pay, partner and firm finances, anything under its own confidentiality agreement, and HR matters. Limit administrator rights to the people who need them. Decide what Copilot is allowed to read. Do the first four before anyone gets a license.

Does every version of Copilot come with the same data protection?+

No. Microsoft's enterprise data protection commitments come with Microsoft 365 Copilot on a commercial license in the firm's Microsoft 365, under the Microsoft Data Protection Addendum and the Product Terms. The consumer versions do not carry them. Microsoft Copilot on a personal account is free. Microsoft no longer sells Copilot Pro, and points its subscribers to Microsoft 365 Premium.

Why write the review down?+

Because correct settings do not, by themselves, show that anyone reviewed access, or when. For a firm holding customer information, controlling and reviewing access is part of the FTC Safeguards Rule at 16 CFR 314.4(c). In June 2026 the IRS Office of Professional Responsibility asked firms to document their AI procedures. A dated record of the last review is what can show both.

Claremont Security sets up governed Microsoft 365 Copilot in a firm's own Microsoft 365: the access review, the decision about what Copilot may read, and the dated record that the controls were in place. To see where your firm stands, the AI Readiness Check is free and needs no account: claremontsecurity.com/readiness