1) Fix oversharing and permission sprawl
Copilot uses what users already have access to — so overshared content becomes a business risk.
2) Define clear information ownership
Every site/library needs an owner and a governance expectation: access reviews, metadata hygiene, and retention compliance.
3) Standardise a simple site and folder model
Reduce “random team sites” and create repeatable patterns for departments and projects.
4) Implement sensitivity and access controls for critical content
Use a consistent approach for confidential, HR, finance, legal, and executive content.
5) Turn retention schedules into system rules (Purview)
Use retention labels/policies and apply them systematically.
6) Use File Plan discipline to manage labels at scale
Treat retention like a managed catalogue, not scattered settings.
7) Ensure auditability and defensible disposal
You need evidence of controls and actions, not just “we have a policy.”
8) Set up governance for Teams + SharePoint together
Teams content (files, chats, meeting notes) quickly becomes record-relevant; governance must cover the full collaboration layer.
9) Build an operating model (IT + Records + Legal + Business)
Copilot readiness is cross-functional. IT can’t “own governance” alone.
10) Train users on “Copilot-safe behaviour”
AI makes content discoverability feel different. Users need practical rules: where to store what, how to label, and what not to overshare.