10 things IT & Records teams must fix in Microsoft 365 (before AI exposes your weak spots)
Microsoft 365 is changing fast. With Copilot and agents becoming part of everyday work, the biggest risk for organisations isnβt βAI replacing jobsβ β itβs AI surfacing information that was already overshared, mislabelled, or unmanaged.
Β
Microsoft is clear that Copilot and agents pull data from Microsoft Graph and respect existing permissions, sharing settings, and policies. That sounds reassuring β but it also means any permission sprawl and messy governance you already have becomes far more visible and impactful.
Β
If your organisation is serious about productivity, compliance, and audit readiness, this is the moment to modernise your IT + Records Management approach.
A growing best practice is to treat Copilot rollout like a structured governance programme: audit access, restrict discovery while you clean up overshared sites, then enable at scale. Microsoft even provides βRestricted Content Discoveryβ to give organisations time to review and fix permissions during onboarding.
Β
What to do now
Identify overshared sites and broken inheritance
Reduce βeveryone except external usersβ type access
Apply lifecycle controls for sites and content before enabling AI broadly
Microsoft positioned SharePoint Premium as the future of AI-powered content management and governance β essentially accelerating automation in how content is processed, secured, and governed.
Β
What to do now
Treat content services like a controlled system, not a dumping ground
Define what βhigh-value contentβ is and how it should be classified
Make sure governance (not just storage) is embedded into your platform
In many organisations, retention schedules exist on paper but arenβt enforced in systems. Microsoftβs Purview guidance focuses on using retention policies and retention labels to manage retention and deletion across Microsoft 365 workloads.
Β
What to do now
Move from policy documents to actual retention configuration
Align labels/policies with your file plan and legal requirements
Ensure disposition is auditable (who disposed what, when, and why)
When content is unstructured and inconsistently named, AI tools struggle and risk increases. Microsoftβs Purview File Plan capability supports managing retention labels from a single view and is designed to help organisations make retention more systematic.
Β
What to do now
Simplify your file plan (avoid 500+ categories no one uses)
Standardise metadata that matters (owner, sensitivity, retention class)
Train teams on βminimum viable metadataβ and enforce it
For public-sector and many regulated environments, standards alignment remains critical. NARSSA states that the primary endorsed standard for electronic records in office environments is SANS (ISO) 16175-2 (structured records systems managed according to a file plan).
Β
What to do now
Map your EDRMS/ECM system capabilities to ISO 16175-2 principles
Ensure your system supports structured recordkeeping requirements
Treat βrecords complianceβ as an operating model, not a once-off project
1) Fix oversharing and permission sprawl
Copilot uses what users already have access to β so overshared content becomes a business risk.
2) Define clear information ownership
Every site/library needs an owner and a governance expectation: access reviews, metadata hygiene, and retention compliance.
3) Standardise a simple site and folder model
Reduce βrandom team sitesβ and create repeatable patterns for departments and projects.
4) Implement sensitivity and access controls for critical content
Use a consistent approach for confidential, HR, finance, legal, and executive content.
5) Turn retention schedules into system rules (Purview)
Use retention labels/policies and apply them systematically.
6) Use File Plan discipline to manage labels at scale
Treat retention like a managed catalogue, not scattered settings.
7) Ensure auditability and defensible disposal
You need evidence of controls and actions, not just βwe have a policy.β
8) Set up governance for Teams + SharePoint together
Teams content (files, chats, meeting notes) quickly becomes record-relevant; governance must cover the full collaboration layer.
9) Build an operating model (IT + Records + Legal + Business)
Copilot readiness is cross-functional. IT canβt βown governanceβ alone.
10) Train users on βCopilot-safe behaviourβ
AI makes content discoverability feel different. Users need practical rules: where to store what, how to label, and what not to overshare.
In 2026, the strongest organisations will be those that treat information governance as productivity infrastructure. When governance is clean:
audits become easier
risks decrease
AI adoption becomes safer
and teams spend less time searching, recreating, and correcting information
Prospen Africa supports organisations with training in IT and Records Management β from EDRMS fundamentals through governance, lifecycle management, and standards alignment.
Explore the IT & Records category:
https://prospen.co.za/it-and-records/
Please check your email for confirmation
Search across our courses and qualifications
Our trainings can be customised to fit your organisation's needs.