Before Copilot: Check Your Firm's Client File Access
A new AI assistant can make information easier to find. For an accounting firm, that raises a practical question: is the information available to the right people in the first place?
A client folder may have started with a small team, then gained temporary staff, external collaborators and several sharing links. The work finished, but nobody reviewed the access. Introducing better search does not resolve that history.
Before a Microsoft 365 Copilot rollout, review the files and permissions that the pilot group already uses. Start with a manageable part of the practice and an owner who understands the work. A focused review is more useful than a long spreadsheet of permissions that nobody can interpret.
Understand what the permission boundary means
Microsoft states that Microsoft 365 Copilot uses content within the user's existing access permissions. See its data, privacy and security guidance.
The practical consequence is straightforward: if a staff member already has unnecessarily broad access, that is a problem to fix before making information easier to retrieve. It is not evidence that Copilot has bypassed permissions.
Do not treat a product purchase as proof that your information is correctly organised. Equally, do not remove access across the whole practice without checking how staff complete their work. The aim is deliberate access, with a record of who needs what.
Pick a small set of sensitive locations
Begin with locations that have clear business owners. Examples include a payroll workspace, a client engagement folder and the partners' management documents. These are suggested review areas, not a claim that your firm currently exposes them.
For each location, ask:
- Who is accountable for the information?
- Which roles need access now?
- Are former staff, old guests or broad groups still included?
- Which sharing links remain necessary?
- Is there another copy in a personal OneDrive or separate team?
Review the underlying file location as well as the place staff normally open it. A familiar Teams screen can make it easy to forget that document permissions need their own attention.
Have the business owner approve intended changes. Keep a change record and a way to restore legitimate access if a working process is interrupted.
Test with ordinary staff access
An administrator's successful test does not show what a normal user can or cannot see. Use approved test accounts with representative access, and fictional files with clear labels.
For example, place a fictional payroll note in the test location. Confirm that an authorised payroll role can find it and an unrelated role cannot open it. Test direct links and the relevant search experience. If Copilot is included in the pilot, test that route as well, allowing for service propagation delays.
Record the expected and actual results. Do not copy real payroll or client records into a broad test area. If a test reveals unexpected access, stop the affected pilot and investigate before adding more users.
Microsoft's guidance on applying Zero Trust principles to Copilot includes access reviews and controls for oversharing. Some controls depend on the product and licences held; confirm availability before making them part of your plan.
Keep ownership after the rollout
Add access reviews to ordinary changes in the practice: a new engagement, staff departure, completed project or external collaborator leaving. Give each shared location a current owner and an escalation contact.
A useful review record is short: location, owner, access decision, date checked and unresolved issues. It should help the next reviewer understand the decision, not merely prove that someone exported a report.
Our Zero Trust guide explains the wider approach to checking access. For help planning a contained permissions review before an AI rollout, contact SuperStack IT. Bring a description of the workflow rather than sending confidential client files with the enquiry.