Copilot does not create access, it inherits existing permissions
The most underestimated architecture decision in a Copilot rollout is not about Copilot itself, but about the permissions already in place. Copilot only shows content the user already has access to, security trimming ensures that, but it also means every overly broad site or folder suddenly becomes findable through a simple question instead of an accidental search. Oversharing is therefore not a risk Copilot introduces, it is a risk that already existed and that Copilot makes visible for the first time.

