Government: knowledge access with strict governance in Microsoft 365 Copilot
A government agency exposes large document corpora with Copilot within a strict grounding scope, after oversharing remediation and with labels, DLP and EU Data Boundary.

Business challenge
A government agency managed large document corpora under strict GDPR and information security requirements. Staff wanted to find and draft policy and procedures faster, but years of SharePoint growth had produced widely shared sites where nobody knew exactly who could access what anymore. An AI rollout without cleaning that up first would only make the problem more visible.
Architecture
Before rollout, the organization remediates oversharing: Restricted Content Discovery (RCD) temporarily limits the search scope to approved sites, while SharePoint Advanced Management and a permissions cleanup restore the underlying access model. Only then does Copilot go live, with sensitivity labels and Purview DLP factored into every answer, and audit recording every Copilot interaction. Where required, the EU Data Boundary processes data within the European border.
Why this choice
The organization did not want to choose between productivity and control: the answer was not to delay Copilot until everything was perfect, but to deliberately narrow the grounding scope during remediation and widen it only once underlying permissions were correct. That kept progress moving without the risk of oversharing becoming broadly visible.
Alternatives
Rolling out Copilot organization-wide without remediating first would have been faster, but would have exposed exactly the problem the organization wanted to avoid: documents that were too broadly shared, suddenly findable by anyone who asked. Waiting to roll out until remediation was complete everywhere cost months without any interim value.
Trade-offs
- Restricted Content Discovery (RCD) temporarily limits the grounding scope, which reduces Copilot's usefulness during that period.
- Permissions cleanup at scale is labor-intensive and needs involvement from site owners who are not always available.
- EU Data Boundary processing can, depending on configuration, impose limits on certain features.
Microsoft products
Microsoft 365 Copilot, Microsoft Purview (DLP, sensitivity labels, audit), SharePoint (Restricted Content Discovery, Advanced Management), Microsoft Entra ID.
Best practices
- Remediate oversharing before broad rollout, not in reaction to an incident.
- Roll out in phases per department, starting with the sites with the cleanest permissions.
- Document which sites fall within the grounding scope and why, so expansion is a deliberate decision.
Lessons learned
Remediation took more time than the technical Copilot rollout itself, but proved the right order: departments that went live after remediation had almost no reports of unwanted visible content. The department that went live early under time pressure, without full remediation, had to fix permissions after the fact while users were already active.
Architecture at a glance
Click a component for details
Oversharing remediation
Temporarily limits the search scope to approved sites.
The grounding scope is deliberately narrowed during remediation and only widened once permissions are correct.
Related content
Related how-tos
Related best practices
