What we do

Microsoft 365 & AI readiness

Copilot inherits your permissions. Fix those first.

Copilot does not invent access. It uses exactly the access the person asking already has. Point it at a SharePoint nobody has tidied since 2019 and it will cheerfully surface the payroll spreadsheet to whoever asks a politely worded question.

The permissions clean-up is worth doing whether or not you ever buy Copilot. AI just makes the mess searchable.
The honest version of the pitch We'd rather say that up front than let you buy an AI licence to solve a problem that is really a filing problem.

Here's what actually happens in most tenants. Someone shares a folder with "Everyone Except External Users" in 2021 to stop a colleague asking again. Someone breaks permission inheritance on a subfolder for one contractor. Someone creates a Team for a project that finished, and then leaves the business, so the site has no owner. None of it was reckless. It just accumulated.

For six years that mess was harmless, because nobody could find anything anyway. Search was bad enough to act as a security control. Copilot is not bad at search. That's the entire problem in one sentence.

The clean-up

What we look for, and what we do about it.

This is mostly Microsoft's own tooling used properly. There's no magic here — just someone actually running the reports and then doing the unglamorous work the reports point at.

Step one — find it

The Content Management Assessment

SharePoint Advanced Management includes an assessment that surfaces the things that will bite you:

  • Oversized audiences — content shared far wider than anyone intended
  • Use of "Everyone Except External Users", the one that quietly means "the whole company"
  • Broken permission inheritance, where a subfolder no longer follows its parent
  • Sharing that shouldn't have happened, including links that never expire
  • Inactive and ownerless sites — nobody's job, nobody's cleaning them up

Microsoft recommends re-running it every 30 days. We do, and we send you the delta rather than the whole report, because nobody reads the whole report.

The default that nobody changed

By default, SharePoint sets sharing to the most permissive option available. Most tenants have never touched it. That single setting is usually the biggest gap in an environment and it takes minutes to change — though working out who it will inconvenience takes rather longer, which is why it's still sitting there.

Data access governance reports

A site permissions baseline tells us who can reach what today. Sharing link activity tells us what's actually being handed out. Between the two you get a real picture instead of an org chart's worth of good intentions.

Restricted Content Discovery

This one is genuinely useful. It excludes sensitive sites from Copilot discovery without changing the underlying permissions. So the HR site stops appearing in AI results on day one, while the proper remediation runs over the following weeks. It's the interim control, not the fix.

Purview, labels and grounding

Purview DSPM data risk assessments show where sensitive content is sitting, and DLP for Microsoft 365 Copilot excludes that content from Copilot grounding. Worth knowing: legacy IRM-protected documents are not used in Copilot grounding at all, so if you've got old IRM content you need to migrate it to sensitivity labels or it will simply be invisible.

Site lifecycle and owners

Every site needs a valid owner. Sites for finished projects get archived rather than left drifting. This is the part that stops the mess coming back six months after we've cleaned it up.

The bit that gets left out of the sales meeting

Most of you are on the wrong licence for this.

SharePoint Advanced Management requires a base of Office 365 E3, E5 or A5, or Microsoft 365 E1, E3, E5 or A5.

Nearly every business we see with 10 to 50 people is on Microsoft 365 Business Premium. Business Premium is a good product and it is not on that list.

We're saying this out loud because plenty of people won't. It is very easy to sell "Copilot governance" to a business that cannot run the tooling on the licences it holds, collect the project fee, and let the gap turn up later.

So the conversation goes one of three ways, and we'll tell you which one you're in before you spend anything:

  • Change licences. Sometimes justified, often not. It's a real per-user increase every month, forever, and we'll do the sums with you rather than for you.
  • Do the clean-up manually. Slower and more of our time, but no licence change. For a small tenant this is frequently the cheaper answer.
  • Don't do Copilot yet. A completely legitimate outcome. If the permissions work isn't affordable this year, buying the AI licences first is the wrong order.

Shadow AI

Your staff are already using AI. You just don't know which one.

Someone in your business has pasted a client's details into whatever chatbot was open, to make an email sound better. They weren't being careless by their own lights — they were trying to do a good job faster. Nobody told them not to, because nobody has thought about it.

This is a governance problem, and naming it is most of the work. You need a position, in writing, that staff can actually follow: which tools are approved, what can go into them, and what absolutely cannot.

Give people a sanctioned tool that works and the shadow usage mostly stops. Ban everything and issue no alternative, and it goes underground where you can't see it.

The unglamorous majority of the job

All the ordinary Microsoft 365 work, done properly.

AI readiness is the interesting half. This is the half that has to be right first, and it's what we spend most of our time on. Incidentally, it's Microsoft 365 now — the "Office 365" branding went years ago, though the phrase will outlive all of us.

Tenant setup and migration

Moving from another provider's tenant, from Google Workspace, or from an on-premises Exchange. Mailboxes, files, permissions and the hundred small settings nobody documents. Done on a weekend, with a rollback plan we hope not to use.

Exchange Online and email

Mail flow, spam and phishing controls, shared mailboxes, and the SPF, DKIM and DMARC records that stop someone sending invoices as you. That last one is the single cheapest fraud control most businesses are still missing.

Teams and Teams Phone

Including replacing an ageing phone system with Teams Phone, which is usually cheaper and always more popular with people who work from two places. We'll tell you when your call volumes or call flows mean it's a bad fit.

SharePoint and OneDrive

Structure that matches how your business actually works, rather than a faithful copy of the shared drive folder tree from 2014. Getting this right once is what makes the permissions story manageable later.

Identity with Entra ID

Single sign-on, multi-factor authentication done across everything rather than just email, and conditional access rules so a login from an unmanaged device at 2am is treated differently to one from the office.

Intune device management

Laptops that arrive configured, encrypted and enrolled without anyone spending a day on them. And the ability to wipe one remotely when it goes missing at an airport, which does happen.

Free tool, no email needed

Not sure which licences you actually need?

Eight questions and you'll have a costed licence mix with the reasoning attached — including the cheaper frontline licences for site and plant staff that most businesses never find out about.

Open the licensing wizard

Before you buy Copilot, find out what it can see.

We'll run the permissions and sharing reports across your tenant and show you, in writing, what an AI assistant would be able to surface today. Then you can decide what to do about it.

  • Microsoft Solutions Partner

    Infrastructure (Azure)

  • Microsoft Solutions Partner

    Modern Work

  • Microsoft Solutions Partner

    Security