← All services
AI Solutions

AI Solutions

Practical AI with real outcomes, starting with a Microsoft 365 Copilot readiness assessment.

Overview

Ease your organisation into the world of AI

In short: Copilot readiness first, licences second. Copilot inherits your existing permissions exactly, so oversharing that has sat harmlessly for years becomes visible on day one. That sequencing is the project, not a preliminary to it.

Switch Copilot on before your permissions and data are ready, and it will happily surface files nobody should see. With AI, readiness isn't optional, it's the whole project.

Who this is for
You're considering or piloting Microsoft 365 Copilot
Nobody has audited SharePoint or OneDrive permissions and oversharing recently
You want measurable productivity gains, with the governance to back them up

The problem

Copilot surfaces whatever a user can already access, so existing oversharing, stale permissions or unlabelled sensitive data becomes instantly and disastrously more visible the day you switch it on. Most businesses discover this after rollout, not before.

What we would do

Do the permissions and data work before buying Copilot licences, not after. Copilot inherits your existing permissions exactly, so oversharing that has sat harmlessly for years becomes visible on day one. That sequencing is the project, and what follows it is comparatively straightforward.

  • If your tenant is young and sharing has always been controlled, a smaller readiness check may be all you need before a pilot.
  • If nobody has decided what the tool is actually for, decide that first. A pilot without a named use case produces opinions rather than evidence.

When we are not the answer: If you are buying Copilot to reduce headcount, we are the wrong partner. We do not sell it that way, and we will tell you when a particular team will get very little from it.

How we help

AI only delivers when the groundwork is right. We start with a Copilot readiness assessment, reviewing your data, permissions and governance, then guide a safe, measured rollout.

More on how we deliver AI adoption

From Microsoft 365 Copilot to custom assistants and process automation, we help you adopt AI with the governance and data protection to back it up, and the productivity gains to prove it.

Systech is founder-led by Ryan Mangan, a Microsoft MVP for Azure Virtual Desktop and Windows 365, a Chartered Fellow of the BCS (FBCS) and author of Packt's two-edition Mastering Azure Virtual Desktop.

Retro pixel-art illustration of a friendly rounded pixel robot with a speech bubble above its head
What's included

Everything you need, managed for you

Copilot readiness assessment and rollout
Data, permissions and governance review
Custom copilots and process automation
AI governance and data protection
User training and adoption support
Measurable productivity benchmarking

What does a Copilot readiness assessment actually check?

Four things, in this order:

  • Who can see what
  • What your data actually is
  • Whether identity and devices are controlled
  • Whether anyone has decided what the tool is for

Permissions come first, because Copilot inherits them exactly. So the assessment starts with SharePoint and OneDrive sharing settings, links set to 'anyone with the link', sites with no owner, guest accounts left over from projects that finished, and the company-wide groups that quietly grant everybody access to everything.

The rest follows from that. Data lifecycle: whether retention and disposal have ever been applied, because a tenant that has never deleted anything is one where a decade of superseded documents is exactly as available to be surfaced as this month's version.

Sensitivity labelling: whether the material that genuinely needs restricting is marked in a way the platform can act on. Identity and device posture: multi-factor authentication, Conditional Access and device compliance, because a Copilot licence raises the value of a compromised account. And the licensing position, which is the easiest part and the one most people start with.

Why does Copilot surface files people should not see?

Because it is doing exactly what it was designed to do. Copilot has no permissions model of its own: it queries content as the signed-in user, so anything they could already have found through search, they can now find by asking a question in plain English. The change is not access, it is discoverability. Files that were technically reachable but practically invisible, buried in a site nobody browses, twelve folders deep, named something meaningless, become one sentence away.

That is why oversharing which has sat harmlessly for years turns into an incident on day one. The examples are depressingly consistent:

  • An HR site shared to a company-wide group for one document and never re-scoped
  • A leadership site inheriting permissions from a parent everyone was added to
  • Restructure or salary material in a personal OneDrive, shared to a colleague and never unshared
  • A finance workbook dropped into a chat, which quietly lives in the sender's OneDrive behind an organisation-wide link

None of those are Copilot faults. All of them become Copilot's problem the moment you switch it on.

What has to be true before you assign the first licence?

A short list, and none of it is optional. Multi-factor authentication enforced for every user without exception. Sharing defaults set to named people rather than anyone with the link, with expiry on any anonymous link you do keep.

Company-wide access removed from sites that should never have had it. An owner assigned to every site and Team, because an unowned workspace has nobody who can make a decision about its content. Guest access reviewed by last activity rather than by whether the name still looks familiar.

Then the things that are less obviously security controls but decide whether the pilot goes well:

  • A retention and disposal position, so the index is not dominated by superseded material
  • Sensitivity labels applied where they genuinely matter rather than everywhere, because a labelling scheme nobody can follow gets ignored
  • A written statement of what staff may and may not do with AI output

Doing the permissions work first is not a delay to the project. It is the project. What follows it is comparatively straightforward.

What does a safe Copilot rollout look like, step by step?

Assess, remediate, pilot, measure, expand. The assessment produces a written picture of permissions, sharing, data and readiness. Remediation fixes what it found, and this is the phase that takes real time, because re-scoping site access and clearing legacy sharing is careful work that changes how people currently get at things. Only then does a pilot start, deliberately small and deliberately chosen: a group with real, repetitive, document-heavy work, rather than whoever asked first.

The pilot has to be measured against something. Pick two or three tasks the group genuinely does, record roughly how long they take today, and compare afterwards. Then expand by role rather than by enthusiasm, because the value is uneven: people who spend the day in Outlook, Word, Teams meetings and SharePoint get far more from it than people who spend the day in a line-of-business application Copilot cannot see. Reviewing usage after each expansion, and reclaiming licences from users who stopped, is what stops this becoming an annual renewal for something nobody opens.

How does Copilot licensing interact with what you already own?

Microsoft 365 Copilot is an add-on rather than a plan in its own right, so it sits on top of a qualifying Microsoft 365 subscription and is assigned per user. Two consequences are worth planning for.

First, the base licence you hold is part of the decision, and where a tier change is needed it is far easier to handle at renewal than mid-term. Second, it is a per-user cost that runs whether or not anyone opens it, so who receives a licence is a commercial decision rather than an inclusive gesture.

There is also more than one thing called Copilot, and conflating them causes most of the confusion in a licensing conversation. A general web chat experience is not the same as the paid Microsoft 365 Copilot that reaches into your own tenant content, and neither is the same as a purpose-built agent published to a named audience.

Establishing which one a request actually refers to settles half the argument before price comes up. The wider question of what you own, what you use and what you are paying twice for sits on our licensing and cost management page, and right-sizing there frequently funds a good part of a Copilot pilot.

What does the published evidence say about Copilot saving time?

There is now real published evidence rather than only vendor case studies, and it is worth reading carefully because it is more modest and more useful than the marketing.

HMRC published a Phase 3 evaluation covering 3,000 randomly allocated licences plus 500 for volunteers, run from September to December 2024 with 1,364 survey responses. Staff self-reported saving 2 to 3% of their working week, which HMRC put at around 60 minutes, and HMRC then reduced its own headline figures by about 20% to account for non-users and response bias. A separate cross-government trial covering more than 20,000 civil servants reported around 26 minutes a day.

Those two numbers are not comparable, and the gap between them is the point. Different populations, measured differently, both self-reported. Anyone quoting one of them at you as the figure your business will achieve is selling rather than advising, and we are not going to do it either.

What the HMRC evaluation does support, which is more useful than a headline figure:

  • Adoption was high where licences were targeted: 83% of staff given one used it, and 64% said their use grew over the trial.
  • Satisfaction averaged 7.1 out of 10 and 61% would have been disappointed to lose the licence, which is a solid result rather than a spectacular one.
  • The tasks that dominated were document drafting in Word at 53% and collaboration in Teams at 45%, which is where to point a pilot.
  • 46% of non-users gave security and data privacy concerns as their main reason for not using it.

That last figure is the one worth sitting with, because it is the readiness argument made by the users themselves. Nearly half the people who never touched a licence their employer had already paid for stayed away because they were not confident about what it could reach. That is not a training problem and it is not solved after rollout: it is the permissions and governance work, done first, and it is the difference between licences that get used and licences that get quietly abandoned.

How do you tell whether Copilot is actually delivering value?

By choosing how you will measure it before the rollout rather than after. The mistake is to look for a single productivity percentage, which nobody can produce honestly. What works is a small number of concrete tasks with an observable before and after: how long a first draft of a routine report takes, how long it takes someone to catch up on a meeting they missed, how long the monthly summary takes to assemble.

Ask the pilot group to record the starting position candidly, including how much they dislike the task, because time recovered from work people resent is worth more than the minutes suggest.

Then watch usage rather than licence count. Active use per person, which applications it is being used in, and how many licensed users have stopped entirely are the numbers that predict whether renewal is worth it. A licence assigned to somebody who used it twice in March is a recurring cost with no return, and reclaiming it is not a failure of the project, it is the project working properly.

What should an AI use policy actually say?

Less than most drafts, and far more specifically. A policy people will follow states which tools are approved and which are not, what categories of information must never be pasted into an unapproved tool (client data, personal data, anything under NDA, credentials, unpublished financials), that AI output is a draft and the person who sends it owns it, and where to ask when something is unclear. A policy that opens with a definition of machine learning is one nobody reads to the end of.

The part most often missing is the route to yes. If there is no approved way to use a tool people find genuinely useful, they will use it anyway on a personal account, and you lose the control and the visibility together.

Naming approved tools and providing a simple request process for new ones converts shadow AI into something you can see. Where automated output feeds a decision about a person, whether that is recruitment, credit or anything else with a consequence, the policy also needs to say who reviews it, because that is a legal position rather than a preference.

What is shadow AI, and how do you find it?

Shadow AI is the use of AI tools nobody approved, on accounts nobody manages, with company information nobody agreed to share. It is almost always well intentioned: somebody had a tedious task and found something that helped.

The risk is not the intent, it is that the data has left your control, the output has no audit trail, and when a client or an auditor asks whether their information has been put into a third-party model, the honest answer is that you do not know.

Finding it starts with signals you already hold rather than with a survey, because a survey asks people to confess. Sign-in and application consent records in Entra ID show which third-party applications have been granted access to your tenant and by whom.

Expense claims and card statements show personal subscriptions. Browser and network telemetry, where you have it, covers the rest. What matters more than the inventory is what happens next: a genuine approved option offered quickly does more to reduce shadow AI than any prohibition.

Where does Copilot help, and where does it genuinely not?

It helps most where the work is language-shaped and the source material already lives in Microsoft 365. Summarising a long thread or a meeting you missed, producing a first draft from documents that already exist, finding the thing you know you read but cannot locate, turning rough notes into something presentable, and restructuring content you already have. In those tasks it changes the shape of the work: instead of starting from nothing you start from something imperfect, which for most people is considerably easier.

It helps least where the answer depends on data it cannot see, or on being exactly right. Anything sitting in a line-of-business system outside Microsoft 365 is invisible to it unless deliberately connected. Numerical work needs checking, because a confident wrong figure looks identical to a confident right one.

And any output going to a client, a regulator or a court needs a human who is accountable for it, which is a governance decision rather than a technical one. Saying this plainly at the start protects the project, because expectations set too high in month one are the most common reason adoption stalls by month three.

What are Copilot agents, and what changes when you publish one?

An agent is a Copilot pointed at a defined set of content, given instructions, and published to a specific audience. That focus is what makes agents useful, and it is also what makes three questions unavoidable: what content it can reach, who can use it, and who owns it.

An agent holds a standing pointer at company data, so one published broadly against a site with loose permissions is the oversharing problem again, in a form that is harder to notice because it presents as a small helpful tool rather than as a search index.

The workable position is that every published agent has a named owner, a stated purpose and a review date recorded somewhere central, and that it joins the same review cycle as unowned sites and stale guest accounts. Start narrow. An agent scoped to one well-governed document library and used by one team is a good first agent. An agent scoped to everything is a governance problem with a friendly interface.

When do you not need this, and where does our scope end?

You do not need a readiness engagement if your tenant is small and recently built, sharing is already locked down, multi-factor authentication is everywhere and every site has an owner. In that position, buy a handful of licences, run a pilot and measure it.

The assessment earns its cost where the tenant has history:

  • Several years of accumulated sharing
  • Sites nobody owns
  • Guests nobody has reviewed
  • No confident answer to the question of who can currently see the HR folder

Our scope is the Microsoft side of this and the governance around it:

  • Permissions and sharing remediation
  • Labelling
  • Licensing
  • Rollout
  • Policy, training and measurement

We do not sell AI as a headcount reduction, and we will say so when the honest answer is that a particular team will get little from it.

Where the requirement is AI answering from your own data, or built into your own application, that is a different discipline and it sits on our AI engineering page rather than this one.

Copilot readiness: the dimensions an assessment covers, and what skipping each one costs.
Readiness dimensionWhat 'ready' looks likeWhat happens if you skip it
Permissions and sharingSharing defaults set to named people, company-wide access removed from sites that should not have it, every site and Team ownedCopilot answers from content the user could always technically reach, so years of quiet oversharing becomes instantly findable
Guest and external accessGuests reviewed by last activity, anonymous links expiring, external members removed when a project endsContent is exposed beyond the organisation with no record of who still has a way in
Data lifecycleRetention and disposal applied, superseded material removed rather than accumulating indefinitelyAnswers are drawn from old versions and abandoned drafts as readily as from current documents
Sensitivity labellingLabels applied to the material that genuinely needs restricting, in a scheme people can actually followThe platform has no signal to distinguish confidential content from everything else
Identity and device postureMulti-factor authentication everywhere, Conditional Access and device compliance enforcedA compromised account becomes far more valuable, because it now carries a fast way to find the sensitive material
Licensing positionQualifying base licences confirmed, add-on seats assigned deliberately by role and reviewed for usePer-user cost runs whether or not anyone opens it, and shelfware appears at the first renewal
Policy and governanceA written AI use policy, an approved tool list, an owner and review date for every published agentShadow AI fills the gap, on personal accounts, with company data and no audit trail
Adoption and measurementA pilot group, two or three benchmarked tasks, and a usage review before each expansionNobody can answer whether it was worth the money, so renewal becomes a matter of opinion
Frequently asked

Questions we hear a lot

Is my business ready for Microsoft 365 Copilot?

That's exactly what a readiness assessment answers. Copilot inherits every user's existing access, so before licensing anyone we audit SharePoint and OneDrive permissions, sensitivity labelling and governance. If oversharing exists, we fix it first, so Copilot boosts productivity without exposing data.

What's the difference between Copilot and a custom AI assistant?

Microsoft 365 Copilot works across your existing Microsoft apps. A custom copilot or assistant is built for a specific task or dataset, for example answering questions from your own documents. We help with both, and our AI Engineering service goes deeper into fully custom builds.

How do you measure whether AI is actually delivering value?

We benchmark before and after against the tasks that matter, so productivity gains are evidenced, not assumed. Adoption support and training make sure the tools are genuinely used rather than licensed and forgotten.

Can Copilot see files a user doesn't already have access to?

No. It answers as the signed-in user, so it can only reach what that person could already have opened or found through search. That is precisely why readiness work matters: the risk isn't that Copilot grants new access, it's that it makes existing over-permissive access trivially easy to find. Content sitting in a site shared company-wide by mistake was always reachable; before Copilot it was buried, after Copilot it is one question away.

Does Microsoft train its AI models on our company data?

Microsoft's published commitments for Microsoft 365 Copilot state that customer prompts, responses and tenant content are not used to train the underlying foundation models, and that data remains within the service's compliance boundary. Because these terms have been revised more than once, treat the current published terms as the authority rather than any summary, including this one, and check them as part of your own due diligence. The wider point is that the same assurance does not automatically apply to every AI tool your staff might use, which is why an approved tool list matters.

How many Copilot licences should we start with?

Enough for one pilot group doing genuinely document-heavy work, and no more. A pilot exists to produce evidence, and evidence needs a group small enough that you can actually talk to all of them and large enough that one enthusiast doesn't skew the result. Expand by role afterwards, based on what the pilot showed, rather than buying broadly on the assumption that everyone benefits equally. They don't: the value varies enormously depending on how much of someone's day is spent in Microsoft 365 rather than in a line-of-business system.

How long does permissions remediation usually take before a rollout?

It depends almost entirely on how much history the tenant has, which is why we assess before quoting the remediation rather than the other way round. A tenant built in the last couple of years with sharing controls already in place needs comparatively little. A tenant that has run for a decade, with sites nobody owns, guests nobody has reviewed and company-wide access granted to solve one-off problems, needs real work, and that work touches how people currently reach things, so it has to be staged and communicated rather than applied overnight.

AI adoption is delivered UK-wide from our office in Brough, East Yorkshire, with on-site support across the county where it helps. We work with businesses in Hull, Leeds, York, Sheffield, Barnsley and Halifax and 6 more Yorkshire towns and cities, and remotely with clients right across the UK.

Get Copilot-ready, safely

Book a free Copilot readiness assessment and we'll check your data, licensing and governance, then help your team actually adopt and use Microsoft 365 Copilot.

Technology partners

Best-of-breed technology we use to deliver AI adoption.

See all technology partners →