Skip to content

By Colin Riddle, Chief Product Officer, Ekco Cloud & Security

The pattern is familiar: an organisation rolls out Copilot to a group of enthusiastic early adopters, the initial reaction is positive, people are impressed, a few genuine time savings get reported, momentum looks real.

The moment Copilot is switched on, it can see everything a user already has permission to access, and it will answer questions using whatever data it finds, accurate or not, current or not, meant for wide viewing or not.

This isn’t a training problem or an adoption problem. It’s almost always a failure to check, before go-live, whether the data Copilot draws on and the access it inherits are actually fit for that job.

The checkpoint everyone reaches, and most skip

By the time an organisation reaches this stage, the instinct is usually to just switch Copilot on.

The spend is under control, the data’s been cleaned up, the security evidence exists, surely that’s the hard part done. It’s close, but there’s one more checkpoint worth taking seriously, because skipping it is exactly how AI pilots produce concerning results and underwhelming outcomes that quietly kill momentum.

Information governance: has it kept pace?

The first thing that decides whether go-live is a good moment or a bad one is information governance: whether the controls, ownership and lifecycle processes around your information have kept pace with the growth of the business, or whether years of unmanaged content and inconsistent governance have left people unsure what information can still be relied upon.

Get it right, and Copilot can draw from an environment that is properly governed and easier to trust.

Data access: does it reflect who should actually see what?

The second is data access: whether access to files, mailboxes and Teams sites reflects who should actually see what, or whether years of default sharing and permission creep mean Copilot will happily surface content to people who were never supposed to have it.

For some organisations, the conversation doesn’t stop at Copilot

As AI ambitions mature, attention often turns to Microsoft Azure and whether it’s ready to support future workloads.

The Azure Well-Architected Review provides that perspective, evaluating the estate against Microsoft’s five Well-Architected pillars and identifying the architectural risks, operational weaknesses and improvement opportunities that could affect future growth.

For organisations planning to expand their use of AI, host their own AI services, or support increasingly business-critical workloads in Azure, it provides a clear view of whether the platform is ready for what’s next.

The difference between switching Copilot on and being ready to

Ekco’s M365 Copilot Readiness Assessment reviews tenant configuration, data access, data governance and shadow AI usage to produce a prioritised risk register before go-live, on its own.

For organisations planning their own LLM deployment in Azure, the Well-Architected Review is a separate exercise, checking the wider cloud estate against Microsoft’s own five-pillar framework: cost, security, reliability, performance and operational excellence.

Neither assessment takes long

Getting the right one done, or doing both – if you’re planning your own LLM deployment too – is what actually gives the adoption phase that follows a fair chance. Helping you avoid layering Copilot on top of problems that were already there.

And none of this requires assuming your rollout will go wrong. It requires checking, before go-live, whether the data Copilot will draw on and the access it inherits are actually fit for that job. .

This is the last of the four AI-Ready pillars, and the point where a readiness conversation turns into an adoption one.

Explore the full AI-Ready Suite

And why not sign up for our short webinar series on how to get AI-Ready?

Four short webinars available to watch live or on demand after each session.

Sign up here

Question?
Our specialists have the answer