Claude Cursor GitHub Copilot Skill

copilot-data-readiness-protocol

Use this skill before enabling Microsoft 365 Copilot for any user population. Runs an oversharing assessment, applies sensitivity labels and DLP controls, validates permissions baseline, and confirms a secure data foundation exists. Orchestrates m365-copilot-readiness-governance-

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_cross-functional_copilot-data-readiness-protocol-febe32a.zip · 8 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/cross-functional/copilot-data-readiness-protocol
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Copilot Data Readiness Protocol

Purpose

Microsoft 365 Copilot surfaces content that users already have permission to access. If that content is over-shared, unlabelled, or poorly governed, Copilot amplifies the exposure. This skill defines the mandatory readiness sequence that must complete before Copilot is enabled: oversharing baseline, sensitivity labelling, DLP guardrails, and a permissions baseline sign-off. It exists so organisations never enable Copilot into an ungoverned data estate. It does not configure production systems; it produces structured recommendations that data owners and security teams confirm.

When to use

  • An organisation is planning to enable Microsoft 365 Copilot for the first time.
  • Copilot is expanding to new user groups and the data estate for those users has not been assessed.
  • A periodic data readiness review is due for an active Copilot deployment.
  • An oversharing alert has been raised by Microsoft Purview DSPM and must be assessed before Copilot access continues.

When NOT to use

  • Copilot is already enabled and this is a routine operational review with no new user groups — use the periodic governance review workflow instead.
  • The matter is a data breach or security incident — route to the incident response protocol.
  • The organisation has not yet deployed Microsoft Purview or SharePoint Advanced Management — prerequisites are not met; this protocol cannot proceed.
  • You need live tenant configuration changes — escalate to the data owner; this protocol is recommendation-only.

Participating agents

  • m365-copilot-readiness-governance-agent (primary — oversharing assessment, sensitivity labels, DLP, permissions baseline)
  • m365-identity-zero-trust-agent (secondary — Conditional Access, identity-layer least privilege)
  • copilot-governance-maestro-agent (cross-pillar sign-off and final readiness gate)

Inputs required

  • Tenant-level SharePoint sharing settings and EEEU (Everyone except external users) status
  • Microsoft Purview DSPM Data Risk Assessment output (or permission to run one)
  • SharePoint Advanced Management (SAM) Content Management Assessment output
  • List of user groups proposed for Copilot enablement
  • Existing sensitivity label taxonomy and publishing scope
  • DLP policy inventory for Microsoft 365 workloads

Evidence required

  • Microsoft Purview is deployed and DSPM is active
  • SharePoint Advanced Management is licensed and configured
  • Sensitivity labels are published to users in scope
  • Purview Audit is enabled for Copilot interaction activity
  • A data owner is identified for each high-risk site

Workflow

  1. Oversharing baseline — Run (or review) the Microsoft Purview DSPM Data Risk Assessment and SAM Content Management Assessment. Identify sites with EEEU access, broken permission inheritance, ownerless sites, inactive sites, and sensitive content exposed broadly.
  2. Interim protections — Before remediating, apply SAM Restricted Content Discovery (RCD) to exclude high-risk sites from Copilot discovery. Apply Purview DLP policies scoped to the Copilot location to exclude sensitive content from grounding.
  3. Sensitivity label review — Confirm that sensitivity labels are published to all users in scope. Identify content lacking labels on high-risk sites. Draft labelling recommendations for data owners.
  4. Permissions remediation — For sites flagged as high-risk: remove excessive access and company-wide sharing links, correct broken inheritance, rescope sharing to approved users or groups, confirm site ownership.
  5. Gate 1 — Oversharing remediation sign-off — Confirm that all critical-risk sites have been remediated or have accepted interim protections. Do not proceed to Copilot enablement without this sign-off from the data owner and copilot-governance-maestro-agent.
  6. Identity layer check — Invoke m365-identity-zero-trust-agent to confirm that Conditional Access policies for Copilot users enforce MFA and device compliance. Flag any gaps.
  7. DLP guardrails — Confirm DLP policies cover the Copilot location and are actively monitoring sensitive content interactions. Validate Insider Risk Management (IRM) adaptive protection is configured for high-risk users.
  8. Gate 2 — Permissions baseline — Produce a permissions baseline document: confirmed label coverage rate, EEEU status, high-risk site count (open vs. remediated), DLP policy coverage. This is the minimum viable baseline before Copilot enablement.
  9. Copilot readiness recommendation — copilot-governance-maestro-agent produces a go / conditional-go / no-go recommendation per user group. Conditional-go requires time-bound remediation commitments.
  10. Human confirmation — Route the readiness recommendation to the data owner, security team, and Copilot programme owner for final sign-off. This protocol never enables Copilot autonomously.

Decision gates

Gate Condition Action
Oversharing baseline Purview DSPM or SAM assessment not run Block enablement; run assessment first
Critical-risk sites unmediated High-risk sites without interim protection or remediation Block enablement; apply RCD and DLP interim controls
EEEU active at tenant level Everyone except external users enabled tenant-wide Escalate to SharePoint admin; recommend disabling before enablement
Sensitivity label gap >20% of content on high-risk sites lacks labels Require labelling sprint before go-live
Identity layer gap MFA or device compliance not enforced for Copilot users Invoke m365-identity-zero-trust-agent; hold enablement

Refusal triggers

  • Hard refusal: do not recommend Copilot enablement without an oversharing baseline. This is unconditional.
  • Stop if the Purview DSPM assessment has not been run — do not substitute manual estimates for a real assessment.
  • Stop if credentials, tenant IDs, or customer PII are requested to perform this assessment — refuse and escalate.
  • Stop if the data owner cannot be identified for a critical-risk site — flag as a blocker; do not proceed past Gate 1.

Handoff rules

  • All handoffs carry: tenant_scope, skill_id, skill_version, invoked_by, oversharing_risk_level, label_coverage_rate, gate_status, open_questions, do_not_do_list.
  • Gate 1 sign-off must include the data owner name/role, the date, and a statement of residual risk accepted.
  • copilot-governance-maestro-agent's readiness recommendation is the final cross-pillar artefact; it must not be bypassed.

KPIs

  • Oversharing risk sites: critical / high / medium count (pre- vs. post-remediation)
  • Sensitivity label coverage rate (% of files on high-risk sites labelled)
  • EEEU status: tenant-level and site-level
  • DLP policy coverage for Copilot location
  • Time from assessment to enablement (days)

References

Files (vanguard-frontier-agentic)
  • references
    • workflow-and-output.md 11.6 KB
      # Copilot Data Readiness Protocol — Workflow and Output Contract
      
      ## Detailed Workflow
      
      ### Phase 1: Oversharing Baseline
      
      **Trigger**
      An organisation is planning to enable Microsoft 365 Copilot for a new user
      population, or a periodic readiness review has been initiated.
      
      **Step 1.1 — Purview DSPM assessment**
      Run (or review the most recent) Microsoft Purview Data Security Posture
      Management (DSPM) Data Risk Assessment. Identify:
      - Sites with sensitive data exposed to broad audiences (EEEU, company-wide links)
      - Risky sharing links (Anyone links, organisation-wide links on sensitive sites)
      - Content frequently accessed by large audiences that contains sensitive data
      - Oversharing posture score
      
      If the DSPM assessment has not been run: stop. Require the data owner to
      initiate the assessment before this protocol proceeds.
      
      **Step 1.2 — SAM Content Management Assessment**
      Run (or review) the SharePoint Advanced Management (SAM) Content Management
      Assessment. Identify:
      - Sites with oversized audiences
      - EEEU usage at site or folder level
      - Broken permission inheritance (files or folders with unique permissions
        broader than the parent site)
      - Inappropriate sharing (external sharing on internally-classified sites)
      - Inactive or ownerless sites
      
      **Step 1.3 — High-risk site inventory**
      Produce a ranked inventory of high-risk sites. Classify as:
      - Critical: sensitive content + EEEU or Anyone links
      - High: sensitive content + broad internal sharing
      - Medium: oversharing without confirmed sensitive content
      - Low: inactive/ownerless without confirmed sensitive content
      
      ---
      
      ### Phase 2: Interim Protections
      
      **Step 2.1 — SAM Restricted Content Discovery**
      For all critical and high-risk sites not yet remediated, apply SAM Restricted
      Content Discovery (RCD) to exclude them from Microsoft 365 Copilot discovery.
      Validate via Purview Auditing that Copilot is no longer surfacing content from
      these sites.
      
      **Step 2.2 — DLP for Copilot location**
      Configure (or confirm) Microsoft Purview DLP policies scoped to the Copilot
      location. These policies should exclude sensitive content from Copilot
      grounding. Validate policy coverage against the high-risk site inventory.
      
      **Step 2.3 — EEEU tenant-level check**
      Confirm whether EEEU is enabled at the tenant level in SharePoint. If yes:
      escalate to the SharePoint admin as a high-priority remediation item. Recommend
      disabling EEEU before Copilot enablement.
      
      ---
      
      ### Phase 3: Sensitivity Label Review
      
      **Step 3.1 — Label taxonomy check**
      Confirm that a sensitivity label taxonomy is configured and published in
      Microsoft Purview. Verify that labels are published to all users in the Copilot
      enablement scope.
      
      **Step 3.2 — Label coverage on high-risk sites**
      For critical and high-risk sites: assess the percentage of files that carry a
      sensitivity label. If label coverage is below the agreed threshold:
      - Draft labelling recommendations for the data owner.
      - Flag as a conditional readiness blocker (not a hard block if interim
        protections are in place, but must be resolved before interim protections
        are lifted).
      
      **Step 3.3 — Legacy IRM content**
      Identify any content using legacy Information Rights Management (IRM) protection.
      Flag for migration to Microsoft Purview sensitivity labels, as IRM-protected
      documents are not used in Copilot grounding.
      
      ---
      
      ### Phase 4: Permissions Remediation
      
      **Step 4.1 — High-risk site remediation tasks**
      For each high-risk site identified in Phase 1, produce a remediation task list:
      - Remove EEEU and company-wide sharing links
      - Rescope sharing links to approved users or groups
      - Correct broken permission inheritance at library and folder level
      - Confirm site ownership (assign or confirm a site owner)
      
      **Step 4.2 — SAM site access reviews**
      For sites where the data owner needs to manage access, initiate SAM site access
      reviews. Site owners review down to the file level and take the recommended
      actions.
      
      **Step 4.3 — Interim protection lifecycle**
      Once a site is fully remediated, remove the SAM RCD exclusion and Copilot DLP
      exclusion for that site. Validate via Purview Auditing that Copilot grounding
      now works as expected for that site.
      
      ---
      
      ### Phase 5: Gate 1 — Oversharing Remediation Sign-off
      
      **Required sign-off:**
      - Data owner confirms that all critical-risk sites are either remediated or have
        accepted interim protections with a time-bound remediation commitment.
      - m365-copilot-readiness-governance-agent attests that the oversharing baseline
        is established and the inventory is documented.
      
      If sign-off cannot be obtained: stop. Do not proceed to identity layer or DLP
      guardrails without this gate. This is a hard prerequisite for any Copilot
      enablement recommendation.
      
      ---
      
      ### Phase 6: Identity Layer Check
      
      **Step 6.1 — Conditional Access for Copilot users**
      Invoke m365-identity-zero-trust-agent to confirm:
      - Conditional Access policies enforce MFA for all Copilot-enabled users
      - Device compliance is required for access to Microsoft 365 Copilot workloads
      - No broad exceptions or exclusions exist for the Copilot user population
      
      **Step 6.2 — Identity layer gaps**
      If gaps are found: flag to the identity owner. Hold the Copilot enablement
      recommendation until m365-identity-zero-trust-agent confirms remediation.
      
      ---
      
      ### Phase 7: DLP Guardrails
      
      **Step 7.1 — DLP coverage validation**
      Confirm that Purview DLP policies:
      - Cover the Microsoft 365 Copilot location (Copilot interactions)
      - Are actively monitoring sensitive content interactions
      - Align with the sensitivity label taxonomy
      
      **Step 7.2 — Insider Risk Management**
      Confirm that Microsoft Purview Insider Risk Management (IRM) adaptive protection
      is configured to detect patterns of inappropriate or noncompliant Copilot usage
      and to automatically apply more restrictive policies to risky users.
      
      ---
      
      ### Phase 8: Gate 2 — Permissions Baseline
      
      Produce the permissions baseline document. This is the minimum viable sign-off
      before any Copilot enablement recommendation:
      
      | Metric | Status |
      |---|---|
      | DSPM assessment run | yes / no |
      | SAM assessment run | yes / no |
      | EEEU tenant-level status | enabled / disabled |
      | Critical-risk sites (open) | count |
      | High-risk sites (open) | count |
      | Sites with RCD interim protection | count |
      | Sensitivity label coverage (high-risk sites) | % |
      | DLP policy covers Copilot location | yes / no |
      | IRM adaptive protection configured | yes / no |
      
      ---
      
      ### Phase 9: Copilot Readiness Recommendation
      
      copilot-governance-maestro-agent reviews the permissions baseline and produces
      a per-user-group recommendation:
      - **Go**: oversharing baseline complete, interim protections in place or
        remediated, identity layer confirmed, DLP guardrails active.
      - **Conditional-go**: enablement permitted for the user group with time-bound
        remediation commitments for residual gaps.
      - **No-go**: critical prerequisites not met; Copilot must not be enabled.
      
      ---
      
      ### Phase 10: Human Confirmation
      
      Route the readiness recommendation to the data owner, security team, and Copilot
      programme owner for final sign-off. This protocol never enables Copilot
      autonomously.
      
      ---
      
      ## Decision Tree
      
      ```
      Copilot enablement requested for user group
        └── DSPM assessment run?
              ├── No  → Stop; require data owner to run assessment
              └── Yes → High-risk sites identified?
                          └── Interim protections applied (RCD + DLP)?
                                ├── No  → Apply RCD + DLP before continuing
                                └── Yes → EEEU at tenant level?
                                            ├── Yes → Escalate to SharePoint admin; flag as high priority
                                            └── No  → Sensitivity label coverage meets threshold?
                                                          ├── No  → Flag as conditional blocker; continue with interim controls
                                                          └── Yes → Permissions remediation complete for critical sites?
                                                                        ├── No  → Continue with RCD protection; set remediation timeline
                                                                        └── Yes → Gate 1 sign-off obtained?
                                                                                      ├── No  → Stop
                                                                                      └── Yes → Identity layer gaps?
                                                                                                    ├── Yes → Hold; route to identity owner
                                                                                                    └── No  → DLP guardrails confirmed?
                                                                                                                  ├── No  → Hold; configure DLP
                                                                                                                  └── Yes → Gate 2 permissions baseline
                                                                                                                                └── copilot-governance-maestro-agent readiness recommendation
                                                                                                                                      └── Human confirmation required
      ```
      
      ---
      
      ## Output Contract
      
      ### Readiness assessment record
      | Field | Type | Description |
      |---|---|---|
      | tenant_scope | string | User group or tenant segment assessed |
      | skill_id | string | `copilot-data-readiness-protocol` |
      | skill_version | string | `0.1.0` |
      | invoked_by | string | Agent or human who invoked this protocol |
      | assessment_date | ISO 8601 | Date of assessment |
      | dspm_assessment_status | enum | run / not-run |
      | sam_assessment_status | enum | run / not-run |
      | eeeu_tenant_level | enum | enabled / disabled / unknown |
      | critical_risk_sites_open | integer | Sites not yet remediated |
      | high_risk_sites_open | integer | Sites not yet remediated |
      | sites_with_rcd | integer | Sites with interim RCD protection |
      | label_coverage_rate | float | % of files on high-risk sites with sensitivity labels |
      | dlp_copilot_location | boolean | Whether DLP covers Copilot location |
      | irm_adaptive_protection | boolean | Whether IRM adaptive protection is active |
      | gate_1_status | enum | signed-off / not-signed-off |
      | gate_2_status | enum | baseline-complete / incomplete |
      | readiness_recommendation | enum | go / conditional-go / no-go |
      | open_questions | array | Unresolved questions |
      | do_not_do_list | array | Actions excluded from this protocol's scope |
      | timestamp | ISO 8601 | Protocol execution timestamp |
      
      ### Gate verdicts
      | Gate | Verdict options |
      |---|---|
      | Oversharing remediation sign-off (Gate 1) | signed-off / not-signed-off |
      | Permissions baseline (Gate 2) | complete / incomplete |
      
      ### Refusal record (when triggered)
      | Field | Description |
      |---|---|
      | refusal_reason | Which refusal trigger was hit |
      | escalation_target | Data owner / security team / SharePoint admin |
      | timestamp | ISO 8601 |
      
      ---
      
      ## Quality Assurance Notes
      - The oversharing baseline gate is unconditional. There is no path to a Copilot
        enablement recommendation that bypasses Gate 1.
      - DSPM and SAM assessments must be run — estimated or anecdotal oversharing
        assessments are not accepted as substitutes.
      - copilot-governance-maestro-agent's readiness recommendation is the final
        cross-pillar artefact and cannot be bypassed by any individual agent or owner.
      - This protocol does not execute SharePoint sharing setting changes, DLP policy
        changes, or Entra Conditional Access changes. All configuration changes
        require the relevant service owner.
      
  • metadata.json 2.4 KB
    {
      "id": "copilot-data-readiness-protocol",
      "name": "Copilot Data Readiness Protocol",
      "type": "skill",
      "provider": "generic",
      "harnesses": ["codex", "claude-code", "cursor", "gemini", "kiro", "other"],
      "summary": "Mandatory pre-enablement readiness protocol for Microsoft 365 Copilot. Runs an oversharing assessment via Microsoft Purview DSPM and SharePoint Advanced Management, applies sensitivity label and DLP controls, validates identity-layer Conditional Access, and confirms a permissions baseline before any user population is enabled. Hard refusal: Microsoft 365 Copilot must not be enabled without an oversharing baseline. All readiness recommendations require data owner, security team, and Copilot programme owner sign-off; this protocol never enables Copilot autonomously.",
      "source_type": "original",
      "official_docs": [
        "https://learn.microsoft.com/microsoft-365/copilot/secure-govern-copilot-foundational-deployment-guidance",
        "https://learn.microsoft.com/microsoft-365/copilot/configure-secure-governed-data-foundation-microsoft-365-copilot",
        "https://learn.microsoft.com/sharepoint/get-ready-copilot-sharepoint-advanced-management",
        "https://learn.microsoft.com/purview/data-security-posture-management-learn-about",
        "https://learn.microsoft.com/security/zero-trust/copilots/zero-trust-microsoft-365-copilot"
      ],
      "security_notes": "This protocol is a recommendation and orchestration aid only; it is never an authorisation to enable Microsoft 365 Copilot or to change data access permissions. Enabling Copilot without an oversharing baseline is a hard refusal — no exception. It never requests credentials, tenant IDs, or customer PII to perform assessments; all inputs are aggregate governance signals. Critical-risk sites without interim protection (SAM Restricted Content Discovery, Purview DLP) block the enablement recommendation until remediated or accepted by the data owner. Sensitivity label coverage and DLP guardrails must be confirmed by the data owner and security team before any go recommendation. Production SharePoint, Purview, or Entra configuration changes escalate to the relevant service owner. This protocol does not publish knowledge articles, modify sharing settings, or change Conditional Access policies autonomously.",
      "last_verified": "2026-06-16",
      "path": "skills/cross-functional/copilot-data-readiness-protocol",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.0"
    }
    
  • SKILL.md 8.2 KB
    ---
    name: copilot-data-readiness-protocol
    description: Use this skill before enabling Microsoft 365 Copilot for any user population. Runs an oversharing assessment, applies sensitivity labels and DLP controls, validates permissions baseline, and confirms a secure data foundation exists. Orchestrates m365-copilot-readiness-governance-agent as primary, m365-identity-zero-trust-agent for identity-layer controls, and copilot-governance-maestro-agent for cross-pillar sign-off. Hard refusal: Microsoft 365 Copilot must not be enabled for any user until the oversharing baseline is established and remediated. Never requests credentials, tenant IDs, or customer data. Production-impacting steps escalate to the relevant data owner or compliance team.
    allowed-tools: Read Grep Glob
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.0"
      updated: "2026-06-16"
      category: ai
      lifecycle: experimental
    ---
    
    # Copilot Data Readiness Protocol
    
    ## Purpose
    Microsoft 365 Copilot surfaces content that users already have permission to
    access. If that content is over-shared, unlabelled, or poorly governed, Copilot
    amplifies the exposure. This skill defines the mandatory readiness sequence that
    must complete before Copilot is enabled: oversharing baseline, sensitivity
    labelling, DLP guardrails, and a permissions baseline sign-off. It exists so
    organisations never enable Copilot into an ungoverned data estate. It does not
    configure production systems; it produces structured recommendations that data
    owners and security teams confirm.
    
    ## When to use
    - An organisation is planning to enable Microsoft 365 Copilot for the first time.
    - Copilot is expanding to new user groups and the data estate for those users
      has not been assessed.
    - A periodic data readiness review is due for an active Copilot deployment.
    - An oversharing alert has been raised by Microsoft Purview DSPM and must be
      assessed before Copilot access continues.
    
    ## When NOT to use
    - Copilot is already enabled and this is a routine operational review with no
      new user groups — use the periodic governance review workflow instead.
    - The matter is a data breach or security incident — route to the incident
      response protocol.
    - The organisation has not yet deployed Microsoft Purview or SharePoint Advanced
      Management — prerequisites are not met; this protocol cannot proceed.
    - You need live tenant configuration changes — escalate to the data owner;
      this protocol is recommendation-only.
    
    ## Participating agents
    - `m365-copilot-readiness-governance-agent` (primary — oversharing assessment, sensitivity labels, DLP, permissions baseline)
    - `m365-identity-zero-trust-agent` (secondary — Conditional Access, identity-layer least privilege)
    - `copilot-governance-maestro-agent` (cross-pillar sign-off and final readiness gate)
    
    ## Inputs required
    - Tenant-level SharePoint sharing settings and EEEU (Everyone except external
      users) status
    - Microsoft Purview DSPM Data Risk Assessment output (or permission to run one)
    - SharePoint Advanced Management (SAM) Content Management Assessment output
    - List of user groups proposed for Copilot enablement
    - Existing sensitivity label taxonomy and publishing scope
    - DLP policy inventory for Microsoft 365 workloads
    
    ## Evidence required
    - Microsoft Purview is deployed and DSPM is active
    - SharePoint Advanced Management is licensed and configured
    - Sensitivity labels are published to users in scope
    - Purview Audit is enabled for Copilot interaction activity
    - A data owner is identified for each high-risk site
    
    ## Workflow
    
    1. **Oversharing baseline** — Run (or review) the Microsoft Purview DSPM Data
       Risk Assessment and SAM Content Management Assessment. Identify sites with
       EEEU access, broken permission inheritance, ownerless sites, inactive sites,
       and sensitive content exposed broadly.
    2. **Interim protections** — Before remediating, apply SAM Restricted Content
       Discovery (RCD) to exclude high-risk sites from Copilot discovery. Apply
       Purview DLP policies scoped to the Copilot location to exclude sensitive
       content from grounding.
    3. **Sensitivity label review** — Confirm that sensitivity labels are published
       to all users in scope. Identify content lacking labels on high-risk sites.
       Draft labelling recommendations for data owners.
    4. **Permissions remediation** — For sites flagged as high-risk: remove
       excessive access and company-wide sharing links, correct broken inheritance,
       rescope sharing to approved users or groups, confirm site ownership.
    5. **Gate 1 — Oversharing remediation sign-off** — Confirm that all
       critical-risk sites have been remediated or have accepted interim protections.
       Do not proceed to Copilot enablement without this sign-off from the data
       owner and copilot-governance-maestro-agent.
    6. **Identity layer check** — Invoke m365-identity-zero-trust-agent to confirm
       that Conditional Access policies for Copilot users enforce MFA and device
       compliance. Flag any gaps.
    7. **DLP guardrails** — Confirm DLP policies cover the Copilot location and
       are actively monitoring sensitive content interactions. Validate Insider Risk
       Management (IRM) adaptive protection is configured for high-risk users.
    8. **Gate 2 — Permissions baseline** — Produce a permissions baseline document:
       confirmed label coverage rate, EEEU status, high-risk site count (open vs.
       remediated), DLP policy coverage. This is the minimum viable baseline
       before Copilot enablement.
    9. **Copilot readiness recommendation** — copilot-governance-maestro-agent
       produces a go / conditional-go / no-go recommendation per user group.
       Conditional-go requires time-bound remediation commitments.
    10. **Human confirmation** — Route the readiness recommendation to the data
        owner, security team, and Copilot programme owner for final sign-off.
        This protocol never enables Copilot autonomously.
    
    ## Decision gates
    
    | Gate | Condition | Action |
    |---|---|---|
    | Oversharing baseline | Purview DSPM or SAM assessment not run | Block enablement; run assessment first |
    | Critical-risk sites unmediated | High-risk sites without interim protection or remediation | Block enablement; apply RCD and DLP interim controls |
    | EEEU active at tenant level | Everyone except external users enabled tenant-wide | Escalate to SharePoint admin; recommend disabling before enablement |
    | Sensitivity label gap | >20% of content on high-risk sites lacks labels | Require labelling sprint before go-live |
    | Identity layer gap | MFA or device compliance not enforced for Copilot users | Invoke m365-identity-zero-trust-agent; hold enablement |
    
    ## Refusal triggers
    - Hard refusal: do not recommend Copilot enablement without an oversharing
      baseline. This is unconditional.
    - Stop if the Purview DSPM assessment has not been run — do not substitute
      manual estimates for a real assessment.
    - Stop if credentials, tenant IDs, or customer PII are requested to perform
      this assessment — refuse and escalate.
    - Stop if the data owner cannot be identified for a critical-risk site — flag
      as a blocker; do not proceed past Gate 1.
    
    ## Handoff rules
    - All handoffs carry: tenant_scope, skill_id, skill_version, invoked_by,
      oversharing_risk_level, label_coverage_rate, gate_status, open_questions,
      do_not_do_list.
    - Gate 1 sign-off must include the data owner name/role, the date, and a
      statement of residual risk accepted.
    - copilot-governance-maestro-agent's readiness recommendation is the final
      cross-pillar artefact; it must not be bypassed.
    
    ## KPIs
    - Oversharing risk sites: critical / high / medium count (pre- vs. post-remediation)
    - Sensitivity label coverage rate (% of files on high-risk sites labelled)
    - EEEU status: tenant-level and site-level
    - DLP policy coverage for Copilot location
    - Time from assessment to enablement (days)
    
    ## References
    - https://learn.microsoft.com/microsoft-365/copilot/secure-govern-copilot-foundational-deployment-guidance
    - https://learn.microsoft.com/microsoft-365/copilot/configure-secure-governed-data-foundation-microsoft-365-copilot
    - https://learn.microsoft.com/sharepoint/get-ready-copilot-sharepoint-advanced-management
    - https://learn.microsoft.com/purview/data-security-posture-management-learn-about
    - https://learn.microsoft.com/security/zero-trust/copilots/zero-trust-microsoft-365-copilot
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related