Copilot is ready. Is your data?

Copilot is ready. Is your data?


The pressure is familiar by now. The announcements are everywhere, the board has seen them, and somewhere on your desk is a proposal to enable Microsoft Copilot across the organisation. Perhaps the licences are already bought. The question has narrowed to how fast.

Here is the part that gets lost in the rush. Copilot is capable, and Microsoft has built a tool that works from the moment you switch it on. What decides whether it delivers is not the tool. It is the data it is pointed at.

Where that foundation was never made ready, the same pattern shows up: answers that cannot quite be trusted, adoption that never takes, and a productivity case that never arrives. Copilot readiness is a data problem, not a licensing one. The fix is well understood, and you cannot buy your way to it by adding more licences.

Copilot brings no knowledge of your business. It reads what it can reach — your files, your mailboxes, your databases — and it inherits, precisely, the permissions already in place. Where those permissions are loose, it surfaces content the reader was never meant to see. Where the data is stale or duplicated, it answers from whichever version looks relevant, in fluent prose, with a confidence the underlying data has not earned.

This is not a rare edge case, and it is not a criticism of the technology.

Readiness-first is the vendor’s own sequence

Microsoft says much the same thing. Its deployment blueprint for Copilot puts remediating oversharing first — ahead of guardrails, ahead of roll-out. Independent studies of enterprise generative-AI adoption reach a parallel conclusion: where returns disappoint, the cause usually lies in the conditions around the model, in how the data is governed and how well the tool is fitted to the work, rather than in the model itself.

In South Africa it is a compliance question too

Under Popia your organisation remains the responsible party for how personal information is accessed and used. That accountability does not transfer to a vendor, and certainly not to an AI. An assistant that can retrieve and redistribute personal information across the estate in seconds raises the obligation rather than easing it.

Readiness is a programme, not a switch

The instinct, faced with this, is to treat readiness as a quick tidy: clean up a few permissions, delete some old files, proceed. The opposite instinct is just as common, which is to freeze everything until the data is spotless. Neither serves you.

Copilot earns real value well before an estate is perfect, so the goal is narrower than it first appears. Govern the data each use case actually touches, before that use case goes live, and sequence the readiness to the roll-out.

That still takes deliberate work: understanding what data you hold and where it lives, modernising the platform it sits on, governing who can reach what, and cleaning the data so that what the AI retrieves is current, correct and permitted.

Microsoft has shipped stop-gaps, and the best known of them is now going away. Restricted SharePoint Search — the tenant-wide switch that held content back from Copilot while permissions were remediated — was closed to new enablement on 31 July 2026 and retires fully on 31 January 2027. Its replacement, Restricted Content Discovery, works per site rather than tenant-wide, and Microsoft will not migrate existing configurations across. Anyone who reached for the old control as a way of deferring the work now has a deadline rather than a reprieve.

Ascent Technology

The sequence matters as much as the steps. Modernise the platform so the data has a sound home. Optimise and govern access so that only the right people — and the right AI — can reach it. Protect the estate so that what Copilot reads is current, authorised and compliant. Done in the right order, that work compounds. Done piecemeal, it leaves exactly the gaps an AI will find first.

How Ascent delivers

Ascent’s Data Platform Modernisation is the programme that makes an organisation ready for AI. It begins with a structured assessment of the data estate — platform, integration, governance and access — and turns what is usually a scramble into a sequenced roadmap.

That assessment is the part clients feel first: a clear view of where the estate is exposed, what to remediate and in what order, so the work is prioritised by risk and value rather than guesswork.

From there we modernise the foundation itself, consolidating fragmented data, embedding governance and security into the platform rather than bolting them on afterwards, and putting in place the controls that decide what an AI is allowed to read.

Read: Your databases are being watched – just not by you

We build that foundation on Microsoft Fabric. Fabric’s OneLake gives an organisation a single, governed data estate — Microsoft’s own “AI-ready data foundation” — where access, lineage and quality are set once and enforced everywhere the data is used, Copilot included. It is the difference between an AI grounded on a trustworthy source and one guessing across a sprawl nobody has curated.

Because Ascent is a Microsoft Direct cloud solution provider, the Copilot and Azure licensing can sit with the same partner that builds the foundation beneath it. One accountable relationship for the licence and the readiness, rather than a tool bought in one place and a foundation neglected in another.

Read: The breach is in the database

Get it right and Copilot stops being a gamble. The business gets an assistant it can trust, an estate it can defend to the board and to the Information Regulator, and a head start that compounds while competitors are still cleaning up.

Modernise, optimise, protect — and then switch on.

Contact Ascent Technology

Contact Ascent to arrange a readiness assessment of your data estate: a structured review of your permissions, data quality and platform governance, before or alongside your Copilot roll-out, so that when the AI is switched on it reads from a foundation you can trust.