Zum Inhalt springen
Governance Sensitivity Labels Agent Identities Rollout

Governance before the rollout. Not after.

Copilot and agents are headed into the whole company — and you don't want to be left cleaning up what the rollout exposed afterward. We build the governance before go-live, not as a fix-up after the fact. For IT administrators, SharePoint and Teams admins, security teams, and IT managers.

Daniel Rohregger speaks in front of an audience, with a slide about the use-case-catalog process in the background
Infinity 365 Conference: which Copilot use cases actually pay off.

The typical mistake isn't technical: governance gets built only after the first agent is already running in the tenant. And yet the mechanism fits in one sentence — an agent inherits the access rights of the person it acts on behalf of, and so reaches exactly what's already reachable through SharePoint oversharing — more people have access to a document than was actually intended. That's why governance belongs before the rollout, not after.

For whom

Who's typically in the room

IT administrators
You manage M365 but are new to Copilot and agents — and want to know what an agent can do inside the tenant before it goes live.
SharePoint and Teams admins
You know the existing compliance structure inside out, but now need to build your own governance for Copilot and agents on top of it.
Security teams
Sensitivity labels, data classification, an oversharing audit — what used to be a compliance topic suddenly turns urgent with Copilot.
IT managers
You're planning a pilot or a full rollout and need a roadmap that's in place before go-live, not after.

The situation

The mistake is in the order

Rollout first — the usual way

  1. Roll out Copilot
  2. Agents spring up all over
  3. Oversharing comes to light
  4. Clean up afterward

Governance first — the one that holds up

  1. Tenant inventory
  2. Classify data
  3. Set guardrails
  4. Roll out in waves

You can tell by the situations that come up afterward. A Copilot agent goes live and reads files that, in principle, nobody outside a small circle should have access to — but technically has had access to for a long time. An agent acts “on behalf of the organization,” but nobody clarified beforehand who's liable when it does something wrong — the agent identity was never settled. Sensitivity labels, the confidentiality marking of a document as public, internal, or confidential, have often been sitting ready in the environment for a long time, but Copilot doesn't take them into account yet, or gets them wrong. A misconfigured agent reaches half the organization within hours, before anyone notices — its blast radius, the worst-case reach, simply wasn't bounded. And decentralized teams build their own agents connected to external systems via MCP servers — connections using the Model Context Protocol, through which an agent reaches tools and data outside M365 — without any central oversight, because nobody's watching.

On top of that, there's a question that has to be answered independently of your own tenant: the EU Data Boundary, Microsoft's commitment to process EU customers' data within the EU, determines where Microsoft is allowed to process the data at all. But it doesn't replace your own governance for access within the tenant — one governs the location, the other governs who sees what.

Where you start

Examples of where we help: Workflows and Control

For IT and admins, the usual entry point is stage 3: Workflows — automating processes end-to-end across system boundaries, instead of just using Copilot day to day. Running alongside it is the Control track — administration, configuration, governance — present at every level.

Workflows

For IT teams that want to put Copilot agents and processes into productive use across the tenant

  • Provide technical guidance through the agent rollout
  • Assess MCP servers and external connections
  • Set up monitoring and support processes for agents in production

Control

The side-track for IT and admins — not a stage of its own, but running across every level

  • Configure sensitivity labels
  • Fix SharePoint oversharing
  • Define agent identities and permissions
  • Separate governance layers — application, service, compliance

What we do

The ten-step readiness plan

Instead of theory about AI security: a plan you work through directly in your own tenant — applied to your real structure, not to a generic example.

Tenant inventory
How is the compliance structure really set up today: sensitivity labels, sharing settings, Teams channels.
SharePoint oversharing audit
Who has access to what, and is that still intentional? Oversharing means more people can see a document than was actually intended.
Data classification
Which information is public, internal, or confidential — the basis for every further decision in this plan.
Clarify agent needs
Which Copilot agents does the organization actually need, and which would just be a solution looking for a problem?
Set build rights
Who's allowed to build agents: centrally in IT, decentrally in the business units, or both with clear guardrails in between?
Separate governance layers
The application layer, service layer, and compliance layer each need their own rules, not one shared layer for everything.
Sharpen sensitivity labels
Enforce labels and require them on new documents, so they actually control what Copilot is allowed to use in an answer.
Define agent identities
Who is allowed to act on whose behalf — and how big is the blast radius, the worst-case reach, if this exact agent is misconfigured?
Assess MCP servers
Every connection to an external system via an MCP server — a protocol that opens tools and data sources outside M365 to an agent — gets its own risk assessment.
Wave planning for the pilot
Roll out in waves instead of all at once: first a small group with monitoring, then a department, then the whole organization — with a champion structure and a go-live checklist.

Which step comes first, we decide on your own tenant — following the same pattern as everywhere else in the coaching: Checkpoint, Route, and Doing.

An example

What a starting point looks like

Prompts and queries take shape in coaching using your own data. This one is the starting point for a SharePoint oversharing audit — in coaching, it gets tailored to your tenant, your roles, and your classification.

SharePoint oversharing audit

Look at the SharePoint sites where, according to the access list, more than ten people outside the actual team circle have access. Sort them first by sensitivity label, if one is set, otherwise by the number of people with access. Flag every site that carries a confidential label despite having access broader than ten people — that's the fix list for before the agent rollout.

Rolle: IT administration, security

Formats

Single session, package, or workshop

Here too, the difference is in the intent, not the price. The single session clarifies one concrete technical question. The ten-hour package prepares a whole pilot rollout. The governance workshop brings the entire IT team to one table — on your own tenant, not a sample one.

The three formats for IT and admins, by intent
FormatIdeal forOutcome
Single sessionOne concrete technical questionA clear answer and a next step
Ten-hour packageFull governance planning before a pilot rolloutGovernance documentation, implemented in your own tenant
Governance workshopThe whole IT team learns together on your own tenantA shared governance baseline and a clear rollout order

Kennenlern-Termin

Kostenlos

kostenlos 20 Min

Zwanzig Minuten, in denen wir klären, welches Format zu deiner Aufgabe passt — und ob eines davon überhaupt passt.

  • Deine Situation und dein nächstes Vorhaben durchsprechen
  • Einschätzung, welches Format dazu passt
  • Klare Antwort, wenn kein Format passt

Du weißt noch nicht, ob Einzelstunde, Paket oder Workshop das Richtige ist.

Einzelstunde

225 € netto 45 Min

Eine Coaching-Stunde an deiner echten Aufgabe. Danach läuft etwas.

  • Bestandsaufnahme deiner tatsächlichen Aufgabe
  • Gemeinsam gebauter Prompt oder Agent
  • Ergebnis, das am nächsten Tag benutzbar ist

Du hast eine konkrete Aufgabe und willst sie diese Woche vom Tisch haben.

Zehn-Stunden-Paket

2.250 € netto Zehn-Stunden-Paket

inkl. kostenlosem Onboarding-Call

Kostenloser Onboarding-Call, danach mindestens zehn Termine für einen gemeinsam ausgearbeiteten Lernplan — ohne festen Rhythmus, nach Bedarf abgerufen.

  • Kostenloser Onboarding-Call vorab, danach mindestens zehn Termine — Assessment, Lernplanung und Umsetzung
  • Eigene Prompt- und Agentensammlung am Ende
  • Zwischenstände schriftlich festgehalten

Du willst dich wirklich umstellen und danach selbst weiterbauen können.

Governance-Workshop

Nach Aufwand

auf Anfrage 1 Tag, IT-Team

Tenant-Größe und Governance-Stand bestimmen den Preis

Ein Tag mit deinem IT-Team am eigenen Tenant: Oversharing, Labels, Agent-Grenzen und die Reihenfolge des Rollouts.

  • Bestandsaufnahme des eigenen Tenants statt Beispiel-Tenant
  • Der zehnschrittige Readiness-Plan, auf eure Struktur angewendet
  • Priorisierte Liste dessen, was vor dem Rollout zu klären ist
  • Rollout-Reihenfolge mit benannten Verantwortlichkeiten

Mehrere Leute in der IT müssen dieselbe Entscheidungsgrundlage haben.

All formats compared, with the questions that come up regularly: Pricing and packages.

From the field

What came of it

Daniel supported us in rolling out M365 Copilot and, in individual sessions, highlighted and demonstrated the possibilities and benefits of AI with Microsoft for us.
Jörg Riha, Managing Director, Prinzing Elektrotechnik GmbH Aalen Company rollout

The focus was on a company-wide rollout: not a single automation, but individual sessions that show what Copilot and Microsoft AI concretely bring to your own company.

Governance before the rollout. Shall we get started?

Tell us where your rollout currently stands — a pilot in planning, mid-go-live, or still right at the start. We'll get back to you within two business days — with an assessment of which format fits your tenant, and an honest answer if none of them do.

Auch auf Deutsch verfügbar