Coverage
Microsoft 365 Copilot
Copilot can reach everything your users can
That is the point of it, and it is also the problem. Copilot turns years of accumulated oversharing into fluent, cited answers. SAF3AI reads Copilot through Microsoft's own interfaces and shows you which data is genuinely reachable — before someone asks the question that surfaces it.
What you see
The telemetry we pull
Prompts and responses
Full interaction content across Word, Excel, PowerPoint, Outlook, Teams and Copilot Chat — what was asked, what was returned, and which documents grounded the answer.
Grounding and citations
The files, sites and mailboxes Copilot reached into to build each answer. This is where oversharing shows up: a citation nobody expected that user to be able to see.
Purview signals
Sensitivity labels, DLP verdicts and retention state, read natively rather than reimplemented — so your existing Purview classification drives AI policy too.
Copilot Studio agents
Low-code agents built by business teams: who published them, what connectors they hold, and which data sources they can reach.
Usage by person and app
Adoption and intensity per user and per surface — the baseline that makes an anomalous spike legible.
Admin and tenant events
Configuration changes, plugin and connector approvals, and licence assignments that widen what Copilot can reach.
How it connects
From zero to first signal
- 1
Register the connector in Entra ID
A guided wizard walks through creating the app registration and granting the read scopes. Nothing requires Global Administrator standing consent beyond the initial grant.
- 2
Choose your ingestion path
Graph change notifications push events to SAF3AI as they happen, or a Logic App forwards them via Event Hub if your tenant policy prefers that route. Both land in the same pipeline.
- 3
Connect Purview if you use it
Sensitivity labels and DLP verdicts are read through the native integration, so AI policy inherits the classification your compliance team already maintains.
- 4
Backfill and stream
Recent history is pulled so the picture is populated on day one, then events stream continuously with a durable watermark across restarts.
- 5
Users and files join the graph
People, mailboxes, sites, files, agents and connectors become entities — so an oversharing path is visible as a path, not inferred from a report.
Copilot Studio agent inventory requires the Power Platform admin scope. Purview signal enrichment requires an existing Purview deployment; without it, SAF3AI still classifies content with its own validated detectors.
What it catches
Risks specific to this surface
Oversharing at machine speed
Copilot inherits every permission a user has. A SharePoint site shared broadly in 2019 becomes an answer in 2026. The graph shows exactly which files are reachable by whom.
Regulated data in prompts and outputs
PHI, PCI and PII moving into and out of Copilot, detected with validated recognisers and mapped back to the sensitivity label on the source document.
Indirect prompt injection
Instructions planted in a document or email that Copilot then follows on the reader's behalf — including hidden text and bidirectional-override attacks.
Ungoverned Copilot Studio agents
Business-built agents wired to production connectors with no review. Every one is inventoried with the data it can reach and the identity it acts as.
Label and DLP drift
Documents whose sensitivity label no longer matches their content, surfaced when Copilot starts citing them in answers it should not.
Licence sprawl with no oversight
Copilot seats assigned to people or teams handling regulated data before controls were in place, with usage to match.
See Microsoft 365 Copilot in your own tenant
Connect this surface in a pilot and get a mapped inventory, a scored risk list and the attack paths that actually reach your data.