Before rolling Copilot out across your business, check the work you want it to do, the information staff can access, the technical setup and who will manage the pilot. An eligible subscription is only part of that decision.
This Copilot readiness checklist helps business owners, operations managers and IT teams gather the evidence, identify gaps and decide what to do next. It is designed for growing Australian businesses, including teams of around 20–200 staff.
If you need help assessing your environment or planning implementation, explore Stanfield IT’s AI consulting and managed AI services.
What does Copilot readiness mean?
Copilot readiness means your business has the technical access, information controls and working practices needed for its intended use. You should be able to explain the task, the data involved, who is responsible and how you will judge the result.
Microsoft’s documentation now calls Microsoft 365 Copilot Microsoft Copilot, although some licences and interfaces retain the previous name. This guide covers Copilot for work in the Microsoft 365 environment. Check the exact product and features in your proposal. Microsoft product overview
A key consideration is existing access. Microsoft explains that Copilot surfaces organisational information the individual user has permission to view. If a confidential document is already shared too broadly, AI can make it easier to find and summarise. Reviewing those permissions is therefore part of preparing for a rollout. Microsoft data and security guidance
Your Copilot readiness checklist at a glance
Use the table to start a conversation with your IT team or provider. Record evidence and an owner for each check. An unanswered question should remain not confirmed until somebody verifies it.
| Check | Evidence to request | Suggested owner | If unresolved |
|---|---|---|---|
| 1. Useful business task | Task, frequency, current effort and intended users | Business sponsor | Define the task |
| 2. Product and licences | Selected experience, features and entitlements | IT or licensing lead | Verify the arrangement |
| 3. Technical setup | App, account and network checks | IT lead | Resolve feature blockers |
| 4. Sensitive information | Relevant locations and business owners | Data owners | Map information and owners |
| 5. Permissions | Access findings and verified corrections | IT and data owners | Correct and verify access |
| 6. Identity and devices | Controls appropriate to the proposed use | IT or security lead | Address material gaps |
| 7. Source quality | Approved, current information | Department owners | Confirm authoritative sources |
| 8. Information handling | Sharing, retention and protection decisions | IT and privacy lead | Resolve handling decisions |
| 9. Agents and connections | Approved extensions and data flows | IT or security lead | Restrict unreviewed connections |
| 10. People and review | Training, output checking and escalation | Pilot owner | Train and assign reviewers |
| 11. Pilot boundaries | Participants, scope and stop procedure | Sponsor and IT | Agree and verify the plan |
| 12. Value and costs | Baseline, quality measures and full costs | Sponsor and finance | Set measures before expansion |
These checks combine technical requirements, recommended safeguards and business decisions. They are a planning aid, not a Microsoft certification or a guarantee that an environment is secure.
1. Choose a task worth improving
Start with a task people perform regularly: finding an approved procedure, drafting an internal document or preparing meeting follow-up.
Record how often it happens, how long it takes and what a good result looks like. Choose a business owner who can judge the output. If the task is unclear or rarely performed, resolve that before committing to a wider rollout.
2. Confirm the product and licence requirements
Use an organisation-managed work account and confirm whether the task needs Copilot Chat, particular in-app features or an approved agent. Ask your provider to identify the required subscriptions and any usage-based charges, and verify that the demonstrated features are available under the proposed arrangement.
Licensing varies across Copilot products. Business Premium is not the only eligible base plan, and eligibility alone does not confirm that your environment is ready. Check Microsoft’s current licence options.
3. Check that the intended features work
Your IT team should verify accounts, supported applications, update settings and network access for the selected users. Requirements depend on the features being used.
Test a representative task on the actual devices and applications involved. Microsoft publishes app and network requirements. Stanfield IT’s Microsoft 365 support services can help with the underlying environment.
4. Identify sensitive information and its owners
List the information relevant to the pilot and the sensitive material its users could potentially access. Include SharePoint, Teams, OneDrive and connected systems where applicable.
Assign owners for client records, financial information, personnel documents and other restricted material. Someone who understands the business purpose should approve access decisions; IT should not have to guess who needs a confidential document.
5. Review effective permissions
Ask for evidence of who can actually access the information. Review group membership, inherited permissions, broad sharing links and guest access.
Correct unintended access and verify the changes. Giving pilot users an instruction to “only use this folder” does not establish a technical boundary. The review needs to consider the access those users have through the selected Copilot experience, including relevant information beyond the intended working folder.
6. Check identity and device controls
Review how users sign in, how administrator access is managed and whether devices meet your agreed security requirements. Multi-factor authentication, appropriate access policies and device management should be considered in the context of the pilot.
Ask which controls are already operating, which need configuration and which require additional licences. Keep recommended protections distinct from Microsoft’s formal product prerequisites.
7. Prepare reliable source material
Outdated procedures and conflicting document versions make it harder to obtain useful answers.
Identify the authoritative source for the selected task and assign an owner to maintain it. Review duplicates and obsolete content, following retention requirements before deleting anything. Begin with the information the pilot needs, while separately addressing material access issues across the users’ relevant environment.
8. Agree how information will be handled
Decide what information staff may use, who may receive outputs and how prompts, responses and meeting material will be retained or reviewed.
Confirm the actual protection settings and vendor commitments for the chosen experience. Avoid assuming that an Australian tenant means all AI processing occurs in Australia. Check the relevant Microsoft data-residency commitments against your business requirements.
9. Review agents and connected services
If the pilot includes agents, connectors or other extensions, record their purpose, permissions and data flows. Establish who can approve them and who will maintain them.
Review web search settings and each relevant service’s terms and handling of business information. Treat an unreviewed integration as an unresolved item, even if the core Microsoft 365 environment is well managed. Microsoft explains these considerations in its enterprise data protection guidance.
10. Train people and assign output reviewers
Staff need practical guidance on permitted uses, sensitive inputs, checking answers and reporting mistakes. Define which outputs require approval before reaching a client or changing a business record.
Assign a support contact and an owner for improving the guidance. Your company AI policy should support this work, with examples staff can apply to their own tasks.
11. Set the pilot boundaries
Document the participants, approved tasks, data sources, excluded activities, support arrangements and review date. Agree how the pilot will be paused if a significant problem appears.
A smaller group helps manage learning and support. It does not repair excessive permissions. Verify the relevant technical boundaries before relying on them, and keep consequential decisions and actions subject to appropriate human approval.
12. Establish how value will be measured
Measure the complete task, including time spent checking and correcting the output. Record quality, staff use, support effort and any work that still needs manual handling.
Include software, preparation, training and ongoing support costs. Agree in advance who will decide whether to expand, adjust or stop. Microsoft’s adoption planning guidance also emphasises sponsorship, early adopters, training and monitoring.
Use the Copilot readiness worksheet
The accompanying worksheet gives your team a place to record the 12 checks, evidence references, responsible people, actions and decisions. It also includes a completed fictional example and a pilot-value calculator.
Mark each item confirmed, action required, not confirmed or not applicable—with a reason. Refer to evidence held in your business systems instead of copying passwords, client records or confidential documents into the worksheet.
Download the Copilot readiness worksheet.
What should stop or limit a Copilot pilot?
A missing answer matters most when it affects the proposed use. Avoid turning readiness into a percentage that lets several completed tasks outweigh one serious access problem.
| Decision | When it is appropriate |
|---|---|
| Ready for a limited pilot | The scope is defined, material access issues are addressed, users are prepared and accountable owners approve the plan. |
| Fix identified issues first | Unintended access, unverified boundaries or missing ownership would undermine the proposed pilot. |
| Specialist review needed | The business cannot establish the suitability of sensitive-data use, vendor arrangements or relevant obligations. |
For example, unclear formatting preferences may be resolved during a pilot. A confidential library unintentionally accessible to participants needs attention before those users start the affected use.
A limited pilot should also have a practical stop procedure: who receives a report, who can restrict access or suspend use, and how any exposed information or incorrect output will be handled.
A worked example for a 50-person business
Consider a professional-services firm with 50 staff. It wants five people to test drafting internal documents from approved procedures.
This is a fictional example to show the decision process. It is not a Stanfield IT client case study.
The initial review finds a remuneration library accessible through a broad staff group. The procedures also contain two conflicting versions. The business records the following actions:
| Finding | Owner and action | Evidence needed before proceeding |
|---|---|---|
| Confidential library accessible too broadly | IT and HR correct access without disrupting legitimate users | Verified effective access after the change |
| Conflicting procedure versions | Operations identifies the approved version and handles old copies under retention rules | Document owner and current source confirmed |
| No pilot review process | Sponsor defines participants, reviewers, support and success measures | Approved pilot plan |
The firm delays the affected pilot until the access issue is corrected and verified. It then confirms the remaining checks and authorises the agreed scope.
At the review date, the decision is based on observed results and unresolved issues. The original plan to involve five people does not commit the business to a company-wide rollout.
How to measure whether Copilot is worth expanding
Use a baseline from the current process and compare equivalent tasks. Count the effort required to produce a usable result.
The following calculation is illustrative:
| Measure | Example |
|---|---|
| Current time per task | 30 minutes |
| Time preparing the AI-assisted draft | 10 minutes |
| Time checking and correcting it | 8 minutes |
| Net time released per task | 12 minutes |
| Tasks completed each month | 40 |
| Monthly capacity released | 8 hours |
The calculation is 30 − 10 − 8 = 12 minutes per task. Across 40 tasks, that is 480 minutes, or eight hours.
These figures are assumptions, not promised savings. Released capacity may help staff complete other work; it becomes a cash saving only where a real cost is avoided.
Alongside time, review accuracy, missed information, customer impact and staff adoption. Compare the benefit with all incremental costs. A faster first draft may still be poor value if checking it takes too long or introduces unacceptable errors.
What should a Copilot readiness assessment include?
A professional assessment should give you a clear basis for a decision about the proposed use.
Before engaging a provider, ask for a written scope covering:
- The users, applications, information and integrations being examined.
- The checks and evidence to be collected.
- Findings, their significance and the recommended order of work.
- Actions that require a business decision or additional investigation.
- Responsibility for remediation, verification and pilot support.
- Deliverables, exclusions and separate implementation costs.
Microsoft’s admin readiness report can inform technical preparation. Treat it as one input. It does not replace a review of your actual permissions, business requirements and intended outcomes.
Avoid assuming that an initial conversation includes a full assessment or remediation. Agree those activities separately so both parties understand the work.
Copilot readiness FAQs
Do we need a readiness review before buying licences?
Review the intended use, licence requirements and material information risks before committing to a broad purchase. A limited, properly scoped pilot can help establish value, but its participants still need suitable access controls and guidance.
Can Copilot access confidential SharePoint files?
It can surface organisational information the user is authorised to access, subject to applicable controls. If confidential material is shared too broadly, review and correct that access. A “confidential” filename is not an access restriction. Microsoft security guidance
Do we need Microsoft 365 Business Premium?
Not necessarily. Microsoft lists several eligible base subscriptions. The required licences depend on the selected Copilot product, features and security controls. Ask for the complete proposed arrangement, including any additional subscriptions or usage charges. Microsoft licence options
Does having an AI policy make us ready?
A policy establishes expectations and accountability. Your IT team and information owners still need to confirm access, configuration, approved uses and how the pilot will be supported. Staff also need to understand and apply the policy.
Can we start with only a few staff?
Yes, where the scope and controls are appropriate. Choose participants who perform the selected tasks and can assess the results. Review their relevant access first and agree how problems will be reported and handled.
How long does a readiness assessment take?
It depends on the environment, scope and available evidence. The number of systems, condition of permissions, sensitive information and required stakeholder input all affect the work. Ask the provider to explain its assumptions and separate assessment time from remediation.
Discuss your Copilot rollout with Stanfield IT
Stanfield IT helps Sydney businesses connect AI adoption with Microsoft 365 administration, cyber security and practical business requirements.
Based in Frenchs Forest, we work with growing teams across the Northern Beaches and wider Sydney. Our AI consulting services can help assess use cases and readiness, while our AI governance and secure adoption services support appropriate policies and controls.
Bring one or two tasks you want to improve, the systems involved and any concerns about information access. We can discuss an appropriate next step. Detailed assessment, remediation and implementation work are scoped separately.