/
Services
/
AI and Copilot

Microsoft Copilot consulting that starts with your content

Copilot answers from the content it can reach. If that content is duplicated, out of date, badly structured or wrongly permissioned, Copilot will say so to your people – confidently, and in front of an audience. We find it, fix it, and get people using what you paid for. Before a rollout, or after one that disappointed.

We work on Microsoft 365 and we do not sell Copilot licences, so we have no reason to recommend more than you need.

In short

The real blocker

Not licensing or configuration. Copilot is only as good as the content and permissions behind it, and most organisations have not looked at either in years.

What we do

Assess whether your content is ready, fix what is not, then get people using it. Every engagement is scoped around what you already have.

The gap we fill

The Copilot project sits with IT. The content problem sits with comms, HR and operations. Nobody owns the join, and that is where rollouts fail.

What we are not

Not a licence reseller and not a security practice. We work alongside whoever handles those.

Where Copilot actually fails

Why does Copilot give wrong answers?

Almost always because of what it was asked to read.

Copilot does not know that the 2019 policy was superseded, that three teams keep separate versions of the same process, or that the site nobody has opened since a reorganisation is still full of confidently worded instructions. It reads what it can reach and answers from it. So the failure mode is not that it finds nothing – it is that it finds something plausible and wrong, and states it with the certainty of a correct answer. An employee burned by that twice stops using it, and no amount of training brings them back.

The other half is permissions, and Microsoft says this itself: Copilot surfaces any internal file a user has permission to view, exposing poorly managed SharePoint and OneDrive content. It respects permissions exactly – that is the problem, not a bug – and most organisations discover the true state of theirs the week Copilot goes live.

Both are content and information architecture problems, and they are what our SharePoint consultancy has been doing since 2005. It is the same work as making an intranet findable – audits, ownership, review cycles, taxonomy, metadata, structure. Copilot just made it urgent.

What one recent readiness audit found
1,179
Sites with no identifiable owner
8
Versions of the same policy live at the same time
11 years
Age of the oldest document still returned in search

Findings from a single anonymised Content Formula readiness audit. One organisation, not an average across engagements.

How we work

Microsoft Copilot consulting: assess, fix, adopt

Three things, in that order. Most suppliers selling Copilot readiness stop after the first.
Step 01

Access

What Copilot would say about your content today, and what it would surface that it should not.

No service commitments or monitoring. If you rarely need us, this is the honest answer.

Step 02

Fix

Remediate what the assessment found. The part most Copilot suppliers cannot do, and the part that takes the time.

Step 03

Adopt

Get the licences used, by the people who will get something from them, for jobs worth doing.

Not sure which of the three you need?

You can start at any of them. Organisations that have not deployed usually start at the first; those that deployed and were underwhelmed usually need the second. Tell us where you are and we will say which – or that you need less help than you think. If Copilot is one part of a bigger question, our digital workplace solutions cover the rest.

Step 01 - Access

Copilot readiness: the four areas we check

Four areas we work through before a Copilot deployment. Most organisations have a problem in at least two.

Area What we look for Why it matters for Copilot
Content quality Duplication, superseded versions, unowned content, material nobody has reviewed in years Copilot cannot tell current from obsolete. Whatever it reads, it will repeat
Permissions Oversharing, inherited access nobody intended, sites open to everyone by accident Copilot respects permissions precisely, which exposes exactly what should not have been shared
Structure and metadata Information architecture, taxonomy, tagging, whether documents carry any usable context Determines whether Copilot can distinguish a policy from a draft from a meeting note
Use cases and licensing fit Who would genuinely benefit, what they would use it for, and how many seats that actually needs Deciding this after buying licences is how organisations end up paying for shelfware

The output is a prioritised list of what to fix, what to accept, and what to fix later – not a report saying you are not ready. Everybody is partly not ready.

Step 01 - The engagement

What does a Copilot readiness assessment involve?

We scope each one around what you already have, because no two content estates are in the same state.

How we work
Scoped per organisation

The shape of a readiness engagement

Four strands run in parallel, then a playback to the people making the decisions.

  • Content and permissions review. What Copilot could reach, what state it is in, where oversharing exists
  • Structure and metadata. Whether there is enough context to distinguish a policy from a draft
  • Use case conversations. Who would benefit, for which tasks, and how many seats that needs
  • Playback. Findings and recommendations to the project team, with a shorter version for the board

What you come away with is a decision document rather than a report saying you are not ready – everybody is partly not ready. In practice that means knowing what Copilot would surface today, which content and permissions problems matter enough to fix before rollout, where Copilot would earn its licence first, and roughly how many seats that starting position needs.

How long it takes and what it costs depend on what you have. How much content, how many sites and systems it sits across, how much of it anyone can currently account for, and how many people need to be involved in deciding what happens to it. We would rather look at that and tell you than quote a number now and revise it later. If Copilot is not the immediate question, a digital workplace discovery is the broader version of the same exercise.

What we need from you

Read access to the environment, a project contact, and time with a handful of people across the functions that would use it. The research effort is ours.

Step 02 - Fix

Fixing what a Copilot readiness assessment finds

An assessment that hands you a list and leaves is half a service. Somebody has to do the work.

Every readiness assessment finds the same things: content nobody owns, competing versions of the same document, sites stranded by a reorganisation, a structure that made sense to whoever built it in 2016. The question that follows is who fixes it.

Most suppliers selling Copilot readiness are security and infrastructure practices – they will find the problem accurately and hand you a risk register. Remediating content needs people who can make editorial decisions, design an information architecture and get a business to agree ownership. A different discipline, and the one we have.

Content audit & rationalisation

What is current, what is superseded, what is duplicated, what should never have been published - then archive, merge or rewrite. Done with the people who own the subject matter rather than around them, which is the only version that holds.

Ownership & review cycles

Everything that matters gets a named owner and a review date. Without it the problem returns within about eighteen months, which is usually how it arrived.

Information architecture & taxonomy

A structure built around how people look for things rather than how the organisation appears on a chart. It determines whether Copilot can tell a policy from a draft from a meeting note.

Metadata & findability

Enough context on each document for a person or a model to know what it is, how current it is and whether it applies to them. The same territory as knowledge management, and the highest-leverage item here.

Done properly the result is not just a Copilot that answers correctly. It is content your people can find without asking anything at all – which is why this work outlives whichever AI tool you happen to be using.

Remediation can be scoped from our assessment or somebody else’s. If another supplier has produced a readiness report and you need people who can act on it, that is a reasonable place to start.

Step 03 - Adopt

Copilot adoption: already deployed and underwhelmed?

If Copilot is live and the usage figures are not what the business case promised, the cause is almost always one of three things – and none require starting again.

A licence is bought, an announcement goes out, a training session is recorded, and three months later a small group uses it daily while everyone else has forgotten it exists. Not a technology failure, and it happens for three reasons – all recoverable.

Worth knowing where the bar sits: Microsoft’s own adoption score counts somebody as an active Copilot user if they use it on three days in twenty-eight – roughly one day a week. That is the definition of healthy, not of good.

It was bought before anyone decided what for

Copilot in general is hard to adopt. Copilot for a specific job - drafting a particular kind of document, summarising a particular meeting - is easy. Use cases first, licences second.

It gave a bad answer early

Trust is lost faster than it is built. If the content underneath is not ready, the first fortnight does more damage than no rollout at all.

Training explained the tool, not the job

Showing people what Copilot can do is not the same as showing them what it can do for the work in front of them. The second one changes behaviour.

All three are avoidable before a rollout and recoverable after one. The fix is the same either way: decide the job before the seat count, and build adoption around the group who will actually use it first.

Facing a renewal you cannot justify? Find out which of the three you have before cutting the seat count. A rollout that underperformed because nobody defined the job is a different problem from one that failed because the content was not ready, and only one of them is solved by buying fewer licences.

Extension

Copilot Studio agents over your own content

An extension rather than a fourth step, and one that only works once the content underneath is in order. Copilot works across Microsoft 365; an agent answers from a defined set of your material, for a defined job.

A policy agent

Answers from the current version of your policies and only that. Useful anywhere a wrong answer has a compliance consequence.

A bid library agent

Answers from approved content rather than whatever a colleague last sent. Removes the reason people rewrite from scratch.

A service desk agent

Answers the questions your desk gets forty times a week, from your documentation rather than the open web.

Most agents ship with whatever interface came out of the box

That is the difference between an agent people use and one they try twice. We design how people actually ask, what the agent says when it does not know, and how it shows its working – so somebody can tell whether to trust the answer.

Same discipline as information architecture, applied to a conversation rather than a page. It is also the part almost nobody building agents is doing.

Built in Copilot Studio, agents stay inside your tenant and inherit your permissions – so everything above about content applies here, only more sharply. A narrow agent pointed at unreviewed material is worse than none. Where one needs engineering rather than configuration, that is SharePoint development work.

Where this is going

What happens to the intranet when AI is the interface?

Our view, and the reason content work matters more now rather than less.

"There is a view that AI makes the intranet redundant. The opposite is true. AI has made the intranet the single most valuable content asset an organisation has, because it is the layer that grounds AI in information people can trust." "Well governed intranets lower the risk of AI producing confident answers from content that is out of date, duplicated or simply wrong." "There is an upside beyond risk. When the intranet is properly structured, employees no longer have to explain their context in every prompt. Better still, AI can draw on context the employee wouldn't have thought to supply in the first place, from policies, guidance and institutional knowledge sitting across the organisation. That is where the real quality gain lies."

"Over time this becomes a genuine competitive advantage. Organisations that treat the intranet as their source of truth for AI will make better decisions, faster, with less risk. Those that don't will find that AI amplifies whatever mess was already there."
Dan Hawtrey
Dan Hawtrey
Chief Executive

We built this for ourselves before advising anyone else on it. Our own intranet is now the source our team’s AI tools answer from, connected through Model Context Protocol – we ask it rather than browse it – so we know first-hand which parts are straightforward and which are not.

Whether it suits you depends on your content, your tenant and which AI tools your people use, and it is a conversation worth having in its own right rather than bolted onto a Copilot rollout. Joe and Jeremy cover the practical end of it in AI search on your intranet.

Working together

How we fit alongside your Microsoft partner

You almost certainly have one. This is not a replacement – a Copilot rollout usually involves two or three suppliers anyway.

Your existing partner handles the tenant, licences, security posture and infrastructure. That is a real discipline and we are not it. What they rarely have is a content team – people who audit material, make editorial calls, design an information architecture and get a business to agree ownership. Those are the two halves of a Copilot rollout, and they need different people.

Your Microsoft partner

Licences and commercial terms. Tenant configuration and security posture. Data loss prevention, compliance tooling, threat protection. Identity and technical prerequisites. Azure and model-level development.

Content Formula

Content audit, ownership and review cycles. Information architecture, taxonomy and metadata. Permissions reviewed from a findability angle. Use case identification. Adoption and role-based enablement. Agents designed around how people actually ask.

On the permissions line

We will find oversharing and tell you where it is, because it directly determines what Copilot surfaces. Remediating tenant-wide security posture is a security practice’s job, and we will say so rather than pretend otherwise.

Who does the work

The Microsoft Copilot consultants who would be on this

Named practitioners rather than an account manager and a resourcing pool. The people who scope the work deliver it.

2006
John Scott

UX Director

Content, structure & findability

2014
Joe Perry

Technical Director

Copilot Studio, agents & integration

2019
Adam Hickman

Microsoft 365 consultant lead

Readiness & adoption

2005
Content Formula

Digital workplace consultancy

London

What makes a Copilot consultancy useful is not how early it adopted the product. It is whether it can fix what Copilot exposes – content nobody owns, structure nobody designed, permissions nobody has reviewed. That is what we have been solving as a digital workplace consultancy since 2005.

We have built with it as well as advised on it: AI search is shipped in both our own products – Lightspeed365 and Xoralia – and our own intranet runs the AI-source model described above. A different kind of credential from a badge, and the one we would rather be judged on.

Intranets, findability or content structure for

More of the work behind these in our SharePoint intranet case studies.

"Lots of organisations come to us having created an AI knowledge agent, but unsatisfied with the quality of answers that it provides. We help to improve the quality, clarity and completeness of the information that the agent has access to. This leads to far better experiences for employees, less wasted time and reduced compliance risk"
john scott 2
John Scott
UX Director
Google logo
Google review

My consulting firm hired Content Formula to advise us on a better approach to information management and redesign our SharePoint site to support the new approach. We had an exceptional experience, and came away very pleased with both how the project went and its results.

Find out what Copilot would say about your content

A conversation about what you have, who owns it and when anyone last looked at it. If the answer is that your content is in good order, you need less help than you think and we will tell you that.
Common questions

Microsoft Copilot consulting, answered

A Microsoft Copilot consultant helps an organisation get value from Microsoft 365 Copilot rather than simply switching it on. That covers assessing technical and content readiness, identifying the use cases where it will genuinely help, remediating the content and permissions problems that would otherwise produce wrong or overshared answers, supporting adoption so licences get used, and where relevant building custom agents in Copilot Studio. The consulting work that matters most usually happens before deployment, not after it.

Probably not entirely, and that is normal. Four things determine it: whether your content is current and owned, whether permissions reflect what you actually intend, whether there is enough structure and metadata for Copilot to tell a policy from a draft, and whether anyone has decided what people will use it for. Most organisations have a problem in at least two of those. The useful question is not whether you are ready but which gaps matter enough to fix before rollout.

Once you know what Copilot would say about your content, and not before. A Copilot deployment is technically quick – the licences switch on and the product works – which is exactly why so many organisations do it first and deal with the consequences afterwards. The sequence that works is to find out what it would surface today, fix the content and permissions problems that would produce wrong or overshared answers, then deploy to a defined group with a defined job rather than to everybody at once. Deploying to a pilot group while remediation is still running is usually sensible; deploying to the whole organisation while it is still running rarely is.

Because it is answering from content that is wrong, out of date or duplicated. Copilot has no way of knowing which version of a document is current, that a policy was superseded, or that three teams maintain separate versions of the same process. In one recent audit we found eight versions of the same policy live at the same time – Copilot is not choosing wrongly between them, it has no basis on which to choose at all. It reads what it can reach and answers with equal confidence either way. This is a content and information architecture problem rather than a Copilot problem, and it is fixable – but not by changing a setting.
Yes, and this is the issue most likely to cause a visible incident. Copilot respects existing permissions exactly, which means it will surface anything a user technically has access to – including content that was overshared years ago and never noticed because nobody was searching for it. A permissions review before rollout is considerably less uncomfortable than discovering the problem through a member of staff finding something they should not have.

It depends on how much content there is and how many places it sits. The things that move it are the number of sites and systems in scope, how much of the content already has an owner who can speak for it, and how many people need to be involved in deciding what happens to it. An organisation with a single well-governed tenant is a very different piece of work from one carrying fifteen years of accumulated SharePoint across several acquisitions. We would rather look at what you have and tell you than give you a number now and revise it later. Worth saying separately: the assessment is the short part. Remediating what it finds is the longer piece of work and it is scoped on its own.

It is scoped per engagement rather than sold as a fixed package, and it is driven by the same things as the duration – the size and state of the content estate, and how much of the work you want to do yourselves versus hand over. We do not take any margin on Copilot licences, so nothing in what we quote is subsidised by seats you may not need, and equally nothing is discounted by them. The most useful first step is a conversation about what you have, after which we can put a real number against it rather than a range that would not survive contact with your environment.

A security audit asks whether your tenant is configured safely. A Copilot readiness assessment asks whether your content will produce answers worth having. They overlap on permissions – oversharing is both a security and a findability problem – and diverge everywhere else. A security audit will not tell you that three teams maintain competing versions of the same process, that half your policy library has no owner, or that nothing carries enough metadata for Copilot to tell a policy from a draft. Those are what make Copilot confidently wrong, and they need a content and information architecture review rather than a security one. Most organisations deploying Copilot need both, usually from different suppliers.

No. We are not a licence reseller and we take no margin on Copilot seats, which means we have no reason to recommend more of them than you need. It also means we are free to say that a smaller initial rollout to the people who will genuinely use it is usually a better start than licensing everybody. You will buy licences through Microsoft or your existing licensing partner, and we will tell you how many we think you need.