Copilot answers from the content it can reach. If that content is duplicated, out of date, badly structured or wrongly permissioned, Copilot will say so to your people – confidently, and in front of an audience. We find it, fix it, and get people using what you paid for. Before a rollout, or after one that disappointed.
We work on Microsoft 365 and we do not sell Copilot licences, so we have no reason to recommend more than you need.
The real blocker
Not licensing or configuration. Copilot is only as good as the content and permissions behind it, and most organisations have not looked at either in years.
What we do
Assess whether your content is ready, fix what is not, then get people using it. Every engagement is scoped around what you already have.
The gap we fill
The Copilot project sits with IT. The content problem sits with comms, HR and operations. Nobody owns the join, and that is where rollouts fail.
What we are not
Not a licence reseller and not a security practice. We work alongside whoever handles those.
Copilot does not know that the 2019 policy was superseded, that three teams keep separate versions of the same process, or that the site nobody has opened since a reorganisation is still full of confidently worded instructions. It reads what it can reach and answers from it. So the failure mode is not that it finds nothing – it is that it finds something plausible and wrong, and states it with the certainty of a correct answer. An employee burned by that twice stops using it, and no amount of training brings them back.
The other half is permissions, and Microsoft says this itself: Copilot surfaces any internal file a user has permission to view, exposing poorly managed SharePoint and OneDrive content. It respects permissions exactly – that is the problem, not a bug – and most organisations discover the true state of theirs the week Copilot goes live.
Both are content and information architecture problems, and they are what our SharePoint consultancy has been doing since 2005. It is the same work as making an intranet findable – audits, ownership, review cycles, taxonomy, metadata, structure. Copilot just made it urgent.
Findings from a single anonymised Content Formula readiness audit. One organisation, not an average across engagements.
How we work
What Copilot would say about your content today, and what it would surface that it should not.
No service commitments or monitoring. If you rarely need us, this is the honest answer.
Remediate what the assessment found. The part most Copilot suppliers cannot do, and the part that takes the time.
Get the licences used, by the people who will get something from them, for jobs worth doing.
You can start at any of them. Organisations that have not deployed usually start at the first; those that deployed and were underwhelmed usually need the second. Tell us where you are and we will say which – or that you need less help than you think. If Copilot is one part of a bigger question, our digital workplace solutions cover the rest.
Step 01 - Access
Four areas we work through before a Copilot deployment. Most organisations have a problem in at least two.
| Area | What we look for | Why it matters for Copilot |
|---|---|---|
| Content quality | Duplication, superseded versions, unowned content, material nobody has reviewed in years | Copilot cannot tell current from obsolete. Whatever it reads, it will repeat |
| Permissions | Oversharing, inherited access nobody intended, sites open to everyone by accident | Copilot respects permissions precisely, which exposes exactly what should not have been shared |
| Structure and metadata | Information architecture, taxonomy, tagging, whether documents carry any usable context | Determines whether Copilot can distinguish a policy from a draft from a meeting note |
| Use cases and licensing fit | Who would genuinely benefit, what they would use it for, and how many seats that actually needs | Deciding this after buying licences is how organisations end up paying for shelfware |
The output is a prioritised list of what to fix, what to accept, and what to fix later – not a report saying you are not ready. Everybody is partly not ready.
Step 01 - The engagement
We scope each one around what you already have, because no two content estates are in the same state.
Four strands run in parallel, then a playback to the people making the decisions.
What you come away with is a decision document rather than a report saying you are not ready – everybody is partly not ready. In practice that means knowing what Copilot would surface today, which content and permissions problems matter enough to fix before rollout, where Copilot would earn its licence first, and roughly how many seats that starting position needs.
How long it takes and what it costs depend on what you have. How much content, how many sites and systems it sits across, how much of it anyone can currently account for, and how many people need to be involved in deciding what happens to it. We would rather look at that and tell you than quote a number now and revise it later. If Copilot is not the immediate question, a digital workplace discovery is the broader version of the same exercise.
Step 02 - Fix
An assessment that hands you a list and leaves is half a service. Somebody has to do the work.
Every readiness assessment finds the same things: content nobody owns, competing versions of the same document, sites stranded by a reorganisation, a structure that made sense to whoever built it in 2016. The question that follows is who fixes it.
Most suppliers selling Copilot readiness are security and infrastructure practices – they will find the problem accurately and hand you a risk register. Remediating content needs people who can make editorial decisions, design an information architecture and get a business to agree ownership. A different discipline, and the one we have.
What is current, what is superseded, what is duplicated, what should never have been published - then archive, merge or rewrite. Done with the people who own the subject matter rather than around them, which is the only version that holds.
Everything that matters gets a named owner and a review date. Without it the problem returns within about eighteen months, which is usually how it arrived.
A structure built around how people look for things rather than how the organisation appears on a chart. It determines whether Copilot can tell a policy from a draft from a meeting note.
Enough context on each document for a person or a model to know what it is, how current it is and whether it applies to them. The same territory as knowledge management, and the highest-leverage item here.
Done properly the result is not just a Copilot that answers correctly. It is content your people can find without asking anything at all – which is why this work outlives whichever AI tool you happen to be using.
Remediation can be scoped from our assessment or somebody else’s. If another supplier has produced a readiness report and you need people who can act on it, that is a reasonable place to start.
Step 03 - Adopt
A licence is bought, an announcement goes out, a training session is recorded, and three months later a small group uses it daily while everyone else has forgotten it exists. Not a technology failure, and it happens for three reasons – all recoverable.
Worth knowing where the bar sits: Microsoft’s own adoption score counts somebody as an active Copilot user if they use it on three days in twenty-eight – roughly one day a week. That is the definition of healthy, not of good.
Copilot in general is hard to adopt. Copilot for a specific job - drafting a particular kind of document, summarising a particular meeting - is easy. Use cases first, licences second.
Trust is lost faster than it is built. If the content underneath is not ready, the first fortnight does more damage than no rollout at all.
Showing people what Copilot can do is not the same as showing them what it can do for the work in front of them. The second one changes behaviour.
All three are avoidable before a rollout and recoverable after one. The fix is the same either way: decide the job before the seat count, and build adoption around the group who will actually use it first.
Facing a renewal you cannot justify? Find out which of the three you have before cutting the seat count. A rollout that underperformed because nobody defined the job is a different problem from one that failed because the content was not ready, and only one of them is solved by buying fewer licences.
Extension
An extension rather than a fourth step, and one that only works once the content underneath is in order. Copilot works across Microsoft 365; an agent answers from a defined set of your material, for a defined job.
Answers from the current version of your policies and only that. Useful anywhere a wrong answer has a compliance consequence.
Answers from approved content rather than whatever a colleague last sent. Removes the reason people rewrite from scratch.
Answers the questions your desk gets forty times a week, from your documentation rather than the open web.
That is the difference between an agent people use and one they try twice. We design how people actually ask, what the agent says when it does not know, and how it shows its working – so somebody can tell whether to trust the answer.
Same discipline as information architecture, applied to a conversation rather than a page. It is also the part almost nobody building agents is doing.
Built in Copilot Studio, agents stay inside your tenant and inherit your permissions – so everything above about content applies here, only more sharply. A narrow agent pointed at unreviewed material is worse than none. Where one needs engineering rather than configuration, that is SharePoint development work.
Where this is going
Our view, and the reason content work matters more now rather than less.
We built this for ourselves before advising anyone else on it. Our own intranet is now the source our team’s AI tools answer from, connected through Model Context Protocol – we ask it rather than browse it – so we know first-hand which parts are straightforward and which are not.
Whether it suits you depends on your content, your tenant and which AI tools your people use, and it is a conversation worth having in its own right rather than bolted onto a Copilot rollout. Joe and Jeremy cover the practical end of it in AI search on your intranet.
Working together
You almost certainly have one. This is not a replacement – a Copilot rollout usually involves two or three suppliers anyway.
Your existing partner handles the tenant, licences, security posture and infrastructure. That is a real discipline and we are not it. What they rarely have is a content team – people who audit material, make editorial calls, design an information architecture and get a business to agree ownership. Those are the two halves of a Copilot rollout, and they need different people.
Licences and commercial terms. Tenant configuration and security posture. Data loss prevention, compliance tooling, threat protection. Identity and technical prerequisites. Azure and model-level development.
Content audit, ownership and review cycles. Information architecture, taxonomy and metadata. Permissions reviewed from a findability angle. Use case identification. Adoption and role-based enablement. Agents designed around how people actually ask.
We will find oversharing and tell you where it is, because it directly determines what Copilot surfaces. Remediating tenant-wide security posture is a security practice’s job, and we will say so rather than pretend otherwise.
Who does the work
Named practitioners rather than an account manager and a resourcing pool. The people who scope the work deliver it.
UX Director
Content, structure & findability
Technical Director
Copilot Studio, agents & integration
Microsoft 365 consultant lead
Readiness & adoption
Digital workplace consultancy
London
What makes a Copilot consultancy useful is not how early it adopted the product. It is whether it can fix what Copilot exposes – content nobody owns, structure nobody designed, permissions nobody has reviewed. That is what we have been solving as a digital workplace consultancy since 2005.
We have built with it as well as advised on it: AI search is shipped in both our own products – Lightspeed365 and Xoralia – and our own intranet runs the AI-source model described above. A different kind of credential from a badge, and the one we would rather be judged on.
More of the work behind these in our SharePoint intranet case studies.
My consulting firm hired Content Formula to advise us on a better approach to information management and redesign our SharePoint site to support the new approach. We had an exceptional experience, and came away very pleased with both how the project went and its results.
Consulting firm
A Microsoft Copilot consultant helps an organisation get value from Microsoft 365 Copilot rather than simply switching it on. That covers assessing technical and content readiness, identifying the use cases where it will genuinely help, remediating the content and permissions problems that would otherwise produce wrong or overshared answers, supporting adoption so licences get used, and where relevant building custom agents in Copilot Studio. The consulting work that matters most usually happens before deployment, not after it.
Probably not entirely, and that is normal. Four things determine it: whether your content is current and owned, whether permissions reflect what you actually intend, whether there is enough structure and metadata for Copilot to tell a policy from a draft, and whether anyone has decided what people will use it for. Most organisations have a problem in at least two of those. The useful question is not whether you are ready but which gaps matter enough to fix before rollout.
Once you know what Copilot would say about your content, and not before. A Copilot deployment is technically quick – the licences switch on and the product works – which is exactly why so many organisations do it first and deal with the consequences afterwards. The sequence that works is to find out what it would surface today, fix the content and permissions problems that would produce wrong or overshared answers, then deploy to a defined group with a defined job rather than to everybody at once. Deploying to a pilot group while remediation is still running is usually sensible; deploying to the whole organisation while it is still running rarely is.
It depends on how much content there is and how many places it sits. The things that move it are the number of sites and systems in scope, how much of the content already has an owner who can speak for it, and how many people need to be involved in deciding what happens to it. An organisation with a single well-governed tenant is a very different piece of work from one carrying fifteen years of accumulated SharePoint across several acquisitions. We would rather look at what you have and tell you than give you a number now and revise it later. Worth saying separately: the assessment is the short part. Remediating what it finds is the longer piece of work and it is scoped on its own.
A security audit asks whether your tenant is configured safely. A Copilot readiness assessment asks whether your content will produce answers worth having. They overlap on permissions – oversharing is both a security and a findability problem – and diverge everywhere else. A security audit will not tell you that three teams maintain competing versions of the same process, that half your policy library has no owner, or that nothing carries enough metadata for Copilot to tell a policy from a draft. Those are what make Copilot confidently wrong, and they need a content and information architecture review rather than a security one. Most organisations deploying Copilot need both, usually from different suppliers.
No. We are not a licence reseller and we take no margin on Copilot seats, which means we have no reason to recommend more of them than you need. It also means we are free to say that a smaller initial rollout to the people who will genuinely use it is usually a better start than licensing everybody. You will buy licences through Microsoft or your existing licensing partner, and we will tell you how many we think you need.