Six months after the licenses were assigned, the Copilot questions stopped being about prompts. A business unit stood up its own agent over a site nobody had reviewed. Restricted SharePoint Search went on during the rollout as a temporary measure and is still on, capping the tenant at an allow list somebody built in a week. The AI Administrator role sits with whoever happened to run the deployment project, and that person moved to a different program in March. Nobody has opened the permission reports since launch, and the usage report shows a third of assigned seats have not touched Copilot in ninety days. None of that is a product defect. It is what happens when a deployment project ends and no operating model takes its place.

How do I hire a firm to provide ongoing governance and support for M365 Copilot post-deployment?

You hire a Microsoft delivery firm to build the governance program and then embed named specialists inside your own operating model, rather than a managed IT provider to take ownership of the tenant. Post-deployment Copilot governance is a control problem, not a help desk problem: who holds the AI Administrator role, which agents exist and who approved them, which SharePoint content is still discoverable to Copilot, and who reads the permission and audit reports on a schedule. The engagement builds those controls, writes the runbooks and the review cadence, and puts senior people alongside your administrators until your team runs it without help. i3solutions delivers under a partner-led engagement model with named accountability and governance that holds up under a client audit, as distinct from contractor-only staff augmentation.

That distinction decides what you put in the statement of work. Ask for managed operations and you get a ticket queue that inherits your problem. Ask for a governance program with embedded specialists and you get a named owner for every control, a cadence for every report, and a handover date.

1. What ongoing Copilot governance actually covers after go-live

Deployment ends when licenses are assigned. Governance starts at the four surfaces that keep producing decisions after that, and a credible firm will name all four in its scope of work rather than describing “Copilot support” in the abstract.

  • Tenant-level Copilot settings. Microsoft’s admin center guidance for Copilot states that when Copilot is available in a tenant, “you can configure some Copilot scenarios by using the Copilot Control System in the Microsoft 365 admin center”, organised across user access, data access, Copilot actions, and other settings. Those tabs are a standing configuration surface, not a one-time setup screen.
  • Content discoverability. What Copilot can see is what the requesting user can see. Microsoft’s Copilot overview states it plainly: “Copilot only shows the data that users have permission to access.” Every permission mistake in the estate is therefore a Copilot answer waiting to happen, which is why the permission reports belong on a review calendar.
  • Agent inventory and approval. Agents are not a separate product to be governed later. Microsoft describes them as “scoped or focused versions of Microsoft Copilot that act as AI assistants and can automate business processes”, and, on the developer side, is explicit that “When you build an agent, you’re also building an app for Microsoft 365.”
  • Audit and evidence. Microsoft’s Copilot setup guidance tells administrators to “Configure audit log retention: Set up retention policies to ensure that audit logs are retained for the required period based on your organization’s compliance needs” and to “Monitor and review logs: Regularly monitor and review audit logs to identify any suspicious activities or potential security threats.” Retention is a policy decision somebody has to own. Review is a recurring task somebody has to be scheduled for.

Two of those four are configuration and two are routines. The failure we see most often is an organisation that got the configuration right at launch and never built the routines, so the configuration decays quietly for a year.

2. Agent sprawl is the part that arrives after deployment

The agent count in most tenants is close to zero on the day Copilot goes live and is not close to zero six months later. Nothing about that is wrong. It is the point of the platform. What goes wrong is that nobody is counting, and no one has decided what approval means.

Microsoft ships the counting instrument. SharePoint Advanced Management includes a report described as “Get insights on agents in SharePoint: Use this report to identify recently created agents across SharePoint and OneDrive sites, and identify sites with the highest number of agents created.” Microsoft’s own framing of that product is worth reading before you scope any engagement: SharePoint Advanced Management “provides administrative governance controls for SharePoint and OneDrive”, and the documentation notes that “SAM capabilities are helpful as organizations prepare for Microsoft Copilot and agents.”

Approval is the harder half, and it is a policy question your firm should be forcing you to answer rather than answering for you:

  1. Who may create an agent, and where. A maker in a governed environment and a maker in the default environment are two different risk positions.
  2. What an agent may ground on. An agent scoped to a curated set of sites is a different object from one pointed at everything the creator can read.
  3. What connects to it. On the extensibility side, Microsoft notes that “Admins can disable this functionality on a user and group basis and control how individual plugins are approved for use, and which plugins are enabled.” That control only means something if someone is exercising it.
  4. What happens when the owner leaves. Agents outlive the people who build them, and an ownerless agent grounded on sensitive content is the artifact your auditor will find.
  5. Where agents built in Copilot Studio live. Those sit in Power Platform environments and inherit that estate’s controls. Microsoft describes managed environments as “a suite of premium capabilities that allow admins to manage Power Platform at scale with more control, less effort, and more insights.”

i3solutions governs client Power Platform tenants with the Center of Excellence Starter Kit, tenant-level and environment-level DLP policies, and managed environment controls. On a Copilot governance engagement that matters because the agent estate and the Power Platform estate are the same estate, administered from the same place, and a delivery firm that treats them separately will hand you two governance programs that disagree.

3. The oversharing problem does not close at launch, and one common control is retiring

Most enterprises turned on a temporary brake during rollout. Microsoft’s documentation on Restricted SharePoint Search is now unambiguous that it was never meant to be permanent, and that the product is going away: “Restricted SharePoint Search is retiring.” Microsoft directs organisations to “Use comprehensive data controls such as Restricted Content Discovery (RCD) for content discoverability.”

Two sentences in that same document are the reason this belongs in a governance engagement rather than in an admin ticket. Microsoft states that “it’s important to note that Restricted SharePoint Search isn’t a security boundary and doesn’t change any permissions on SharePoint sites”, and that “Restricted SharePoint Search limits to 100 sites, which isn’t sustainable as your organization scales Copilot and agentic operations.” An organisation that believes its allow list is a security control has a governance gap it cannot see, and it will keep believing that until somebody says otherwise in writing.

The path off it is a project with a beginning and an end. Microsoft’s own recommended sequence is to use SharePoint Advanced Management “to identify and remediate oversharing risks, such as broad access and unmanaged sharing”, to use Microsoft Purview “to apply data security and AI governance controls with sensitivity labels, data loss prevention (DLP), and auditing”, and only then: “After you validate permissions and governance controls, disable Restricted SharePoint Search.” Microsoft adds a change-management step most plans leave out: “Notify Copilot agent owners and your IT team that Copilot and agentic responses use existing SharePoint permissions.”

On the data side, Microsoft positions Purview as the standing surface rather than a one-off cleanup. Its documentation describes using “Data Security Posture Management or Data Security Posture Management for AI (classic) as your front door to discover, secure, and apply compliance controls for AI usage across your enterprise”, and makes the inheritance rule explicit for agents: “Where these AI apps support agents, they inherit the same security and compliance capabilities as their parent AI app.” The controls you set for Copilot are the controls your agents get, which is good news if you set them and bad news if you did not.

4. The operating model: a program you own, with specialists embedded in it

Ask three firms for ongoing Copilot support and you will get three different products back, and two of them will be managed IT operations wearing the word governance. The proposals look similar on page one and diverge completely on the page that describes who does what on a Tuesday.

An i3solutions engagement does not produce managed-service ownership, a replacement for the internal team, open-ended scope expansion, or vendor lock-in. What it produces is a governance program your own people run, built and then staffed alongside them:

  • A named control owner per surface. Copilot Control System settings, SharePoint permission and agent reports, Purview policy, and audit review each get one accountable person. Microsoft’s role guidance is the starting point: administrators “sign in with the AI Administrator role” to make changes to Copilot scenarios in the Microsoft 365 admin center, and “sign in with the Global Reader role” to view them. Most estates need more readers and fewer administrators than they start with.
  • A review cadence with named artifacts. Permission state reports, the agent inventory, license assignment against actual usage, and the audit log review, each on a stated interval, each producing a document somebody signs.
  • A change watch. This platform moves monthly. Microsoft says so directly, warning that “the Microsoft 365 admin center changes frequently” and telling administrators to “Stay up to date on the latest Copilot features, changes, and announcements by using the Message center in the Microsoft 365 admin center.” A governance program with no mechanism for absorbing product change is a document that expires.
  • Embedded specialists, for a stated period. A senior architect and a platform administrator working inside your cadence, not a queue you file tickets into. The measure of success is the date they are no longer needed.
  • An escalation path for the hard calls. Whether a site should be discoverable, whether an agent should be approved, and whether a label should encrypt are business decisions with technical consequences. They need an owner on your side and an advisor on ours.

If a prospective firm answers the operating-model question with a service level agreement and a ticket portal, they have understood you to be buying managed IT operations. That is a legitimate product. It is not this one, and buying it by accident is how organisations end up unable to explain their own tenant to an auditor.

5. What to expect from the engagement

Two i3solutions cost bands are relevant, and they price different things, so read the labels carefully before comparing them to a quote.

  • The ongoing governance program. Governance Subscription engagements run from $18,000 to $42,000 per quarter, refreshing the recommendation matrix as the estate evolves. That is the shape that matches a post-deployment Copilot governance program: standing control ownership, the recurring reviews, and senior availability as the platform and the estate change. It is a subscription to expertise and cadence, not to operations.
  • The readiness work, if it was skipped. An i3solutions Microsoft 365 Copilot readiness engagement typically runs $18,000 to $35,000. This prices the readiness assessment, which is a bounded pre-deployment exercise, not the ongoing program above. Plenty of organisations deploy first and need this work retroactively, and running it after the fact is cheaper than discovering the same findings through an incident.

The inputs that move either number are countable before you speak to anyone: tenant count, how many SharePoint sites are in scope for permission review, whether Restricted SharePoint Search is currently on, whether SharePoint Advanced Management and Purview are licensed, how many agents already exist, and whether a compliance framework has to be evidenced alongside the governance work. Of those, the one that moves the number hardest is the site count in scope for permission review, because it is the only input that scales with the size of the estate rather than with the size of the tenant. Everything else is a fixed cost you pay once.

Ask for the control owner map and the review calendar as named deliverables. A findings deck with no owner against each finding is an assessment, and you already had the assessment.

What to require of the firm you engage

A reseller and a managed services provider will both quote this work, and both will be selling something other than delivery. What separates the delivery firm you want, which is the shape i3solutions works in, is testable in the first conversation:

  1. They ask what your agent inventory looks like before they quote. A firm that prices Copilot governance without asking how many agents exist and where they are grounded is pricing a template.
  2. They name the handover date. Embedded specialists with no end state is staff augmentation wearing a governance label.
  3. They separate the discoverability remediation from the ongoing program. Getting off Restricted SharePoint Search is a project. Keeping permissions correct afterwards is a routine. One quote covering both without distinguishing them hides which part you are actually buying.
  4. They can operate what they design. Ask whether the same firm has run the controls it is recommending, in someone else’s tenant, on a schedule. Design that has never been operated tends to specify reviews nobody can staff.
  5. They cite Microsoft’s current documentation rather than their own deck. This product surface changed materially in the last year, and Restricted SharePoint Search is the proof: a firm still recommending it as a durable control is working from a deck written before the retirement notice.

i3solutions is a Microsoft Solutions Partner. Ask any firm you are evaluating to show the same, and to show it against the specific work you are buying rather than against a logo.

Frequently asked questions

Is this a managed service, or do we keep running Copilot ourselves?

You keep running it. An i3solutions engagement does not produce managed-service ownership, a replacement for the internal team, open-ended scope expansion, or vendor lock-in. The work builds the governance program, staffs it alongside your administrators while the routines take hold, and hands it over. If what you actually want is a provider to own tenant operations and a ticket queue, that is a managed IT services purchase and it should be scoped and priced as one, by a firm that sells it.

We deployed Copilot without a readiness assessment. Where do we start?

With discoverability and the agent inventory, in that order, because those are the two that produce incidents. Microsoft’s own adoption guidance points at the Copilot Optimization Assessment for exactly this gap, noting that “It evaluates your data governance maturity and data security controls.” Doing the readiness work after deployment is common and it is not wasted. The findings are the same findings, you just get them while people are already using the product, which raises the urgency and shortens the argument about whether the work is necessary.

Who inside our organization should own Copilot governance?

Split it deliberately rather than assigning it to one overloaded administrator. Microsoft’s own role separation is the model: change to Copilot scenarios requires the AI Administrator role, while viewing them requires only the Global Reader role, and Microsoft notes that “Lower permissioned accounts help improve security for your organization.” In practice a workable split is one accountable owner for tenant configuration, one for SharePoint content and permissions, one for Purview policy, and a business owner who decides whether an agent gets approved.

How do we keep track of agents people build?

Two things do it, a report and a rule, and a policy document is neither. The report exists: SharePoint Advanced Management can “identify recently created agents across SharePoint and OneDrive sites, and identify sites with the highest number of agents created.” The rule is yours to set, and it has to cover who may create agents, what they may ground on, and what happens when the owner leaves. Agents built in Copilot Studio also live in Power Platform environments, so the Power Platform controls you already have are part of the answer rather than a separate program.

What changes when we turn Restricted SharePoint Search off?

Search and Copilot results widen back out to whatever your permissions actually allow, which is why Microsoft’s sequence puts the remediation first and says “After you validate permissions and governance controls, disable Restricted SharePoint Search.” Microsoft also flags the human half of the change: “Notify Copilot agent owners and your IT team that Copilot and agentic responses use existing SharePoint permissions.” Expect user-visible changes in results on the day it goes off, and plan the communication before the switch rather than after the first surprised email.

What to bring to a scoping conversation

Four answers and thirty minutes are enough to size this honestly: whether Restricted SharePoint Search is currently on, whether SharePoint Advanced Management and Purview are licensed in your tenant, roughly how many agents exist today, and who holds the AI Administrator role right now. If the fourth answer is a name nobody is sure of, that is the finding, and it is usually where the engagement starts.

You do not need a proposal to leave that conversation with something useful. What you should get out of thirty minutes is the shape of the control owner map for your own tenant, a view of which of the two cost bands above your situation sits in and why, and a written distinction between the remediation project and the ongoing program that you can put in front of your own budget holder. If you are building an internal case rather than buying this quarter, that distinction is the part that survives the meeting, because it is the one your finance partner will ask about first and the one a managed-operations quote will blur.

Get a Microsoft 365 Copilot governance roadmap

Related