Free tool · no email required

The Copilot Readiness Scorecard

Ten checks, answered yes / no / unsure, scored right here. The premise is simple and uncomfortable: an AI rollout is also a permissions audit, whether you planned one or not.

Copilot finds every file your permissions let it find.

Content & permissions — the risk half

1Broad sharing. Do you know how much content is shared org-wide ("Everyone" / "Everyone except external users") — and is that number deliberate?
2Sensitivity labels. Are sensitivity labels deployed AND actually applied to the content that matters — not just published and ignored?
3Permission reviews. Has anyone reviewed site and file permissions in the last year, on purpose?
4Stale content. Is there a plan for old content — archives, expired sites, the folder from 2016 — before an AI starts quoting it as truth?
5Ownership. Does every active site have a known owner who could answer "who should see this?"

Adoption & agents — the value half

6Use cases. Are your Copilot use cases prioritized by evidence of real work patterns — not by whoever asked loudest?
7Pilot design. If you're piloting: does the pilot have named users, defined scenarios, and a way to measure whether it worked?
8Adoption support. Is there training and support planned past the license purchase — the part that separates adoption from shelf-ware?
9Agent inventory. If agents are being built (Copilot Studio or elsewhere) — do you know what exists, who built it, and what it can touch?
10Agent rules. Are there rules for who may build agents and what they may access — proportional to what the agent can do?

What your score means

No JavaScript? No problem — add your points and read your band below.

8–10 yes · Ready-ish. Pilot with confidence — and keep governance moving at the same speed as adoption, because agents raise the stakes with every new permission they hold.
4–7 yes · Exposed. Fix the top of the risk half first: broad sharing and labels. Every "unsure" above is something Copilot will answer for you in production if you don't answer it first.
0–3 yes · Not yet. Licenses won't fix this order of operations. Readiness work first — then the rollout gets to be the success story instead of the incident report.

When you want it measured with evidence

This scorecard is a directional read — honest, but only as good as your answers. The Copilot & Agent Readiness Gauge replaces guesses with artifacts you keep:

  • Oversharing and permissions scan
  • Prioritized, evidence-based use cases
  • Agent governance gap list

$5,000 focused / $12,500 extended · 2 weeks (3 extended) · founder-led · fixed price