|
If you've been in a Copilot security conversation recently, you'll have heard some version of "these new dashboards are a data leak waiting to happen." I've been in that debate too. It's the wrong debate. Same scenario every time. A user opens a dashboard on a SharePoint site and can see data from a List they don't have permission to. If a user shouldn't see that data, they shouldn't have access to the file holding the dashboard. That's a permissions and information architecture problem. It was true before Copilot existed. The pattern of stashing files in Shared Documents where the whole org can open them isn't new. Copilot just made it visible at scale. Which is where SHAREPOINT.md earns its keep. Write the rule. Once. Everywhere.A markdown file at the root of your Agent Assets library. Copilot loads it into every chat, for every user, before responding to anything. One rule you write today shapes every future interaction on that site. Here are 3 types of rules worth writing this week. 1. Where things get saved The one I put in most sites that I architect at the moment... All HTML dashboards created on this site must be saved to the Reports library. No exceptions. Every user, every prompt, every session. The Reports library has the permissions your dashboards need. Copilot loads the rule and obeys. Now every dashboard your team generates lands where it should, not in Shared Documents where people that should not have access can see it. 2. Content rules The one that's saved a lot of red-face moments: Never include pricing in generated content. Pricing varies by retail channel. Never name competitors. Now when someone opens Copilot in the marketing hub and asks for a flyer, it politely leaves the pricing out and tells you why. The rule ran before the user finished typing. 3. Terminology The one that changes what the right answer even means: CPC on this site means cost per conversion, not cost per click. Calculated as spend divided by conversions. Same prompt, different answer. Without this line, "what's our CPC on TikTok this quarter?" returned 19 cents. With the line, it returned $61.89. Same file, same prompt, different definition of the thing being asked about. Why this pattern works 3 reasons SHAREPOINT.md beats the alternatives:
That's how governance actually works now. The IA point underneath all of this Copilot didn't make SharePoint less secure. The gaps were always there. Copilot just made them visible. Remember DELVE? A SharePoint site with clean permissions, sensible libraries, and a working IA does not have a dashboard-leak problem. A site with permissions inherited from a decade of ad-hoc sharing does. And it had that problem before Copilot arrived. SHAREPOINT.md doesn't fix the underlying IA. It gives you a way to encode the rules that stop the IA gaps from spilling into every generated artefact while you're cleaning them up. Write one rule this week. Just one. Pick the thing that most annoys you about how AI is behaving on a site right now, translate it into a plain-English rule, drop it in the file. Watch what happens on the next prompt. If you write one, hit reply and tell me which. I read every reply. Hope that brings you some value. Talk soon, Daniel PS: A quick litmus test for whether a rule belongs in SHAREPOINT.md. If you find yourself typing the same clarification into more than one Copilot chat this month, it belongs in the file. Every clarification you type twice is a rule you haven't written yet. |
Helping leaders and teams cut through the noise and make Microsoft 365 actually work for their business. I share - Strategic guidance on where Copilot delivers real value, SharePoint best practices for organising and governing content, plus Advisory insights that connect tools to business outcomes. Join thousands of CEOs, IT leaders, and professionals who are using these insights to work smarter, reduce complexity, and scale with confidence.
G’day there, I know you’ve got a business process you’d like to bring into SharePoint, or one you’re already managing there. You know what information belongs together and what needs to happen next. An app could give you one place to review those records, see what needs attention and make your updates. Copilot Cowork’s new /app skill lets you build that experience through conversation. You describe what you need, connect the data and refine the application as it takes shape. A lightweight CRM...
G'day, Here’s something I believe many organisations are getting wrong about AI and SharePoint: They think better AI means they no longer need to organise their content. If Copilot can read, reason and search across our documents, why should we still care about metadata, content types and information architecture? The answer became very clear during my recent conversation with Zach Rosenfield from Microsoft: AI doesn’t make information architecture obsolete. It makes good information...
G'day there... this is how I think AI skills should actually be built. Not by opening a SKILL.md file and trying to document the perfect process before you’ve done the work. Start by working through the process with AI. Then validate it, improve it and only package it as a skill once you know it works. A real example in SharePoint I recently demonstrated this using Copilot in SharePoint across two Microsoft Lists, this was from a real world client coaching session. Supplier invoices Purchase...