Download Corporate Calendar 2027 Download
Microsoft 365 Copilot is the most heavily marketed productivity tool of the past two years, and one of the most widely misunderstood. The marketing promises documents that draft themselves and meetings that summarise themselves. That part is true. What the marketing tends to leave out is that Copilot is only as useful as the data and permissions sitting underneath it — and in most Singapore organisations, those two things decide whether the licence is a bargain or an expensive novelty.
This article is the honest version: where Copilot genuinely earns its fee, what it cannot do, what it costs in Singapore dollars, and what to fix before you give it to anyone.
The difference is not branding. A general-purpose chatbot answers from public training data and knows nothing about your organisation. Copilot answers from your mailbox, your SharePoint sites, your Teams conversations and your OneDrive files, retrieved at the moment you ask and filtered by your own permissions. It is a retrieval system with a language model attached, not a model that happens to know about office work.
That grounding is why Copilot can summarise a meeting you missed and quote the client's actual email. It is also why it fails in a way general chatbots never do: when the underlying data is wrong, badly filed, or absent, Copilot confidently reproduces the problem. The tool does not have a data-quality problem. It has your data-quality problem, shown back to you in fluent prose.
This is where most Singapore teams get their money back first. Meeting recap, action-item extraction and "catch me up on this thread" remove work that is genuinely tedious, and they work well because the source material is already structured. If your team lives in Teams and Outlook, this is the use case to pilot, because the value is visible within a week and needs no process change.
Copilot is a strong first-draft machine and an excellent summariser of long documents. It is a mediocre final-draft machine. The sensible workflow is Copilot for the structure and the first pass, a human for the judgement and the numbers. Treat the draft as a draft and the time saving is real; treat it as output and you will publish something plausible and slightly wrong.
The genuinely underrated use is analysis: ask for the trend, the outliers, the pivot you would otherwise build by hand. For anyone whose day is spreadsheets, this is the feature that changes the arithmetic on the licence — not because it replaces analytical judgement, but because it removes the mechanical step between a question and a view of the data.
Copilot inherits your existing permissions exactly. It will not surface the HR folder you were never granted, and it will not respect a folder you were granted but should not have been. This is the most important sentence in this article: Copilot does not create permission problems, it reveals them.
There is no scepticism layer. If a stale policy document sits in a well-indexed SharePoint site, Copilot will summarise it as though it were current. Version discipline, retention labels and a clear "single source of truth" matter more after Copilot than before it.
Most organisations have years of accumulated oversharing: sites open to the whole company, links that "anyone with the link" can open, and files in the wrong library. That debt was invisible because nobody searched across it. Copilot searches across it by design. The uncomfortable audit is the most valuable thing the licence delivers — and it is better to run it deliberately than to discover it in a meeting recap.
Decide which sites Copilot should treat as authoritative and archive the rest. A smaller, cleaner index produces materially better answers than a large, polluted one — and the tidying has value on its own.
Audit every site and library for company-wide and anonymous sharing links. Anything a colleague can reach, Copilot can reach on their behalf. For most organisations this is where the real findings are.
Labels do not merely protect a document; they shape what Copilot can act on. Getting labelling in place before rollout is easier than retrofitting it across a tenant that has already been indexed.
Microsoft Graph exposes the same picture Copilot works from. This script lists every site and counts the sharing links that reach beyond the organisation — the oversharing Copilot would inherit.
import os
import requests
import msal
TENANT_ID = os.environ["AZURE_TENANT_ID"]
CLIENT_ID = os.environ["AZURE_CLIENT_ID"]
CLIENT_SECRET = os.environ["AZURE_CLIENT_SECRET"]
GRAPH = "https://graph.microsoft.com/v1.0"
app = msal.ConfidentialClientApplication(
CLIENT_ID,
authority=f"https://login.microsoftonline.com/{TENANT_ID}",
client_credential=CLIENT_SECRET,
)
token = app.acquire_token_for_client(scopes=["https://graph.microsoft.com/.default"])
if "access_token" not in token:
raise SystemExit(f"auth failed: {token.get('error_description')}")
session = requests.Session()
session.headers.update({"Authorization": f"Bearer {token['access_token']}"})
sites, url = [], f"{GRAPH}/sites?search=*&$select=id,displayName,webUrl"
while url:
response = session.get(url, timeout=30)
response.raise_for_status()
payload = response.json()
sites.extend(payload.get("value", []))
url = payload.get("@odata.nextLink")
print(f"{len(sites)} sites visible to Copilot")The second step is the one that produces findings: count the links on each site that reach outside the tenant.
RISKY = {"anonymous", "company", "organization", "users"}
for site in sites:
links, url = [], f"{GRAPH}/sites/{site['id']}/drive/root/permissions"
while url:
response = session.get(url, timeout=30)
if response.status_code == 404:
break
response.raise_for_status()
payload = response.json()
links.extend(payload.get("value", []))
url = payload.get("@odata.nextLink")
widened = [l for l in links if RISKY & set(l.get("roles", [])) or l.get("link", {}).get("scope") in RISKY]
if widened:
print(f"{len(widened):>4} broad links {site['displayName']} {site['webUrl']}")Run it, fix what it finds, then roll out. Doing it in that order turns a compliance worry into an ordinary housekeeping task — and it is the single highest-value hour in any Copilot deployment.
Copilot operates inside the Microsoft tenant, which is fine for most commercial work. It is the wrong instrument for material that contractually cannot be processed by a third-party service at all — client files under a strict confidentiality clause, regulated records, or anything your PDPA obligations require you to keep tightly scoped. No amount of configuration changes the fact that the data leaves your control and enters a provider's.
For that subset of work, a locally hosted model is now a practical answer rather than a hobbyist one. An open-weight model running on a modest machine handles summarisation, drafting and classification well enough for internal use, and the data never leaves the building. The trade-off is real — you maintain it, and quality trails the frontier models — but for a defined, sensitive workload it is often the right call.
import json
import urllib.request
def ask_local(prompt, model="qwen2.5:14b", endpoint="http://localhost:11434/v1/chat/completions"):
"""Send a prompt to a local OpenAI-compatible server (Ollama, vLLM, LM Studio)."""
body = json.dumps({
"model": model,
"messages": [{"role": "user", "content": prompt}],
"temperature": 0.2,
}).encode("utf-8")
request = urllib.request.Request(
endpoint, data=body, headers={"Content-Type": "application/json"}
)
with urllib.request.urlopen(request, timeout=300) as response:
payload = json.loads(response.read().decode("utf-8"))
return payload["choices"][0]["message"]["content"]
print(ask_local("Summarise these contract clauses in three bullet points: ..."))A six-person consultancy in Tanjong Pagar. Everything already lives in Outlook, Teams and one tidy SharePoint site. They buy four Copilot licences for the people who write proposals and run meetings. Bills improve, no process change is needed, and the pilot is over in a fortnight.
A forty-person firm handling client records under strict confidentiality. The same licence would be far more powerful — and far riskier, because the tenant has years of oversharing behind it. Here the order inverts: audit first, label second, buy licences third, and expect a meaningful slice of the work to stay off cloud tooling entirely.
Same product, same country, opposite conclusions. Data sensitivity and permission hygiene decide the answer long before model capability does.
Run it as a measurement, not a rollout. Week one: fix the sharing links the audit found. Week two: licence eight to twelve people chosen for variety, not seniority. Week three: measure time saved on meetings and first drafts, and log every answer that was wrong. Week four: decide — expand, hold, or stop. The wrong answers are more informative than the time saved; two or three confident errors tell you exactly which data needs cleaning.
Buying licences before cleaning the tenant. The audit is where the value sits; the licence is only the delivery mechanism. Reversed, you pay a subscription to discover your own oversharing.
Measuring enthusiasm instead of time. "Everyone loves it" is not a business case. Track the specific tasks that got faster and the specific answers that came back wrong — the second list is the one that tells you what to fix.
Treating the draft as the deliverable. Copilot drafts; people decide. Teams that skip the review step ship polished errors, and the first one that reaches a client costs more than the licence ever saved.
Copilot is a genuine productivity gain for teams whose files are already organised, in Teams and Outlook, and permissioned sensibly. For everyone else it is an audit with a subscription attached — valuable, but not in the way the marketing suggests. Fix permissions, label your data, pilot with measurement, and decide from evidence. The licence is the easy part; the data is the work.
If your team needs to build practical Copilot, Microsoft 365 and data skills rather than simply licence them, that is exactly what we train — hands-on, in small groups, with your own documents.
https://www.cbs.com.sg/microsoft-365-copilot-what-it-really-does-for-a-singapore-team/
copy