How to govern Microsoft 365 Copilot
The AI inside Outlook, Word, Excel, PowerPoint and Teams, and what changes when it starts acting on your data.
Microsoft · Reviewed monthly, and when Microsoft announces a capability change · Last reviewed 4 Sep 2026
Governance change Copilot in Excel can now write and run Python to transform, analyse and chart the data in a workbook. The person asks in plain language; Copilot generates and executes the code and puts the result in the sheet. Full changelog ↓How Microsoft 365 Copilot is used
We see seven common ways businesses use Microsoft 365 Copilot, and we govern each one on its own terms. If your team uses it differently, that is fine: you describe the use in your own words and Certrak works out the governance from what it actually does.
General productivity assistance
Consequence to people: LowDrafting, summarising, brainstorming, internal Q&A - day-to-day help with internal work
Meeting notes and transcription
Consequence to people: MediumRecording, transcribing, and summarising meetings, calls, or voice memos
Document analysis and review
Consequence to people: LowReviewing contracts, reports, or technical documents
Internal data analysis and insights
Consequence to people: MediumAnalysing business data, surfacing insights, building dashboards
Marketing content creation
Consequence to people: LowDrafting marketing copy, social posts, ads, blog content
Customer communications drafting
Consequence to people: MediumDrafting customer emails, support replies, or other outbound communications - reviewed before sending
Code generation and review
Consequence to people: LowWriting or reviewing code, with a developer in the loop
Governing Microsoft 365 Copilot in practice
- Name one person who owns Microsoft 365 Copilot in your business. Governance starts with a name.
- Write down what Microsoft 365 Copilot is used for. Certrak recognises 7 common uses: General productivity assistance, Meeting notes and transcription, Document analysis and review, Internal data analysis and insights, Marketing content creation, Customer communications drafting and Code generation and review. Yours may differ; write down yours.
- Decide what Microsoft 365 Copilot may and may not be given. Personal information is in scope for some uses; write the boundary down before it is needed.
- Agree that a person reviews every output before it is used, and name who.
- Microsoft 365 Copilot can run code or scripts without a person approving. Record which of these you allow, and who can change that.
- Look at this again every month, and sooner on any of these: industry incidents, vendor model updates, autonomy level changes and data classification changes.
What changed, and how Certrak responded
We record every check here, including the ones that changed nothing. A check that found no governance change proves we looked.
-
Governance change Vendor change
Use Python when editing with Copilot in Excel
Microsoft shipped it 25 Aug 2026.
Copilot in Excel can now write and run Python to transform, analyse and chart the data in a workbook. The person asks in plain language; Copilot generates and executes the code and puts the result in the sheet.
How Certrak responded: Where Copilot is used for internal data analysis, it can now run code without a person approving each step. Owners of those systems are asked whether this applies to how they use it; if it does, the system is treated as acting on its own and the agentic controls apply.
-
No governance change Scheduled review
Microsoft 365 Copilot release notes, August 2026
Microsoft shipped it 25 Aug 2026.
Reviewed the August release notes against Copilot's use patterns. New features extend where Copilot reads from and what it can do inside Excel; the recorded defaults already treat Copilot as reading internal and personal data with every output reviewed by a person.