Direct answer
What data-governance work should precede a Copilot rollout?
Assess the information architecture and permissions that the service will inherit before expanding access. A Copilot rollout does not correct weak discovery boundaries, inconsistent ownership or unmanaged content. It makes those conditions more visible and potentially more consequential.
Scope: This article covers readiness questions before a rollout. Confirm current product behaviour and configuration options against primary Microsoft documentation for the tenant in scope.
What each rung costs to operate
Cost is the part of this argument most often waved away, so here are the published ones. Every figure below was read from Microsoft's own Australian pricing pages on 28 July 2026 and is cited at the foot of the piece. Prices move. The way you compare them does not.
Microsoft 365 Copilot is an add-on licence at AU$31.40 per user per month on an annual commitment, or AU$37.68 month to month, with a promotional AU$26.91 showing at the time of checking. All three exclude GST, as Microsoft's own pricing page states. Take the annual list price at a thousand seats and the licensed rung is a little under AU$377,000 a year excluding GST, recurring, before anybody has established whether the thousandth seat opens it. That is the number to hold next to a build estimate, because a build is usually quoted as a one-off and a licence never is.
Microsoft 365 Copilot Chat is a different product and requires no additional licence at all. It uses the web and lets users supply organisational data, rather than grounding on the tenant the way the licensed product does. That makes it the cheapest honest way to find out whether demand exists before buying seats, and skipping that step is how organisations end up measuring adoption after the invoice rather than before it.
Copilot Studio is sold as tenant-wide Copilot Credit packs of 25,000 credits at AU$299.30 per pack per month, available as a pre-purchase with a pay-as-you-go fallback, and it is included at no extra cost for users who already hold a Microsoft 365 Copilot licence when the agents they build are internal. That combination is the reason the middle rung is almost always cheaper than the argument in the room assumes, and it is why skipping it is an expensive habit.
The custom rung has no list price, and stating that plainly is more useful than inventing one. Its cost is not the build. It is the evaluation set, the release gate, the trace store, the identity model and the person who reads the alert at eleven at night, and those costs recur whether or not the system is being changed.
Where does the answer live?
A licensed copilot reaches what Microsoft Graph reaches. If the answer is in a document, a mailbox, a channel or a site, and the permissions on it are correct, that is the whole build. If the answer is a balance, a claim status, a policy in force at a date, or anything else held in a system of record behind a contract, an API or a nightly batch, no amount of licensing gets you to it. That is a retrieval and integration problem, not a licensing one.
Whose permissions apply?
Permission inheritance is the most useful property a licensed copilot has and the most misread. The answer returned is exactly what the person asking could already open, which is the right semantics when an employee is looking for something the organisation trusted them with anyway. It is the wrong semantics the moment the answer has to be assembled across entitlements no single person holds, or shown to somebody who is not the requester. Both of those are builds, and the reason is not capability. It is that the correct entitlement decision is no longer the requester's own.
Who is the user?
A tenant licence reaches people in the tenant. Customers, members, claimants and the public are not in the tenant, and no amount of internal success transfers. This test catches an entire class of programme that starts as an internal assistant, demonstrates well, and is then asked to face outward, at which point it is a different system with a different threat model, a different accessibility obligation and a different failure surface.