baref00t.io

// copilot assessments / copilot-interaction-compliance

Copilot Interaction Compliance Audit

Compliance teams need to know: is Copilot leaking sensitive data? This audit samples a tenant-wide window of Copilot interactions via the Microsoft 365 Copilot Interaction Export API, PII-pattern-scans them in memory (never persisting raw text), and scores compliance posture across PII density, sensitivity-label crossover, citation hygiene, conversation mix, and retention coverage.

One-off
$1,319

Single report, no commitment.

Monthly
$165/month

Continuous monitoring — fresh report every 30 days.

Available in AUD, USD, GBP, EUR, SGD. MSP partners get volume discounts via the partner programme.

What it scores

IC1

Volume & Cost

Interactions per surface, distinct users, heavy-user outliers (top 1%).

IC2

PII Pattern Density

Tax / SSN / credit card / health record / email pattern hits — zero-tolerance on financial identifiers.

IC3

Labelled Content Crossover

Responses citing sensitivity-labelled content above the requester’s clearance.

IC4

Citation Hygiene

Internal-citation share, external-web pollution rate.

IC5

Conversation Type Mix

BizChat vs in-app distribution; governance posture.

IC6

Retention Coverage

Confirms a Purview retention policy covers Copilot interaction artefacts.

Microsoft APIs

  • Copilot Interaction Export API (aiInteractionHistory: getAllEnterpriseInteractions)

Customer prerequisites

  • All 6 M365 Copilot service plans active
  • AiEnterpriseInteraction.Read.All scope