The two-tab model
- Web tab — included for effectively everyone with M365: web-grounded chat with enterprise data protection (signed-in, your terms, prompts protected, not trained on) — the sanctioned alternative to consumer chatbots, which is its strategic job: give people a safe default.
- Work tab — lights up with the M365 Copilot seat: the full grounded pipeline over mail/files/meetings (foundations). Same window, entirely different data reach — the licensing map made visible in one UI.
Plus: agents live here — including custom engine agents usable by NON-seated users on credits (the agents module's strategy-shaping fact). For an unseated employee, Chat = safe web AI + the org's agents; that combination is most orgs' actual day-one AI platform.
Surfaces and rollout
Teams app (pinnable via app setup policies — the Teams curriculum's machinery), microsoft365.com/copilot, Edge/Windows entry points, and mobile (Copilot app + Teams mobile), all honouring the same tab split and MAM/CA (mobile module logic from Teams applies — BYOD prompts ride app protection).
Rollout moves that work: pin Chat for everyone (default AI = the governed one), brief the tab distinction explicitly (one slide: 'web tab knows the internet, work tab knows OUR stuff — the work tab needs the licence'), and route agent launches through Chat so unseated users feel value early.
What to watch (proofs)
- Who sees which tab: a seated vs unseated user side-by-side — the licensing map demo (and the screenshot for every 'we already have Copilot' meeting).
- Pinning coverage: app setup policy census (in the serv365 scan) — Chat pinned = adoption's cheapest lever, verifiable as config.
- EDP claim shown: the web tab's protected-session indicators — the artifact for 'is the free one safe' questions.
- Consumer-AI displacement: DSPM/BYO-AI telemetry trending down after Chat pinning — the strategy's success metric.