The layers of 'it knows me'
- Implicit personalisation — always-on: grounding is inherently personal (YOUR mail, YOUR meetings), and ranking favours your collaborators and current projects. Not a memory store; just the pipeline being user-scoped.
- Explicit memory — the feature: facts and preferences Copilot retains across sessions ('prefers tables', 'works on project Aurora'), user-visible and user-editable, with admin enablement controls at the org level.
- App-level state — Pages, chat history, notebooks: artifacts that FEEL like memory but are content in stores (governed as such — apps module).
The governance questions, answered in order
- Where does memory live? Within the user's M365 data footprint — it is user-scoped service data, not a shared brain; one user's memory never grounds another user's answers.
- Can the user see/edit it? Yes — the memory surface lists retained items with delete controls. Teach this in adoption: memory transparency is the antidote to creepiness.
- Can admins turn it off? Org-level enablement exists in the Copilot settings pages (control-system concept's lever list) — decide the stance WITH the works council where you have one, not after their letter.
- Leaver lifecycle? Memory follows the user's data lifecycle — offboard the account, the personalisation goes with it.
- eDiscovery? The durable, discoverable records remain the INTERACTIONS (security module); memory is preference state, but treat 'facts users tell Copilot' in awareness training — people will tell it things.
What to watch (proofs)
- The org stance: memory/personalisation toggles in admin center, dated screenshot + change alerts (same discipline as web grounding).
- The user surface: one pilot user's memory list — what accumulated in a month of real use; this artifact IS the works-council conversation aid.
- Cross-user isolation: user A tells Copilot a fake fact, user B prompts for it — silence proves the scoping claim in your own tenant.
- Awareness signal: helpdesk/DSPM indications of users confiding sensitive data to the assistant — the training-content trigger.