The control stack
| Level | Control |
|---|---|
| Org | Admin center Copilot settings: web grounding allowed / off for work prompts |
| User | Per-user toggle where org allows choice |
| Surface | Copilot Chat's web vs work framing keeps the modes visible to users |
| Contract | Web queries are handled under search terms, distinct from the M365 DPA — the fact your privacy review needs stated |
Picking a stance (the three defensible positions)
- On for everyone — maximum utility; accept that derived query terms from work prompts reach the search service. Right for most commercial estates; document the derived-query fact and move on.
- Off for regulated groups, on elsewhere — the common landing zone; pair with comms so the regulated group understands WHY their Copilot feels less current.
- Off org-wide — the sovereign stance; Copilot becomes purely tenant-grounded. Honest cost: 'current events' prompts get worse, and users route around via consumer tools unless BYO-AI policy holds (alternatives concept).
The indefensible position is not knowing which stance you're in — this toggle is precisely the kind of quiet default that surfaces in a regulator questionnaire.
What to watch (proofs)
- The stance as fact: the admin-center setting value, screenshot dated, + audit-log alerts on changes (control-system concept's lever list).
- Per-answer evidence: citations distinguishing web vs tenant sources — train reviewers to read them; it settles 'did this answer use the web'.
- The behaviour delta: same prompt with web on vs off (two test users) — the demo for the stance decision meeting.
- Routing-around signal: consumer-AI usage telemetry (DSPM for AI) rising in the groups you toggled off — the cost of stance 2/3, measured.