LearnMicrosoft 365 Copilot › 3 · Governance & the Copilot Control System

Pilot to scale: the staged programme

Microsoft's own guidance says stage it; here is the staged model with actual GATES — the artifacts each stage must produce before the next spend, so the programme survives its first executive challenge.

Stage 0 — Readiness (before ANY seats beyond the trigger licence)

One Copilot licence unlocks the assessment tooling (SAM, DSPM for AI). Run: oversharing reports, DSPM posture scan, label-coverage baseline, the red-list containment (oversharing runbook steps 1-2). Gate artifact: the readiness report — sprawl numbers, containment done, red-team prompt test passing on the red list. No gate, no pilot.

Stage 1 — Pilot (a real cohort, not the IT team)

50-300 users across 2-3 workloads with heavy meeting/document gravity. Instrument from day one: usage dashboards on, task-level value capture (before/after time on recap, drafts, search), weekly prompt-of-the-week enablement (adoption concept), helpdesk tag live. Gate artifacts: utilisation ≥ target (pick it up front — e.g. 60% weekly active), 3+ quantified task wins, zero unresolved red-list findings, the what-users-ask FAQ v1 written from real tickets.

Stage 2 — Controlled scale

Wave deployment by role family (where the pilot proved value first), the oversharing runbook's institutionalise step running (access reviews, link policies — with your drift scanning watching the SPO settings), agent governance stood up BEFORE makers arrive (module 5: registry, approval flow, CA on agent identities). Gate artifacts: per-wave utilisation holding, seat-recycling loop live (unused seats reclaimed monthly), agent census reconciling.

Stage 3 — Steady state

Copilot as operated infrastructure: reliability playbooks (operations module), quarterly DSPM re-runs, renewal pack maintained continuously (value evidence + utilisation), curriculum-style user education always-on.

The two classic failure patterns this prevents

Big-bang seats ("we bought 5,000, why is usage 12%?") — no stage-1 value proof, no role targeting; and pilot purgatory (18 months of pilot, no gates defined, no scale decision possible). Gates are the cure for both directions.

What to watch (proofs)

  • The gate artifacts themselves — each stage's exit evidence in one folder; this IS the programme documentation an exec review wants.
  • Utilisation by wave over time (operations module's reports) — flat lines after a wave = role targeting wrong, pause the next wave.
  • Governance regression: oversharing metrics re-run each stage — scale amplifies whatever sprawl returned.
  • Seat recycling rate: reclaimed/month — the number that keeps the CFO an ally.

Discussion

No messages yet — start the thread.

Sign in with your email to join the discussion — we send a one-time link, no password.