The record model
Copilot interactions — prompt, response, and referenced-resource pointers — are stored as items in the user's mailbox (the Teams-compliance pattern, AI edition: hidden folder, surfaced through Purview). Each surface's interactions land against the interacting user; agent conversations follow the same shape. Consequences:
- eDiscovery: scope a custodian, their Copilot activity is IN scope — searchable and exportable alongside their mail and chats. 'What did the departing exec ask Copilot about our M&A target' is now an answerable discovery question. Practice it before opposing counsel does.
- Audit: Copilot events flow to the unified audit log (interaction events, admin setting changes, agent lifecycle events) — the WHO-DID-WHAT layer, distinct from the content layer above.
- Leavers: interaction records ride mailbox lifecycle — inactive mailboxes/holds preserve them exactly like mail (the Teams curriculum's leaver logic, verbatim).
The disputes this settles — and creates
Settles: 'did the employee know X' (they asked Copilot about it, dated), 'where did this leaked summary come from' (citations name sources), policy-violation investigations (communication compliance can supervise Copilot conversations like chats). Creates: the transparency obligation — works councils and privacy regimes want to know prompts are retained and reviewable; a monitoring posture nobody announced is a grievance in waiting (memory concept's rule: decide deliberately, tell people); and retention tension — legal wants short, investigations want long (next concept's decision).
What to watch (proofs)
- The end-to-end drill: one custodian's Copilot interactions searched, reviewed, exported in your eDiscovery tooling — timed, documented, and shown to legal BEFORE a live matter (the artifact that converts them from surprised to prepared).
- Audit coverage check: perform known Copilot actions, find every event in the unified log with correct actors — the quarterly logging regression test (Teams curriculum discipline, AI edition).
- Reviewability of agent chats: an agent conversation's records located for both the USER side and (for autonomous runs) the run history — the two-surface model verified.
- The disclosure text: the sentence in your AUP/works-council agreement that says interactions are recorded — existing, dated, and linked from adoption comms.