The Two Very Different Copilots
Microsoft has created significant confusion by offering multiple products under the "Copilot" brand. The consumer Copilot at copilot.microsoft.com is a standalone AI assistant with no access to organizational data — it behaves similarly to ChatGPT or Claude. Microsoft 365 Copilot, sold as an enterprise add-on, is fundamentally different: it is deeply integrated into your organization's M365 environment and has access to everything your account can see.
PromptGnome protects users of the standalone copilot.microsoft.com. For enterprise M365 Copilot users, PromptGnome provides protection for queries typed into the web interface — but the deeper risk of M365 Copilot (context pulled from organizational data) requires organizational-level data governance policies, not just a browser extension.
The Overprivileged Access Problem
When Microsoft M365 Copilot was initially rolled out to enterprises, security teams quickly identified a critical pattern: employees with broad SharePoint permissions were receiving AI-synthesized summaries of confidential documents they had never actively read. A marketing coordinator with accidentally broad SharePoint access could ask Copilot "what is our revenue forecast?" and receive a synthesis of confidential finance documents — not because Copilot was misconfigured, but because it faithfully used all the data the user was technically permitted to access.
This prompted a wave of organizational security reviews focused on tightening M365 permission scopes before deploying Copilot. If your organization has deployed M365 Copilot, talk to your IT team about permission scoping before using it with sensitive queries.
What PromptGnome Detects in Copilot Messages
- Employee names, email addresses, and contact details typed into prompts
- Financial figures, account numbers, and revenue data
- API keys, tokens, and credentials pasted into Copilot queries
- Customer PII including names, addresses, and identification numbers
- Medical or HR information shared in conversational queries
- Confidential project names and client identifiers (Pro NER tier)