Before the session: script and baseline evidence
We send a read-only SharePoint exposure script and a session brief. Your administrator reviews the script and confirms the required permissions before running it. Share the CSV output using an agreed secure method so Cocha can review it before the session.
The script provides M365 Group risk counts by tier. It does not review every SharePoint site or establish that every permission boundary is correct.
Have an administrator ready to show Microsoft Secure Score and its recommended actions during the session. We focus on the actions relevant to Copilot and connected agents.
Optional Shadow AI evidence
If agreed in advance, provide a 30-day DNS, firewall, or proxy export for review of external AI service activity. We confirm the format, scope, and secure sharing method first. These logs do not prove what information users shared with those services.
Plan for the administrator’s preparation and evidence sharing in addition to the 60-minute working session and 30-minute findings review. Preparation time depends on your environment; we will confirm what is needed.
Do not send passwords, tenant credentials, confidential client matter files, patient information, or proprietary design documents through the request form or ordinary email.
The schedule
- We confirm fit, participants, and required inputs.
- We hold the 60-minute working session.
- We provide written findings within five business days after the session and receipt of the required inputs.
- We review the findings with you in a 30-minute follow-up.
Missing inputs or participant availability can change the overall timing. We will confirm the schedule with your team.
See sample findings · Read the scope