Microsoft 365 · Tenants of 200–5,000
Graphlint finds the content-hygiene problems that degrade Copilot answers
A read-only Graph scan of your tenant. It surfaces orphaned files in the retrieval set, broken permission inheritance, missing grounding columns, and the other SharePoint failures that make Copilot guess. Ranked by impact on answers — not by site name.
- Read-only Graph scopes
- No end-user sign-in
- Runs from a service principal
Sample findings ranked by Copilot impact
- 01×128
Ownerless docs in active retrieval set
High/sites/Finance-FY23/Shared Documents
Departed owners; files still match Copilot queries for current policy.
- 02×34
Inheritance broken on folder tree
High/sites/Legal-Opinions/Contracts
Unique ACLs hide current contracts from users who receive citations.
- 03×1
Stale library with no writes in 18 months
Med/sites/Project-Atlas-Archive
Retired project content still grounds answers as if it were live.
- 04×56
Required grounding columns empty
Med/sites/HR-Policies/Published
Missing Department and EffectiveDate weaken filter and citation quality.
- 05×1
Everyone except external on forgotten site
Low/sites/Q4-Townhall-2022
Broad grants keep event decks eligible long after the site went quiet.
Six failure modes that degrade Copilot grounding
- 01
Stale libraries still in the retrieval set
Libraries abandoned after a reorg stay indexed. Copilot retrieves outdated project docs and presents them as current. Graphlint flags libraries with no meaningful write activity against sites that still appear in Microsoft Search and Copilot grounding.
- 02
Broken permission inheritance
Unique permissions on folders and files shrink or expand what Copilot can see. Users get answers from items they cannot open, or miss content they should reach. The scan maps inheritance breaks and ties them to retrieval eligibility.
- 03
Orphaned documents with no living owner
Files left behind by departed users keep their ACL footprint and stay eligible for retrieval. Copilot cites work nobody maintains. Graphlint lists ownerless and inactive-owner documents that still land in the ranking set.
- 04
Missing or inconsistent grounding columns
Content types without required managed properties give Copilot weak signals for filtering and citation. Inconsistent column use across sibling sites produces the same symptom. The report calls out libraries where grounding fields are empty, drifted, or never provisioned.
- 05
Dead links inside active sites
Broken hub links, navigation URLs, and embedded references send Copilot and users to 404s or retired sites. Those paths still appear in site chrome and page content that retrieval can surface. Graphlint samples link health on high-traffic sites.
- 06
Oversharing on forgotten sites
Sites with Everyone or broad guest grants keep feeding the index long after the project ended. Copilot answers from material that should have been locked down or archived. The scan ranks open grants on low-activity sites by how often their content enters retrieval.
Alphabetical inventory vs Copilot-impact ranking
Default inventory report, alphabetical
- 01Accounting Templates
- 02Benefits FAQ 2019
- 03Board Pack Archive
- 04Brand Assets — Draft
- 05Building Access Forms
Graphlint report, Copilot-impact ranked
- 01Ownerless docs in Finance-FY23High
- 02Broken inheritance on Legal ContractsHigh
- 03Stale Project-Atlas-Archive libraryMed
- 04Empty grounding columns on HR PoliciesMed
- 05Oversharing on Q4-Townhall-2022Low
The first row on the right is the problem most likely to shape the next wrong answer. The left panel is what most inventory exports already give you.
Built for the people running Copilot rollouts
- Direct engagementSingle tenant · one scan cycle
In-house SharePoint / M365 admin
You already know the estate is uneven. You need a prioritized list tied to retrieval failure modes before Copilot goes broad — not another alphabetized site dump for stewardship theatre.
- Partner deliveryPer-client · quoted per tenant
Microsoft 365 consultant
You inherit tenants mid-rollout. Graphlint gives you a concrete findings pack to brief the customer on what to fix first so Copilot answers stop citing dead projects and locked folders.
- Managed serviceMulti-tenant · repeatable cadence
MSP running Copilot at scale
Same failure modes across dozens of tenants. A read-only service-principal scan and a ranked report fit a repeatable delivery motion without touching customer content.
How a scan runs
- Step 01
Read-only connect via single admin consent
An Entra ID admin grants Graphlint application permissions once. No end-user sign-in. Scopes are Sites.Read.All and related read APIs only.
- Step 02
Categorize by Copilot impact
The scanner walks sites, libraries, permissions, ownership, metadata, and link health. Each finding is scored for how likely it is to degrade retrieval or grounding.
- Step 03
Prioritized report
You get a ranked findings pack: title, site path, severity, count, and a one-line explanation of why it hurts Copilot. Sample structure matches the preview above.
- Step 04
Roadmap into remediation
Findings group into workstreams your team already owns — permissions, lifecycle, metadata, archive. Graphlint stops at the report; you remediate with existing tools and process.
Nothing in the tenant is created, updated, or deleted. The only write is the report we deliver to you.
FAQ
Request a read-only scan of your tenant
Send work email, tenant domain, and approximate seat count. We reply with scope, Graph permissions, and a fixed quote before any consent prompt.