"Copilot has its own controls."
Restricted search and tenant-wide switches blunt the symptom for everyone. ShareCare finds and fixes the specific over-shared items, and does it across every client you manage.
ShareCare answers the question every Microsoft 365 customer suddenly has to answer: what is shared with the outside world — or over-shared internally so Copilot can reach it — and who can fix it?
Copilot can summarise, surface and cite anything a user can technically reach. Sharing links created years ago, "Everyone" groups and inherited permissions that never mattered now decide what an AI assistant will hand to the wrong person. Security teams are being asked — often for the first time — to prove the blast radius before the rollout, and keep it shrinking afterwards.
Underneath that, the classic problems have not gone anywhere: anonymous link sprawl, stale guest access, and mailbox forwarding rules used for exfiltration. Native tooling reports these thinly, one workload at a time, one tenant at a time.
Some planes are read-only today: Exchange forwarding rules, SharePoint site roles, Power Platform and delegated-admin relationships are detected but not revoked app-only. When ShareCare cannot safely act, it tells you the precise reason instead of guessing or silently skipping.
OneDrive permission revoke and sharing-link revoke are live today. Beyond Microsoft 365, Box public links and external collaborations are covered with app-only revoke, and Slack Connect externally-shared channels are read-only pending the admin APIs that would let us act.
The screens you will actually work in.
Not a CSV of everything. A scored item, the reasons behind the score, the root cause, and the action — with the alternative to remediating stated next to it.

A score you have to trust is a score you will argue with. Every one on this screen opens into the reasons that produced it, and every reason names something you can change.

| Capability | What it means for you |
|---|---|
| Cross-workload sharing and permission crawl | One picture of exposure instead of seven separate workload reports |
| Org-wide link and "Everyone" group detection | A direct answer to "what can Copilot reach?" |
| Sensitivity × exposure risk model | Prioritise the shares that actually matter, not the loudest ones |
| Durable remediation with grace window and undo | Fix safely in production, and reverse a mistake |
| Owner-delegated recertification | Push the decision to the person who owns the data |
| Fleet benchmarking | Rank clients by exposure and drive the remediation conversation |
Restricted search and tenant-wide switches blunt the symptom for everyone. ShareCare finds and fixes the specific over-shared items, and does it across every client you manage.
The crawl is app-only and read-first. Remediation is simulate-then-execute with a grace window and undo, and it only runs on the tier you bought.
Sharing sprawl regenerates continuously — new links, new guests, new apps. And the continuous version is what becomes compliance evidence.
It detects them. App-only revoke for that plane needs Exchange PowerShell and is on the roadmap. We would rather say that than imply coverage we do not have.
A real crawl of your worst tenants, a scored exposure report, and a remediation plan — whether or not you buy anything afterwards.