09/07/2026
๐ง๐ต๐ฒ ๐ณ๐ถ๐ฟ๐๐ ๐พ๐๐ฒ๐๐๐ถ๐ผ๐ป ๐ฒ๐๐ฒ๐ฟ๐ ๐ฒ๐ป๐๐ฒ๐ฟ๐ฝ๐ฟ๐ถ๐๐ฒ ๐ฎ๐๐ธ๐ ๐ฎ๐ฏ๐ผ๐๐ ๐๐ผ๐ฝ๐ถ๐น๐ผ๐:
"Does our data leave our tenant?"
Here's the actual flow, step by step and the answer is in step 4.
๐๐ผ๐ ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ฎ๐ฏ๐ฟ๐ถ๐ฐ ๐๐๐ฟ๐ป๐ ๐ฝ๐ฟ๐ผ๐บ๐ฝ๐๐ ๐ถ๐ป๐๐ผ ๐ถ๐ป๐๐ถ๐ด๐ต๐๐:
๐ญ. ๐ง๐ต๐ฒ ๐๐ป๐ฝ๐๐
โข Your prompt, the chat history from the session, your ๐๐๐ฒ๐ฟ ๐๐ผ๐ธ๐ฒ๐ป, and system metadata with a metaprompt
โข Note the user token. Everything downstream runs under ๐๐ผ๐๐ฟ ๐ถ๐ฑ๐ฒ๐ป๐๐ถ๐๐, not a shared service account
๐ฎ. ๐๐ฟ๐ผ๐๐ป๐ฑ๐ถ๐ป๐ด: ๐ง๐ต๐ฒ ๐ฃ๐ฎ๐ฟ๐ ๐ง๐ต๐ฎ๐ ๐ ๐ฎ๐๐๐ฒ๐ฟ๐
โข Copilot pulls from the Fabric workspaces and items ๐๐ผ๐ ๐ต๐ฎ๐๐ฒ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐ ๐๐ผ, the data models and schemas, and item metadata
โข "You" is doing a lot of work in that sentence. Copilot cannot ground on data you couldn't already open yourself
โข ๐ฌ๐ผ๐๐ฟ ๐ฒ๐
๐ถ๐๐๐ถ๐ป๐ด ๐ฝ๐ฒ๐ฟ๐บ๐ถ๐๐๐ถ๐ผ๐ป๐ ๐ฎ๐ฟ๐ฒ ๐๐ต๐ฒ ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ฏ๐ผ๐๐ป๐ฑ๐ฎ๐ฟ๐. This is the single most important thing to understand about enterprise Copilot
๐ฏ. ๐ฃ๐ฟ๐ฒ๐ฝ๐ฟ๐ผ๐ฐ๐ฒ๐๐๐ถ๐ป๐ด
โข Grounding, context assembly, and prompt enhancement happen inside ๐๐ฎ๐ฏ๐ฟ๐ถ๐ฐ ๐ฐ๐ฎ๐ฝ๐ฎ๐ฐ๐ถ๐๐
โข The model never sees your raw question alone. It sees a constructed prompt with the relevant schema and context attached
๐ฐ. ๐ง๐ต๐ฒ ๐ ๐ผ๐ฑ๐ฒ๐น ๐๐ฎ๐น๐น
โข The preprocessed input goes to ๐๐๐๐ฟ๐ฒ ๐ข๐ฝ๐ฒ๐ป๐๐ ๐ฆ๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ, managed by Microsoft
โข Tokenizer, embeddings, processing, response
โข Explicitly ๐ป๐ผ๐ the public internet, and ๐ป๐ผ๐ public OpenAI services. That distinction is the whole compliance story
Your data stays within your capacity's geographic region and compliance boundary
๐ฑ. ๐ฃ๐ผ๐๐๐ฝ๐ฟ๐ผ๐ฐ๐ฒ๐๐๐ถ๐ป๐ด
โข ๐ฅ๐ฒ๐๐ฝ๐ผ๐ป๐๐ถ๐ฏ๐น๐ฒ ๐๐ ๐ฐ๐ต๐ฒ๐ฐ๐ธ๐, query evaluation, and additional model calls if needed
โข Output filtering happens on the way back, not just on the way in
๐ฒ. ๐ฅ๐ฒ๐๐๐ฟ๐ป
โข The result comes back to the user through Copilot in Fabric or Power BI Desktop
โข Consuming ๐๐ฎ๐ฏ๐ฟ๐ถ๐ฐ ๐ฐ๐ฎ๐ฝ๐ฎ๐ฐ๐ถ๐๐ along the way, which is worth watching on your bill
๐ง๐ต๐ฒ ๐๐๐ผ ๐๐ต๐ถ๐ป๐ด๐ ๐๐ผ๐ฟ๐๐ต ๐๐ฎ๐ธ๐ถ๐ป๐ด ๐ณ๐ฟ๐ผ๐บ ๐๐ต๐ถ๐ ๐ฑ๐ถ๐ฎ๐ด๐ฟ๐ฎ๐บ:
Grounding is scoped by existing permissions, so your Copilot rollout is only as safe as your workspace access model already was. ๐๐ถ๐
๐ฝ๐ฒ๐ฟ๐บ๐ถ๐๐๐ถ๐ผ๐ป๐ ๐ฏ๐ฒ๐ณ๐ผ๐ฟ๐ฒ you enable Copilot, not after.
And the model runs inside a ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐-๐บ๐ฎ๐ป๐ฎ๐ด๐ฒ๐ฑ ๐๐๐๐ฟ๐ฒ ๐๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ, isolated from public endpoints. That's the answer to the question your security team is about to ask.
Have you audited workspace permissions before turning Copilot on?
PS: Found this useful?
Join 3,000+ AI architects and engineering leaders from Microsoft, Google, IBM, PwC and others reading my weekly newsletter ๐๐ถ๐ฎ๐ฟ๐ ๐ผ๐ณ ๐ฎ๐ป ๐๐ ๐๐ฟ๐ฐ๐ต๐ถ๐๐ฒ๐ฐ๐.
I break down real enterprise AI systems, agentic patterns, and what actually works in production.