Agentic AI is here – what it means for governance, data exposure, and intranet permissions

TL;DR Agentic AI is AI that acts, not just answers – it reads, writes, and takes steps on your behalf. Every weak permission, orphaned site, and overshared library becomes a new attack surface. The risk isn’t the AI. It’s the permissions you already have, now queried at machine speed. A single user with ‘Everyone except[…]

Getting Copilot-ready as a NDIS provider: a 6-step plan for safe rollout without exposing participant data

TL;DR Copilot doesn’t leak data. But it does reflect whatever’s already in your SharePoint. If permissions are messy, Copilot will happily surface participant records to people who shouldn’t see them. Your NDIS Code of Conduct obligations don’t pause for AI. Principle 2 (“respect the privacy of people with disability”) and the Privacy Act 1988 still apply. Copilot[…]

Intranet ROI in 2026: the metrics execs care about (and how to report them monthly)

TL;DR Page views are a vanity metric. Execs don’t care how many people loaded the homepage. Good intranet ROI reporting answers three questions: is it faster, is it used, and are people informed? Pick 6 to 8 metrics. Report monthly. One page. That’s the whole discipline. Search success rate and self-service deflection are the two[…]

“We got our IT folks to build our Intranet and… This Is What We Got”: When SharePoint Isn’t the Core Capability

TL;DR Paying $25k for an intranet isn’t the problem. Paying it to a team where intranets aren’t their core capability often is. Having a bit of know-how means you  can build something in SharePoint, but building a useful, scalable intranet is a specialist skill set. When intranets aren’t the core skill, organisations usually end up[…]