Where does the permission check operate?

According to Microsoft's August 25 release note, Microsoft 365 Copilot now grounds answers in content from private Viva Engage communities and events. That private content was previously excluded. Under the new arrangement, a person making a query can receive answers grounded only in material they are permitted to see. This describes the visible step at the end of the data path: Copilot checks community access while composing an answer.[1]

The permission check does not mean everyone in the same community can reach every conversation; Microsoft explicitly says existing access rights continue to apply. Permission at query time, however, does not describe how content enters Copilot, how long it is retained, or when an indexed copy is refreshed after a person's community membership ends. The release note's silence on those questions is not evidence of misuse. It marks the boundary of the protection Microsoft has described.[1]

What happens to the copy when membership ends?

The central subject here is the copy of a private conversation. It begins in Viva Engage, becomes a knowledge source Copilot can use, and grounds an answer to another user. Community authorization is specified along that chain; ingestion frequency, retention, re-indexing, and deletion are not. A product release note need not contain the entire data-governance design. The detail may exist in a separate privacy or administrator document, but this page does not link to one.[1]

The needed document is an account of how a membership change propagates into the index. It should say when private content is ingested, how quickly revoked access removes it from subsequent answers, and what appeal route exists if a user sees improper access. Microsoft's stated permission check is a meaningful safeguard. Publishing this data lifecycle makes the safeguard's reach testable.[1]