Glossary
Microsoft 365 and AI governance glossary
Plain-language definitions of the terms that come up in governing Microsoft 365, the Power Platform, and the AI tools around them, from Copilot to Claude, OpenAI, and Gemini.
- AI agent
- An AI agent is a system that uses a language model to pursue a goal with some autonomy, reaching data and taking actions. Definition and governance concerns.
- AI governance
- AI governance is the practices, policies, and controls that keep an organization's AI systems safe, accountable, and compliant across every vendor. Definition and scope.
- AI tool sprawl
- AI tool sprawl is the uncontrolled growth of AI assistants and agents across an org, Microsoft and non-Microsoft, faster than anyone can inventory or govern them.
- Audit trail
- An audit trail is the tamper-evident record of who did what, when, in a system. Definition and its role as compliance evidence in Microsoft 365.
- Copilot agent
- A Copilot agent is a custom assistant built on Copilot Studio or Microsoft 365 Agents. Definition, what it can access, and the governance risk.
- Data residency
- Data residency is the requirement that data is stored and processed in a specific location. Definition and why it matters for cloud and AI tools.
- EU AI Act
- The EU AI Act is the EU regulation that classifies AI systems by risk and imposes obligations accordingly. Definition and what it means for AI governance.
- Grounding data
- Grounding data is the organizational content an AI system can retrieve to answer from real information. Definition and why it defines an AI's exposure.
- Least privilege
- Least privilege is the principle that every user, app, and AI agent gets only the access it needs. Definition and why it is the structural defense against oversharing.
- Microsoft 365 tenant
- A Microsoft 365 tenant is the isolated instance of Microsoft cloud services an organization owns. Definition and why it is the unit of governance.
- Oversharing
- Oversharing is when M365 content is reachable by more people than intended, through broad links or permissions. Definition and Copilot risk.
- Retrieval-augmented generation (RAG)
- RAG is a technique where an AI retrieves relevant documents at query time and feeds them to a model, so answers are grounded in real content. Definition and governance view.
- Sensitivity label
- A sensitivity label is a Microsoft Purview classification that marks and protects M365 content. Definition and its role in Copilot governance.
- Shadow AI
- Shadow AI is the use of AI tools IT and security have not sanctioned or do not know about. Definition, why it is risky, and how to bring it under governance.
- SharePoint sprawl
- SharePoint sprawl is the uncontrolled growth of sites, Teams, and storage that outpaces governance. Definition, causes, and why it matters.