Senior-Beratungsgespräch zu Business Central und ERP bei DGP

Knowledge/Answer

Senior-led answer · AI

What data does Copilot see in Business Central?

Exactly the data the signed-in user may see. That is the short answer, and it has one prerequisite: maintained permissions.

Frank Maier·Last updated: 01.09.2026

Copilot in Business Central works within the permissions of the signed-in user: what the user may not see, their Copilot does not see either. According to Microsoft's documentation, processing runs within the Microsoft cloud service boundary, and business data is not used to train the underlying models. The practical homework therefore lies in your own house: a permission concept that has grown too broad over the years makes Copilot a window that is too wide as well.

The principle: Copilot inherits the user's rights

Copilot is not a second data access route next to the system but an interface on the same permission model. If a sales employee asks about margins they have no read permission for, they do not get them via Copilot either. The same applies to agents with their own account: an order agent works under its own user context with its own, deliberately narrow rights.

The security question therefore does not stand or fall with the AI but with the permission concept underneath. Whoever has worked there for years with catch-all roles and full access had the problem before Copilot. The AI only makes it more visible, because asking questions is easier than searching tables.

What happens to the data during processing

According to Microsoft's documentation, the processing of Copilot requests runs within the service boundary of the Microsoft cloud, under the same contractual commitments as the rest of Business Central. Business data from your system is not used to train the underlying language models. Your documents do not become teaching material for others.

In practice this means: the data protection assessment of Copilot is a continuation of the Business Central assessment, not a new barrel to open. What belongs in writing are the activated functions, their data reach and the owners, and exactly that list emerges anyway once the operating routine is in place.

The real homework: declutter permissions

Before the first broad Copilot activation, three points are worth a look: shared accounts used by several people, legacy roles with full access from the implementation days, and management rights that see everything out of convenience. All three were always untidy. With AI interfaces they become an open shelf.

The declutter is manageable: tailor roles to the work profile, dissolve shared accounts, give agents their own accounts. It pays twice: into security and into answer quality, because AI on cleanly ordered data answers measurably better than on an open sea of data.

Three questions for your next IT meeting

  • Which Copilot and agent functions are activated in our system, and who owns each function?
  • Do all agents work under their own accounts with narrow rights, or does anything run under shared or admin accounts?
  • When were user roles last checked against the actual work profiles?

Whoever can answer these three questions in writing has the data access question under control. Whoever cannot now knows where the work lies, and an Take stock quantifies it in days instead of guesses.

Contents

Your question in detail?

A senior-led conversation gets to the heart of your situation.

Related service

Become AI-ready

Copilot opens no new door to your data. It only shows how many doors were open all along.

Frank Maier, founder of DGP

Frequently asked questions

Briefly asked

Does our data leave the Microsoft cloud for Copilot?

According to Microsoft's documentation, processing runs within the service boundary of the Microsoft cloud, under the existing contractual commitments. For your own assessment, consult the current Microsoft documentation, as capabilities and regions evolve with the releases.

Does Microsoft train its AI models with our business data?

No, according to Microsoft's documentation, business data from Business Central is not used to train the underlying models. Your documents, prices and customer data do not become teaching material for third parties.

Can a colleague see salaries or margins via Copilot?

Only if their permissions allow it anyway. Copilot extends no rights, it uses the existing ones. If this question causes unease in your company, that points at the permission concept, not at the AI, and that is where to tidy up first.

Related

Related questions

Knowledge · AI

Do AI agents in Business Central need a clean data foundation?

An agent acts on your data. Whether it relieves or multiplies chaos is decided by the data foundation, not the agent.

03.08.2026

Read

Knowledge · AI

What does Copilot cost in Business Central?

Licence, credits and the cost block that rarely appears in offers: the honest cost picture for AI in the ERP.

18.08.2026

Read

Knowledge · AI

Which AI agents are there in Business Central?

Business Central comes with several agents. The right start is not the agent with the biggest promise, but the one with the cleanest process.

04.08.2026

Read

Where does your project really stand?

Talk to a senior, not to a sales rep.