CIO Brief: Cleaning Up the Pandemic's Collaboration Mess
Retrospective: this article looks back at events from March 2020, written in 2026 with the benefit of hindsight.
The short version: When COVID-19 sent everyone home in 2020, companies opened up collaboration tools as fast as possible. Many never tightened them again. That leftover sprawl is now a security and AI risk.
What "pandemic debt" looks like
- Thousands of Teams and SharePoint sites, many inactive or without owners.
- Outside guests who still have access to internal files years later.
- Sensitive documents shared with "everyone in the company."
- Personal devices accessing corporate data without controls.
Why it matters now
Microsoft 365 Copilot can find and summarize anything an employee has access to. Files that were overshared in 2020 but rarely discovered can now appear in AI-generated answers in seconds.
The business impact
- Data exposure to external guests and to employees who shouldn't see it.
- AI rollout delays while oversharing is fixed.
- Higher storage and management costs.
Questions to ask your team
- How many Teams and sites do we have, and how many are inactive or ownerless?
- How many external guests have access, and when were they last reviewed?
- How much content is shared with the entire company?
What good looks like
Every Team has an owner, inactive ones expire, guests are reviewed regularly, and sensitive sites are restricted and labeled.
The decision
Fund a collaboration cleanup before expanding Copilot. It improves security, reduces cost and makes AI answers more relevant.
- The COVID-19 Remote Work Shift (Mar 2020): Teams Sprawl, Guest Access and Shadow IT Incident Teardowns
- How to Govern Teams Creation, Guest Access and Expiration Policies How-To & Hardening
- Detecting Teams Guest Access Risk: Defender XDR and Sentinel Hunting Queries Detection & Response