Square One
GUIDE · COMPARISON

Governed AI vs ChatGPT, Copilot and enterprise search

Governed AI is not a better chatbot. It is a different category: AI that operates inside a permission-aware, evidence-grounded, auditable environment, alongside automation and business rules. A public chatbot, Microsoft Copilot and enterprise search each do one useful thing. Governed work is the environment they should operate inside, so their output can be trusted, traced and defended.

IN SHORT
  • A public chatbot (ChatGPT, Claude) is a capability that lives outside your permissions, evidence and record.
  • Microsoft Copilot assists an individual inside Microsoft 365 and respects its permissions, but does not, on its own, govern evidence, approval and workflow across the organisation.
  • Enterprise search finds documents; it does not produce defensible work.
  • Governed work is the operating environment: it adds provenance, permission-awareness, approval, automation and an audit record, and can use any of the above as a capability inside it.
  • The question is not chatbot versus Copilot versus search. It is what governs the AI you use.

At a glance

PUBLIC CHATBOT (CHATGPT)MICROSOFT COPILOTENTERPRISE SEARCHGOVERNED WORK (SQUARE ONE)
What it isA general-purpose AI chatbotAn AI assistant inside Microsoft 365A way to find existing documentsAn operating environment for governed work
Primary jobAnswer anything, for anyoneHelp an individual draft and summariseRetrieve, not produceProduce work you can trust and defend
Evidence / provenanceNone; answers are unsourcedCites files it drew on, per answerReturns the source document itselfEvery output traces to its sources, and stays linked
PermissionsOutside your permission modelInherits Microsoft 365 permissionsRespects the index’s permissionsInherits Microsoft 365 permissions, tightened for shared work
ApprovalNoneNone built inNot applicableWork passes a human approval before it counts
Record / auditNone; the chat is ephemeralLimitedSearch logs onlyAppend-only, auditable record of what happened
Automation & workflowNoneLimited (Power Platform, separate)NoneAutomation and business rules carry the repeatable work
Where your data goesInto a third-party account you don’t controlStays in your Microsoft 365 tenantStays in your indexStays inside your governed perimeter
ModelOne providerMicrosoft-providedNot a modelModel-agnostic, behind a policy gate
Best understood asA capabilityA capabilityA retrieval layerThe environment the others should run inside

Governed AI is a category, not a better chatbot

Most comparisons start in the wrong place, by lining up AI tools as if they were competing chatbots. They are not the same kind of thing. A chatbot, a copilot and a search box are all capabilities: each does one job well. Governed work is not another capability in that line-up. It is the environment those capabilities should run inside, so that whatever they produce is permission-aware, evidence-grounded, approved and on the record.

Read that way, the question stops being “which AI tool should we buy?” and becomes “what governs the AI our people already use?” That is the question that actually matters to a business, and it is the one governed work answers. (For the full definition, see what is governed work.)

vs a public AI chatbot (ChatGPT, Claude)

A public chatbot is a general-purpose assistant. It is genuinely useful, which is exactly why staff already use it. But it sits outside everything that makes work defensible. Its answers carry no evidence, so nobody can say what a sentence rests on. It has no awareness of your permissions, so anything pasted into it steps around your access controls. It keeps no organisational record, so the work, and whatever was pasted in, lives in a third-party account you do not control.

Used inside a business without governance, that is shadow AI. Governed work does not ban the capability. It gives that same instinct a place to operate where evidence, permissions and a record are present by default.

vs Microsoft Copilot

Microsoft Copilot is the closest of the three, and the most often confused with governed work, so it is worth being precise. Copilot assists an individual inside Microsoft 365. It answers over content the signed-in user can already access, which means it respects Microsoft 365 permissions and grants no new access. That is a real strength, and Copilot is a capable tool.

What Copilot does not do, on its own, is govern work at the level of the organisation. It assists a person; it does not run the deterministic work that should be automation rather than AI, it does not put a deliberate approval between a draft and a decision, and it does not maintain an append-only, organisation-wide record of what was produced and on what basis. It also surfaces whatever a user can already reach, so where permissions were over-broad to begin with, Copilot makes that pre-existing exposure visible faster. Governing that is a separate task. (We cover it in governing AI across Microsoft 365.)

The two are not rivals. Copilot is a capability that can sit inside a governed environment. Square One is model-agnostic and built on the same Microsoft 365 ground, so the question is not Copilot or governed work; it is Copilot governed, or Copilot ungoverned.

vs enterprise search

Enterprise search makes existing information findable. It is retrieval: you ask, and it returns documents you are allowed to see. That is valuable, and governed work relies on the same idea of permission-bound retrieval underneath. But search stops at finding. It does not draft a defensible document, it does not reason over evidence to produce an answer, and it does not carry approval or a record. Governed work uses retrieval as one ingredient, then adds the provenance, approval and audit that turn found information into work an organisation can stand behind.

vs an AI assistant or AI wrapper

Many products are an interface wrapped around someone else’s model: a thin assistant that passes your prompt to an AI and returns the answer. That can be handy, but it inherits every limitation above, and adds lock-in to a single provider. Governed work is the opposite in shape. The model is the replaceable part, sitting behind a policy gate; the lasting part is the governance: permissions, evidence, approval and the record. (On why the model should be the swappable component, see don’t marry a model.)

Where the line actually is

All of these tools can coexist. Your people can use a chatbot, your organisation can run Copilot, and you can have enterprise search. The line that matters is not between the tools. It is between work that is governed and work that is not: whether what these capabilities produce can be traced to evidence, bound to permissions, approved, and kept on the record. Governed work is what draws that line, and holds it, whichever capabilities you use.

Frequently asked questions

Is Square One a ChatGPT competitor?

No. ChatGPT is a general-purpose chatbot, a capability. Square One is the governed environment that work happens inside. It can use models like the ones behind ChatGPT, but it adds the evidence, permissions, approval and record a chatbot does not.

How is Square One different from Microsoft Copilot?

Copilot assists an individual inside Microsoft 365 and respects its permissions. Square One governs work across the organisation: automation before AI, evidence-grounded output, human approval, and an append-only record. Copilot is a capability that can run inside a governed environment; Square One is that environment.

Do we still need Copilot if we have Square One?

They are complementary, not exclusive. Square One is model-agnostic and built on Microsoft 365, so a capability like Copilot can operate inside its governance. The choice is not Copilot or Square One; it is Copilot governed, or ungoverned.

Is governed work just enterprise search?

No. Search finds existing documents. Governed work uses permission-bound retrieval as one ingredient, then produces defensible output with provenance, approval and a record. It does what search cannot: turn found information into work you can stand behind.

Is Square One an AI wrapper?

No. A wrapper is an interface around one model. Square One keeps the model as the replaceable part behind a policy gate; the lasting part is governance: permissions, evidence, approval and audit. That is the opposite of a wrapper.

Does Square One replace Microsoft 365?

No. It builds on Microsoft 365, inheriting identity, permissions and files rather than creating a parallel layer.

Related reading

See what governing AI, rather than adding another one, looks like in practice.

Talk to us
SQUARE ONE IS A PRODUCT OF INHOUSE CX© 2026 INHOUSE CX