Exercise 2, Task 1: Use Copilot in Loop to collaborate on updating a company policy
As General Counsel for Lamna Healthcare Company, you’re part of a cross-functional team tasked with updating the company’s Device Handling and Remote Clinical Access Policy to reflect new guidelines for remote work. With an increasing number of employees working from home, there’s a growing need to address how devices, data access, and security protocols should be managed in a remote environment. Legal, IT, and HR personnel are meeting together to ensure the policy is comprehensive, clear, and compliant with current regulations while aligning with the company’s operational needs. Your role is to collaborate with these teams, using Copilot in Microsoft Loop to co-draft and refine the updated policy. Your goal is to ensure that all necessary elements are covered and the policy is aligned across departments.
To facilitate collaboration, you plan to use Copilot in Loop to help draft and revise key sections of the policy. Copilot can help generate content for device use, access control, and security measures. You also plan work with IT and HR to add actionable items, such as ensuring that personal devices are used securely, and tag specific tasks for each department to ensure alignment. Once the Device Handling and Remote Clinical Access Policy is collaboratively reviewed and finalized, you can convert it into a Word or PDF document for distribution and publication across the company. This exercise helps ensure that all relevant stakeholders contribute to the policy, making it clear and enforceable while also improving communication and efficiency within the team.
Perform the following steps to use Copilot in Loop to co-draft and revise policy documents:
-
In your Microsoft Edge browser, sign in to the Microsoft 365 home page (https://www.microsoft365.com), select Apps in the navigation pane, and then select Loop from the Apps menu.
-
In Loop for the web, create a new workspace titled Policy Update - Remote Work Guidelines.
-
You plan to create the following pages under this Loop workspace (in this order):
-
Draft Policy Sections
-
Departmental Input & Review
-
Task Tracker & Assignments
To begin, change the current title of the first page from Untitled to Draft Policy Sections. Note how the page name is automatically updated in the middle navigation pane.
-
-
Repeat the prior step to create the two remaining pages for this workspace.
-
The Policy Update - Remote Work Guidelines workspace should now include these three pages. However, the pages appear in the reverse order from which they were created, so that the last page appears first. You want to rearrange their order, so select the Draft Policy Sections page in the navigation pane and drag and drop it to the top of the list. Then repeat this process for the Departmental Input & Review page to move it up to the second page. The pages should appear in this order:
-
Draft Policy Sections
-
Departmental Input & Review
-
Task Tracker & Assignments
-
-
Select the Draft Policy Sections page. With Loop, you can use Copilot in one of two ways. If you enter a prompt in the Copilot field that appears below the page heading, Copilot can generate text associated with your prompt. However, if you ask it to add another section of content, it replaces the first section of text with the response to your second request. Replacing the first section of text isn’t what you want. Instead, you want to enter multiple prompts, where each prompt asks Copilot to generate text for specific requests.
To perform this action, you must open the Copilot pane, enter your prompt, and then copy Copilot’s response and paste it into the Loop page at the desired location. To open the Copilot pane, select the Copilot icon that appears in the upper-right side of the page, next to the Share button. -
In the Copilot pane that appears, enter the following prompt to have Copilot create a Device Usage section on this Draft Policy Sections page:
[!NOTE] This task includes fully written prompts for you to use. Because each requirement in this task involves a high level of precision and detail, the training provides complete sample prompts so you can clearly see what an effective, well‑structured prompt looks like. These prompts demonstrate the four key elements of an effective prompt—Goal, Context, Sources, and Expectations. Use this task as an opportunity to observe how detailed guidance improves Copilot’s output and to strengthen your own prompt‑writing skills for complex scenarios like this legal compliance and governance task.
Lamna Healthcare Company is updating its Device Handling and Remote Clinical Access Policy to reflect new guidelines for remote work. The existing policy provides only basic expectations for device use and doesn’t address personal devices, remote clinical data access, multi‑factor authentication, or security behaviors outside the workplace. In this Draft Policy Sections page, draft a new Device Usage section that expands the original policy to cover personal vs. company‑issued devices, secure handling of clinical data off‑site, role‑based access expectations, and baseline security controls required for remote work.
-
Review Copilot’s response. Since it looks like a good starting point, select the Copy icon that appears below Copilot’s response. To paste this content into the Loop page, select the page below the page heading and enter Ctrl+V. Review the text that was pasted on the page. Delete any extraneous text that was copied and pasted along with the results (see the start and end of the content).
-
In the Copilot pane, enter the following prompt to have Copilot create an Access Control section on the Draft Policy Sections page:
Lamna Healthcare Company is updating its Device Handling and Remote Clinical Access Policy to reflect new requirements for secure remote work. The existing policy contains only basic statements about login access and doesn’t address secured clinical data gateways, device chain‑of‑custody expectations, authentication standards, session management, or controls for accessing clinical systems off‑site.
Draft a new Access Control section for this Draft Policy Sections page that expands the old policy to cover secured clinical data gateways, device chain‑of‑custody tracking, user authentication requirements, session timeout expectations, and any baseline controls needed to protect clinical data accessed remotely. -
Review Copilot’s response. Since it looks good, copy and paste it into the Draft Policy Sections page. Paste it at the end of the page. Delete any extraneous text that was copied and pasted along with the results (see the start and end of the content).
-
In the Copilot pane, enter the following prompt to have Copilot create a Security Measures section:
Lamna Healthcare Company is updating its Device Handling and Remote Clinical Access Policy to strengthen security expectations for remote work and clinical data handling. The current policy contains only high‑level statements about protecting company equipment and does not provide detailed guidance on data encryption requirements, incident reporting protocols, secure handling of clinical data, or expectations for detecting and responding to potential security events outside the corporate network.
Draft a new Security Measures section for this Draft Policy Sections page that fills these gaps. Your updated section should address data encryption standards for clinical information, expectations for remote incident reporting and escalation timelines, baseline endpoint security controls for off‑site devices, and any additional safeguards necessary to protect sensitive clinical data accessed from remote locations. -
Review Copilot’s response. Since it looks good, copy and paste it into the Draft Policy Sections page. Paste it at the end of the page. Delete any extraneous text that was copied and pasted along with the results (see the start and end of the content).
-
That concludes the updates to the Draft Policy Sections page. Now select the Departmental Input & Review page in the worksheet menu. For this page, you want to invite collaborators from Legal, IT, and HR into the Loop workspace to review and provide feedback on the relevant sections generated by Copilot on the previous Draft Policy Sections page. On this Departmental Input & Review page, you want Copilot to create a subpage for each department. These subpages are where the collaborators can enter feedback for their respective departments.
To create these subpages, you aren’t going to use the Copilot pane. Instead, you’re going to use the Copilot functionality that appears within the Departmental Input & Review page. Below the page title is a line of text that says “Just start typing…” Hover over this text, which triggers Copilot to display a plus sign (+). Select the plus sign (+), and in the menu that appears, select New subpage. Note how Copilot created an Untitled subpage below the Departmental Input & Review page. Change the title of this subpage from Untitled to Legal. -
When you add each remaining subpage (one for IT and another for HR), you must be on the Departmental Input & Review page. If you were on the Legal subpage and you repeated this process of adding a new subpage, the new subpage would be under the Legal subpage rather than the Departmental Input & Review page. So select the Departmental Input & Review page in the worksheet menu. Then repeat the prior step to add a subpage titled IT.
-
Repeat this process one last time to create a third subpage titled HR.
-
In the worksheet menu, you should now see three subpages under the Departmental Input & Review page – Legal, IT, and HR. Representatives from each department can now select their respective subpage and enter their feedback.
- That concludes the updates to the Departmental Input & Review page. Now select the Task Tracker and Assignment page in the worksheet menu. For this page, you want Copilot to create a table that contains a list of potential actionable items for each department. Enter the following prompt in the Copilot pane:
Lamna Healthcare Company is expanding its Device Handling and Remote Clinical Access Policy to clarify department‑specific responsibilities for secure remote work. Use only best practices from healthcare compliance and remote‑work security (for example, HIPAA‑aligned operational controls, clinical data handling safeguards, role‑based access governance, security awareness training) to define actions for each department.
Create three tables—Legal, IT, and Human Resources—that list realistic, best‑practice actions aligned to these policy updates. For each table, include the following columns:-
Action name. Define the name of the action, such as policy review, access governance, device audits, incident escalation, employee training, and policy communication.
-
Short description. Describe what the department must do and why it supports compliant remote clinical access.
Don’t reference internal drafts or internal documentation. Ground each action in authoritative best‑practice guidance from healthcare compliance and remote‑work security, and write in plain, professional language suitable for legal/compliance review.
-
-
Review the three tables with actionable items that Copilot generated in the Copilot pane. Since everything looks good, select the Copy icon that appears below Copilot’s response and then paste the content into the Loop page. Delete any extraneous text that was copied and pasted along with the results (see the start and end of the content).
-
At this point, you want Loop to export the content from each page to a Word document, which you plan to use in Task 3 as the basis for an executive-level PowerPoint presentation. There are several ways to create a Word document from Loop pages. For this task, you plan to create a final Loop page, then run a prompt that tells Copilot to gather the content from the other pages into one structured draft. You can then copy and paste the compiled content into a Word document.
To begin this process, add a final page in your Loop workspace and title it Executive Briefing Source. -
In the Executive Briefing Source page, open the Copilot pane and enter the following prompt:
Combine the content from the following Loop pages in this workspace into a single, structured draft suitable for an executive briefing: Draft Policy Sections and Test Tracker & Assignment. Create a clear outline that includes the following sections: Overview of governance gaps, Updated policy sections (plain language), Cross-department action items for the Legal, IT, and HR departments, 90-day corrective action roadmap, and Metrics and accountability. Write in a professional, concise tone for Legal/Compliance. Don’t invent new findings. Use only what’s on these pages. - Review the content that was displayed in the Copilot pane. Select the Copy icon that appears below the content. Then open a blank document in Word, paste in the copied content, and then delete any extraneous text that was copied and pasted along with the results (see the start and end of the content). Save the file as Lamna Executive Briefing Source.docx in your OneDrive folder. You plan to use this file as the basis for an executive PowerPoint presentation in Task 3.