Copilot Studio logoCopilot Studioby Microsoft
Govern · Copilot Studio

Copilot Studio agents, governed at the connector, per action.

Copilot Studio lets any business team build an agent that reads and writes through more than a thousand Power Platform connectors, runs autonomously on triggers, and ships into Teams and Microsoft 365 Copilot. Agen governs each connector action at runtime, tied to a named owner, and records the verdict. The team keeps building.

Enforced on the cloudAgen.co GatewayAgents hosted in a vendor platform reach your systems through the gateway, which decides every action in-line.
<30ms
per-action verdict at runtime
1:1
a named owner behind every agent
1,000+
connectors governed through one policy
days
from connect to first governed agent

How Agen governs Copilot Studio

  • Every agent built in Copilot Studio is discovered across environments, risk-scored by the connectors and credentials it uses, and resolved to a named human owner.
  • Each connector action the agent takes, a read from SharePoint, a write to Salesforce, an email sent, is judged at runtime against policy and the identity behind the agent.
  • Autonomous agents running on triggers with a maker's shared credentials are governed as their own principal, so the action is attributed to the agent and its owner, not to whoever built it.
  • Policy returns a verdict in under 30ms: allow, mask, step up, hand to a human, or deny. Only the crossing action stops.
  • Power Platform DLP policies, environment settings and Copilot Studio admin controls stay as configured. Agen adds the per-action verdict and the record.
What Copilot Studio agents reach

A thousand connectors, built by anyone, running on triggers.

Copilot Studio is designed for business teams. That is its strength and the reason the agents it produces need a governance layer built for runtime.

Power Platform connectors
SharePoint, Dataverse, Salesforce, ServiceNow, SAP, SQL, email and more than a thousand others, reading and writing through the agent.
Agent flows and actions
Multi-step automations the agent invokes, including Power Automate flows with their own connections.
Autonomous triggers
Agents that start on an email, a record change or a schedule, with no person in the conversation.
Knowledge sources
SharePoint sites, Dataverse tables, public websites and uploaded files grounding the agent's answers.
Channels
Published into Teams, Microsoft 365 Copilot, websites and custom apps, reachable by employees and sometimes customers.
Maker credentials
Connections configured by the person who built the agent, often shared with every user of it.
Where the native controls stop

DLP decides which connectors an environment may use. Not what an agent may do with one.

Power Platform's admin controls are the right controls to keep. They govern the environment, not the action.

01

Agents multiply faster than any registry

Every business team can build one. Across environments, nobody has a single list of the agents that exist, which connectors each one uses, and which ones run autonomously.

agents per tenantunknown
02

Maker credentials are shared credentials

A connection the maker set up is used by everyone who talks to the agent, and by the agent itself on a trigger. When it writes to a system, the record shows the maker's name.

acting identitythe maker's
03

Environment policy is not a runtime verdict

DLP allows or blocks a connector for an environment. Once allowed, every action through it is permitted, whatever the agent is doing and whoever asked.

decision granularityconnector, not action
04

Governance priced per message and per user

Message packs and per-user licences mean the cost of running and governing agents grows with usage. Governance should not be a metered feature.

cost basisper message
How Agen governs it

Same agents, same environments. One verdict per action.

The gateway decides. Agents built in Copilot Studio reach your systems through connectors, and every connector action is decided at the gateway in-line. Nothing changes in how agents are built or published.

01 · Discover
Find every agent in every environment
Continuous discovery across the tenant surfaces every Copilot Studio agent, its connectors, its knowledge sources, its triggers and whether it runs autonomously.
02 · Identify
Give every agent an owner
Each agent becomes a governed principal with its own identity and a named human accountable for it. Shared maker credentials stop being the acting identity.
03 · Govern
Judge each connector action in-line
Reads and writes through Power Platform connectors and flows are decided at the gateway per action, against policy and the agent's identity. Verdict in under 30ms.
04 · Evidence
Record the chain
Every action and verdict logged with agent, owner, connector, target and decision. Exported to your SIEM or Sentinel. Produced at action time.
Shield

The gateway decides. Shield enforces where the gateway cannot see.

Copilot Studio agents run in Microsoft's cloud and reach your systems through connectors, so the gateway decides directly. Shield covers the makers: AgenShield on their devices, BrowserShield on what they paste into the builder and other AI tools.

AS
On the device
AgenShield

Out-of-policy actions like touching production secrets or mass-deleting files are stopped before they execute. Everything else flows. Ships through your MDM.

AgenShield · maker laptop · lt-2210blocked
Actionupload · dataverse-export.csv
Stoppedon device, before execution
Verdict26ms · logged
AgenShield in depth →
BS
In the browser
BrowserShield early access

Keys and sensitive data are recognised as they are pasted into AI tools, and the paste is blocked. Employees keep their tools. Only the leak stops.

BrowserShield · copilotstudio.microsoft.compaste blocked
Detectedconnection string in paste
Everything elseflows normally
Verdictlogged · same audit chain
Join the early-access program →
Same policy · same identity · same verdictShield overviewHow the gateway decides
Governed actions

What a Copilot Studio agent asks to do, and what policy says.

Illustrative verdicts for common agent actions under a typical policy.

Typical per-action verdicts for Copilot Studio
Copilot Studio actionVerdictWhy
Answer from a SharePoint knowledge source the asker can readallowIn scope for the person and the agent. Logged, not interrupted.
Create a ServiceNow incident on behalf of an employeeallowA low-risk write, within policy, tied to the agent's owner, and logged.
Read Dataverse records containing customer personal datamaskThe read runs. Personal data is masked before it enters the model context.
Update a Salesforce opportunity amounthuman-in-the-loopA financial write on a live system. The agent's owner approves before it lands.
Send an email to an external address through the Outlook connectorstep-upOutbound to people outside the company. The owner confirms, the record shows it.
Autonomous agent runs a flow that deletes recordsdenyDestructive, unattended, outside task scope. Blocked and the owner notified.
Agent uses a connector not approved for its environmentdenyReinforces DLP at runtime. Blocked and logged against the agent and owner.
Customer-facing agent looks up an order by order numberallowScoped to the record the customer is entitled to, and logged.

Verdicts are illustrative defaults. Every row is a policy you write once and Agen enforces per action, per identity.

Book a demo

See Copilot Studio governed, live.

Thirty minutes on the way your teams already use Copilot Studio. We show the verdict on each action, the named human behind the session, and the record it leaves. Bring your hardest question.

length30 minutes
formatlive, on your Copilot Studio setup
you seeevery action decided at runtime
Watch it happen

An agent hits a write above policy. The owner approves from their phone.

The agent pauses on the one crossing action, the named owner gets the decision with full context, and the run resumes. No ticket queue, no meeting.

approval flow · live product scene
From connect to governing

No rebuild. Agents keep running while governance switches on.

Copilot Studio, its environments and its DLP policies stay exactly as they are.

Day 1
Connect the tenant
Agen reads the Power Platform environments and the connectors in use. No agent has to be rebuilt or republished.
Day 1
Connect Entra
Owners resolve through Entra ID or any IdP. Every agent gets a named human behind it.
Week 1
Run observe-only
See every agent, every connector action and every autonomous run across the tenant before enforcing anything.
Week 2
Turn on the policies that matter
Start with financial writes, personal data and external sends. Makers only notice the crossing action.
The platform

Discover, Govern, Shield. One policy plane.

The same three capabilities govern Copilot Studio and every other agent you run, internal and external.

Expand a capability

Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.

  • Agentless and API-based across five surfaces
  • First-party, custom, and third-party agents alike
  • Every agent mapped to an owner, approver, and escalation
Agen Discover AI agent discovery flow: any identity provider, productivity suites and assistants, cloud, gateway, endpoints, and MCP server registries all feed one agent registry where every AI agent is inventoried, risk-scored on arrival, given a named human owner, and shadow AI is surfaced.
Discovery pulls from five surfaces into a single agent registry — no SDK self-registration required.
ClosesWhich agents are running that nobody registered?
no SDK required5 surfacesowner-mapped
Discover in depth →

FAQ

Questions, answered.

Does Agen replace Power Platform DLP and Copilot Studio admin controls?
No. Keep them. They govern the environment. Agen governs each action inside it, tied to the agent and its owner, and records the decision.
Do agents need to be rebuilt to be governed?
No. Agen connects to the tenant and the connectors. Agents keep running as built and published.
How are autonomous agents handled?
They are governed as their own principal with a named owner. Actions on a trigger are judged the same way as actions in a conversation, and above-policy actions pause for the owner.
Can this govern agents that face customers?
Yes. Agen governs internal and customer-facing agents on one platform, on a seven-year CIAM foundation. A customer-facing Copilot Studio agent is scoped to what that customer is entitled to.
How is this priced compared with Microsoft's per-message and per-user model?
Agen is priced per governed agent and platform, not per message or per user. The comparison is on the Copilot governance page.

Govern Copilot Studio agents without slowing the makers.

Every agent owned, every connector action judged at runtime, evidence at action time.