Agents multiply faster than any registry
Every business team can build one. Across environments, nobody has a single list of the agents that exist, which connectors each one uses, and which ones run autonomously.
Copilot Studio lets any business team build an agent that reads and writes through more than a thousand Power Platform connectors, runs autonomously on triggers, and ships into Teams and Microsoft 365 Copilot. Agen governs each connector action at runtime, tied to a named owner, and records the verdict. The team keeps building.

Copilot Studio is designed for business teams. That is its strength and the reason the agents it produces need a governance layer built for runtime.
Power Platform's admin controls are the right controls to keep. They govern the environment, not the action.
Every business team can build one. Across environments, nobody has a single list of the agents that exist, which connectors each one uses, and which ones run autonomously.
A connection the maker set up is used by everyone who talks to the agent, and by the agent itself on a trigger. When it writes to a system, the record shows the maker's name.
DLP allows or blocks a connector for an environment. Once allowed, every action through it is permitted, whatever the agent is doing and whoever asked.
Message packs and per-user licences mean the cost of running and governing agents grows with usage. Governance should not be a metered feature.
The gateway decides. Agents built in Copilot Studio reach your systems through connectors, and every connector action is decided at the gateway in-line. Nothing changes in how agents are built or published.
Copilot Studio agents run in Microsoft's cloud and reach your systems through connectors, so the gateway decides directly. Shield covers the makers: AgenShield on their devices, BrowserShield on what they paste into the builder and other AI tools.
Out-of-policy actions like touching production secrets or mass-deleting files are stopped before they execute. Everything else flows. Ships through your MDM.
Keys and sensitive data are recognised as they are pasted into AI tools, and the paste is blocked. Employees keep their tools. Only the leak stops.
Illustrative verdicts for common agent actions under a typical policy.
| Copilot Studio action | Verdict | Why |
|---|---|---|
| Answer from a SharePoint knowledge source the asker can read | allow | In scope for the person and the agent. Logged, not interrupted. |
| Create a ServiceNow incident on behalf of an employee | allow | A low-risk write, within policy, tied to the agent's owner, and logged. |
| Read Dataverse records containing customer personal data | mask | The read runs. Personal data is masked before it enters the model context. |
| Update a Salesforce opportunity amount | human-in-the-loop | A financial write on a live system. The agent's owner approves before it lands. |
| Send an email to an external address through the Outlook connector | step-up | Outbound to people outside the company. The owner confirms, the record shows it. |
| Autonomous agent runs a flow that deletes records | deny | Destructive, unattended, outside task scope. Blocked and the owner notified. |
| Agent uses a connector not approved for its environment | deny | Reinforces DLP at runtime. Blocked and logged against the agent and owner. |
| Customer-facing agent looks up an order by order number | allow | Scoped to the record the customer is entitled to, and logged. |
Verdicts are illustrative defaults. Every row is a policy you write once and Agen enforces per action, per identity.
Thirty minutes on the way your teams already use Copilot Studio. We show the verdict on each action, the named human behind the session, and the record it leaves. Bring your hardest question.
The agent pauses on the one crossing action, the named owner gets the decision with full context, and the run resumes. No ticket queue, no meeting.
Copilot Studio, its environments and its DLP policies stay exactly as they are.
The same three capabilities govern Copilot Studio and every other agent you run, internal and external.
Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.
Every agent owned, every connector action judged at runtime, evidence at action time.