Microsoft 365 Copilot logoMicrosoft 365 Copilotby Microsoft
Govern · Microsoft 365 Copilot

Copilot, governed at the paste and on every agent action.

Microsoft 365 Copilot is grounded in the Graph, and the agents built on it act in Teams and across connected systems. Your people also use three other assistants the Microsoft stack cannot see. BrowserShield stops company data at the paste in all of them. The gateway decides every agent action that reaches your systems. Your people keep Copilot.

Enforced on the browserBrowserShieldearly accessCompany data stopped at the paste. Employees keep their tools. Only the leak stops.
0
sensitive pastes through, in every assistant
<30ms
per-action verdict at the gateway
1:1
a named owner behind every agent in the tenant
0
per-user governance licences

How Agen governs Microsoft 365 Copilot

  • BrowserShield recognises keys, credentials and sensitive data as they are pasted or uploaded into Copilot Chat, and into ChatGPT, Claude and Gemini on the same laptop, and blocks the paste. One policy, every assistant.
  • Every agent in the tenant, built in Copilot Studio or by Microsoft, is discovered, given a named owner, and decided per action at the gateway for every connector it uses to reach your systems.
  • Every assistant your people actually use becomes visible in the Agen.co console, including the ones outside the Microsoft stack that DLP cannot see.
  • Policy returns a verdict in under 30ms at the gateway: allow, mask, step up, hand to a human, or deny. Only the crossing action stops.
  • Sensitivity labels, DLP policies and Copilot admin controls stay as configured. Agen adds the verdict at the paste and at the gateway, priced per governed agent, not per user per month.
What Microsoft 365 Copilot reaches

Everything in the Graph the person can open.

Copilot does not need a connector to reach company data. It is grounded in the Graph by default, and agents extend it further.

Graph grounding
Outlook, OneDrive, SharePoint, Teams chats and meetings, read inside Microsoft's cloud with the person's own permissions.
Copilot agents
Researcher, Analyst and agents built in Copilot Studio, surfaced in Teams and Copilot Chat with actions attached.
Connectors
Graph connectors and Copilot Studio connectors to Salesforce, ServiceNow, Jira and hundreds of other systems.
Copilot in apps
Drafts, edits and acts inside Word, Excel, PowerPoint, Outlook and Teams.
Copilot Notebooks and Pages
Persists documents and generated content across sessions for a team.
Uploads and pastes
Anything a person pastes or uploads becomes model context: contracts, customer records, source code, keys.
Where the native controls stop

The Microsoft stack governs the Microsoft stack. Agents and the other assistants are outside it.

Microsoft's controls are the right controls to keep. They stop at the tenant boundary, and the agents built on Copilot are registered, not governed per action.

01

DLP covers Microsoft surfaces. The paste goes elsewhere.

The person with a Copilot seat is also pasting into ChatGPT, Claude and Gemini. Company data pasted into those tools leaves no trace in any Microsoft log.

coveragethe Microsoft stack only
02

Registered is not governed

Copilot Studio agents get an identity automatically. That is an inventory entry. Nothing decides whether this action, on this record, in this run, should have paused for a human.

decision granularityagent, not action
03

Copilot inherits your permissions debt

Copilot honours existing SharePoint permissions, including the overshared ones. That grounding happens inside Microsoft's cloud, and the fix is a clean-up measured in quarters.

oversharing surfaced atruntime
04

Governance priced per user, per month

The controls that reach beyond the tenant come as add-on licences and per-message agent billing. Governance cost scales with headcount, not with risk.

cost basisper seat
How Agen governs it

Stop the leak in every browser. Decide every agent action at the gateway.

The gateway decides. Shield enforces where the gateway cannot see. For Copilot that is BrowserShield at the paste across every assistant, and the gateway on every agent that reaches your systems.

01 · Discover
See every agent and every assistant
The gateway and tenant connection surface every agent in the tenant and its connectors. BrowserShield surfaces every assistant in use, inside and outside the Microsoft stack.
02 · Identify
Tie each action to a person
Pastes resolve to the person from Entra or any IdP. Every agent becomes a governed principal with a named owner, whoever built it.
03 · Govern
Block the paste, judge the action
Keys and sensitive data are stopped at the paste. Agent actions reaching your systems through connectors are decided at the gateway per action, in under 30ms.
04 · Evidence
Record the chain
Every stopped paste and every gateway verdict logged with person, agent, target and decision. Exported to your SIEM or Sentinel. Produced at action time.
Shield

The gateway decides. Shield enforces where the gateway cannot see.

For Copilot the leak is the paste, in Copilot Chat and in the assistants outside the Microsoft stack, so BrowserShield does the work. AgenShield covers the Copilot desktop apps and coding agents on managed devices with the same policy.

AS
On the device
AgenShield

Out-of-policy actions like touching production secrets or mass-deleting files are stopped before they execute. Everything else flows. Ships through your MDM.

AgenShield · Copilot app · lt-4471blocked
Actionupload · payroll-export.xlsx
Stoppedon device, before execution
Verdict28ms · logged
AgenShield in depth →
BS
In the browser
BrowserShield early access
Primary for Microsoft 365 Copilot

Keys and sensitive data are recognised as they are pasted into AI tools, and the paste is blocked. Employees keep their tools. Only the leak stops.

BrowserShield · m365.cloud.microsoftpaste blocked
Detectedcustomer records in paste
Everything elseflows normally
Verdictlogged · same audit chain
Join the early-access program →
Same policy · same identity · same verdictShield overviewHow the gateway decides
Governed actions

What Copilot and its agents ask to do, and what policy says.

Illustrative verdicts under a typical policy. Paste rows are BrowserShield. Agent rows are the gateway.

Typical per-action verdicts for Microsoft 365 Copilot
Microsoft 365 Copilot actionVerdictWhy
Ask Copilot Chat a question with no company data in the promptallowNothing sensitive in the paste. The person keeps working.
Paste an API key or access token into Copilot ChatdenyRecognised at the paste and blocked before it leaves the tab. The person sees why.
Paste customer records into ChatGPT on the same laptopdenySame policy, different tool. Blocked at the paste, the person is pointed to a governed path.
Copilot Studio agent creates a ServiceNow ticketallowA low-risk write, within policy, tied to the agent's owner, and logged.
Agent reads Dataverse records containing personal datamaskThe read runs. Personal data is masked at the gateway before it enters the model context.
Agent updates a Salesforce opportunity amounthuman-in-the-loopA financial write on a live system. The owner approves before it lands.
Agent sends email to an external address through the connectorstep-upOutbound to people outside the company. The owner confirms, the record shows it.
Autonomous agent runs a flow that deletes recordsdenyDestructive, unattended, outside task scope. Blocked and the owner notified.

Verdicts are illustrative defaults. Every row is a policy you write once and Agen enforces per action, per identity.

Book a demo

See Microsoft 365 Copilot governed, live.

Thirty minutes on the way your teams already use Microsoft 365 Copilot. We show the verdict on each action, the named human behind the session, and the record it leaves. Bring your hardest question.

length30 minutes
formatlive, on your Microsoft 365 Copilot setup
you seeevery action decided at runtime
Watch it happen

A secret is pasted into Copilot. It never leaves the tab.

BrowserShield recognises the key as the prompt is composed and stops the paste. The person keeps working. The record shows who, what and when.

blocked at the paste · live product scene
From connect to governing

Copilot does not change. Neither does your tenant.

Your labels, DLP policies and admin settings stay exactly as they are.

Day 1
Connect the tenant, the gateway and Entra
Agen reads the agents in the tenant and the connectors they use. Every action resolves to a person through Entra ID or any IdP.
Day 1
Join BrowserShield early access
BrowserShield is running with design partners now. It deploys to managed browsers through Intune or the MDM you already have.
Week 1
Run observe-only
See every agent in the tenant, every connector action and every assistant in use before enforcing anything.
Week 2
Turn on the policies that matter
Start with secrets at the paste, financial writes and external sends. People only notice the crossing action.
The platform

Discover, Govern, Shield. One policy plane.

The same three capabilities govern Microsoft 365 Copilot and every other agent you run, internal and external.

Expand a capability

Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.

  • Agentless and API-based across five surfaces
  • First-party, custom, and third-party agents alike
  • Every agent mapped to an owner, approver, and escalation
Agen Discover AI agent discovery flow: any identity provider, productivity suites and assistants, cloud, gateway, endpoints, and MCP server registries all feed one agent registry where every AI agent is inventoried, risk-scored on arrival, given a named human owner, and shadow AI is surfaced.
Discovery pulls from five surfaces into a single agent registry — no SDK self-registration required.
ClosesWhich agents are running that nobody registered?
no SDK required5 surfacesowner-mapped
Discover in depth →

FAQ

Questions, answered.

Does Agen replace sensitivity labels, DLP and Copilot admin controls?
No. Keep them. They govern the tenant. Agen stops the leak at the paste in every assistant, decides agent actions at the gateway, and extends the same policy to every agent outside the Microsoft stack.
Can Agen govern what Copilot grounds on in SharePoint?
Grounding happens inside Microsoft's cloud, so no browser or gateway sits in that path. That is a permissions clean-up. Agen's verdicts apply at the paste and to every agent action that reaches your systems through the gateway.
How are Copilot Studio agents governed?
Each agent is discovered, assigned a named owner, and decided per action at the gateway for every connector it uses. Copilot Studio has its own page covering agents built by business teams.
Does this block people from using Copilot?
No. Guardrails, not blanket blocks. People keep using Copilot. Only the leaking paste or out-of-policy action stops, and the person sees why.
How is this priced compared with Microsoft's governance add-ons?
Agen is priced per governed agent and platform, not per user per month. The comparison is on the Copilot governance page.

Govern Microsoft 365 Copilot without the per-user tax.

Company data stopped at the paste in every assistant, every agent decided at the gateway, a named owner behind each one.