DLP covers Microsoft surfaces. The paste goes elsewhere.
The person with a Copilot seat is also pasting into ChatGPT, Claude and Gemini. Company data pasted into those tools leaves no trace in any Microsoft log.
Microsoft 365 Copilot is grounded in the Graph, and the agents built on it act in Teams and across connected systems. Your people also use three other assistants the Microsoft stack cannot see. BrowserShield stops company data at the paste in all of them. The gateway decides every agent action that reaches your systems. Your people keep Copilot.

Copilot does not need a connector to reach company data. It is grounded in the Graph by default, and agents extend it further.
Microsoft's controls are the right controls to keep. They stop at the tenant boundary, and the agents built on Copilot are registered, not governed per action.
The person with a Copilot seat is also pasting into ChatGPT, Claude and Gemini. Company data pasted into those tools leaves no trace in any Microsoft log.
Copilot Studio agents get an identity automatically. That is an inventory entry. Nothing decides whether this action, on this record, in this run, should have paused for a human.
Copilot honours existing SharePoint permissions, including the overshared ones. That grounding happens inside Microsoft's cloud, and the fix is a clean-up measured in quarters.
The controls that reach beyond the tenant come as add-on licences and per-message agent billing. Governance cost scales with headcount, not with risk.
The gateway decides. Shield enforces where the gateway cannot see. For Copilot that is BrowserShield at the paste across every assistant, and the gateway on every agent that reaches your systems.
For Copilot the leak is the paste, in Copilot Chat and in the assistants outside the Microsoft stack, so BrowserShield does the work. AgenShield covers the Copilot desktop apps and coding agents on managed devices with the same policy.
Out-of-policy actions like touching production secrets or mass-deleting files are stopped before they execute. Everything else flows. Ships through your MDM.
Keys and sensitive data are recognised as they are pasted into AI tools, and the paste is blocked. Employees keep their tools. Only the leak stops.
Illustrative verdicts under a typical policy. Paste rows are BrowserShield. Agent rows are the gateway.
| Microsoft 365 Copilot action | Verdict | Why |
|---|---|---|
| Ask Copilot Chat a question with no company data in the prompt | allow | Nothing sensitive in the paste. The person keeps working. |
| Paste an API key or access token into Copilot Chat | deny | Recognised at the paste and blocked before it leaves the tab. The person sees why. |
| Paste customer records into ChatGPT on the same laptop | deny | Same policy, different tool. Blocked at the paste, the person is pointed to a governed path. |
| Copilot Studio agent creates a ServiceNow ticket | allow | A low-risk write, within policy, tied to the agent's owner, and logged. |
| Agent reads Dataverse records containing personal data | mask | The read runs. Personal data is masked at the gateway before it enters the model context. |
| Agent updates a Salesforce opportunity amount | human-in-the-loop | A financial write on a live system. The owner approves before it lands. |
| Agent sends email to an external address through the connector | step-up | Outbound to people outside the company. The owner confirms, the record shows it. |
| Autonomous agent runs a flow that deletes records | deny | Destructive, unattended, outside task scope. Blocked and the owner notified. |
Verdicts are illustrative defaults. Every row is a policy you write once and Agen enforces per action, per identity.
Thirty minutes on the way your teams already use Microsoft 365 Copilot. We show the verdict on each action, the named human behind the session, and the record it leaves. Bring your hardest question.
BrowserShield recognises the key as the prompt is composed and stops the paste. The person keeps working. The record shows who, what and when.
Your labels, DLP policies and admin settings stay exactly as they are.
The same three capabilities govern Microsoft 365 Copilot and every other agent you run, internal and external.
Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.
Company data stopped at the paste in every assistant, every agent decided at the gateway, a named owner behind each one.