Why agents need a different governance model from Copilot
Microsoft 365 Copilot answers as the signed-in user, inside that user’s permissions, and changes nothing. A Copilot Studio agent can run under its own identity, reach data through connectors the user never sees, and take actions — create a record, send a message, start a flow — on the user’s behalf or on a schedule with no user at all. That is why the controls that make Copilot safe are necessary but not sufficient for agents: an agent also needs an identity of its own, limits on what it may join together, an approval step before it acts, a log of what it did, a way to switch it off and a test that proves it behaves. The eight controls below are that model, and the engagement installs it around the agents you already have.
The eight controls
Identity — Entra Agent ID
Every agent gets its own identity in Microsoft Entra, with the same Conditional Access, lifecycle and ownership rules a service account would have: who created it, who owns it, what it may reach, when it expires. No agent runs as a shared user or under a maker's personal credentials.
Connectors and data-loss prevention
Connector classification (business, non-business, blocked) scoped per environment so an agent cannot join Dataverse or SharePoint data to a consumer service; endpoint filtering for HTTP and custom connectors; the DLP-for-Copilot and sensitivity-label behavior inside the agent's knowledge sources verified rather than assumed.
Actions and approvals
The line between an agent that answers and an agent that acts. Actions that change business data — create a record, send a message, start a workflow, spend money — are catalogued, classified by blast radius and gated by human approval steps, with the approver, the evidence and the fallback defined before the action is published.
Knowledge sources and grounding
What the agent may ground on — which SharePoint sites, Dataverse tables, connectors and public sources — and what it may not; Restricted Content Discovery and label enforcement on the sources; generative-answer settings reviewed so the agent cannot be steered outside its scope.
Logging and audit
Agent conversations, tool calls, actions and approvals captured in Purview audit and, where the risk warrants it, forwarded to Sentinel with detection rules for prompt injection, data exfiltration patterns and out-of-hours action spikes — so an incident has a trail and a regulator has an answer.
Shutdown and lifecycle
A named owner, a review date and a kill switch for every agent: who can pause it, how fast, and what the users see. Agents whose owner leaves, whose connectors change or whose review lapses are suspended automatically rather than running on until someone notices.
Testing and release
Agents move through development, test and production environments as solutions, with a test plan that covers grounding accuracy, refusal behavior, injection resistance and action safety, and with the results attached to the release record. No agent is published to Teams or Microsoft 365 Copilot straight from a maker's environment.
The registry and the operating model
An agent inventory — Agent 365 or the Copilot Studio admin inventory, reconciled — that lists every agent, its owner, its identity, its connectors, its actions and its review date, and a governance board that meets on a cadence. Surface 8 of TAR-8, applied to agents.
The five deliverables
Agent inventory and risk classification
Every Copilot Studio agent in the tenant (published, unpublished, orphaned), its owner, its identity, its connectors, its knowledge sources and its actions, classified by the data it can reach and the changes it can make.
Governance policy set
Environment strategy, connector DLP policies, Entra Agent ID standards, approval rules for actions by blast radius, logging and retention settings, and the lifecycle policy — written as configurations and change requests your administrators execute, not as a policy binder.
Reference agent pattern
One production agent rebuilt inside the governance model — identity, connectors, grounding, an approved action, logging, a kill switch and a passed test plan — as the template every subsequent agent follows.
Test plan and evidence pack
The test cases for grounding accuracy, refusal, injection resistance and action safety, the results for the reference agent, and the audit-log samples that show the trail — the evidence a risk committee or an auditor asks for.
Operating model and roadmap
The registry, the review cadence, the governance board, the maker enablement path and the order in which existing agents are brought under the model. Delivered with a 90-minute executive readout.
How the engagement runs
Every agent, published or not, with its owner, identity, connectors, knowledge sources and actions; each classified by the data it can reach and the changes it can make. The orphaned and the over-privileged surface here.
Environment strategy, connector DLP groups, Entra Agent ID standards, approval rules by blast radius, logging and retention, lifecycle and shutdown — written as configurations and change requests, reviewed with your administrators and security lead.
One production agent rebuilt inside the model in a non-production environment, tested against the plan, released through the pipeline, and documented as the template. Existing agents are sequenced for the same treatment.
The registry reconciled, the governance board and review cadence set, maker enablement designed, and the 90-minute executive readout delivered with the evidence pack.
Why EPC Group
- Agents governed as part of the tenant, not beside it. The model is surfaces 1, 2, 6 and 8 of the published TAR-8 standard applied to agents, so it fits the Copilot, Purview and Entra controls you already run.
- Scale: 300+ Copilot initiatives, 300+ AI implementations, 70+ Fortune 500 organizations served; Microsoft consulting since 1997.
- Microsoft Solutions Partner holding all six designations, including Security and Business Applications.
- G2 Leader — seven consecutive quarters (4.4/5 on G2).
- Proof, not logos. Contracted engagement records are published, redacted, in the EPC Group Evidence Center.
- Senior architect on every statement of work — the person who scopes the engagement leads it.
Frequently Asked Questions
What is Copilot Studio agent governance consulting?
A fixed-scope engagement that puts every Copilot Studio agent in your tenant under one governance model before — or, more commonly, after — the agents have started touching business data: an identity for each agent in Microsoft Entra (Entra Agent ID), connector and DLP policies, approval gates on actions, governed knowledge sources, audit logging, a shutdown control and lifecycle, a test plan and release process, and a registry with an owner and a review date for every agent. EPC Group delivers it with a senior architect end to end.
Who is it for?
Organizations that have enabled Copilot Studio — often through a pilot or a business unit — and now have agents they cannot fully inventory, agents running under makers' personal identities, or agents with actions that nobody approved; and organizations about to build their first production agent in a regulated industry who want the model in place before it is needed. Healthcare, financial services, public sector and energy are the usual callers.
What is Entra Agent ID and why does it matter?
Entra Agent ID gives an AI agent its own identity in Microsoft Entra, distinct from the person who built it and from any shared account. It means Conditional Access, permissions, lifecycle and audit apply to the agent as a first-class principal: you can see what the agent did, restrict where it can act, expire it, and answer "when this agent acted, who was it?" — the first surface of TAR-8, applied to agents.
What counts as an action, and how are approvals handled?
Anything that changes state outside the conversation: creating or updating records in Dataverse or Dynamics 365, sending email or Teams messages, starting Power Automate flows, calling an HTTP endpoint, initiating a purchase. The engagement catalogues every action, classifies it by blast radius and reversibility, and gates the consequential ones behind human approval steps with a named approver and an audit record. Read-only agents need none of this; acting agents need all of it.
How do connectors and DLP fit in?
Copilot Studio agents use Power Platform connectors, so Power Platform data-loss-prevention policies apply. The engagement classifies connectors into business, non-business and blocked groups per environment, so an agent in the production environment cannot pass Dataverse or SharePoint data to a consumer service, adds endpoint filtering for HTTP and custom connectors, and verifies that sensitivity labels and DLP-for-Copilot behave as expected inside the agent's knowledge sources.
What does the logging cover?
Agent conversations, tool and connector calls, actions taken and approvals granted, captured in Microsoft Purview audit with the retention your regulator expects, and forwarded to Microsoft Sentinel where the risk justifies detection rules — prompt-injection patterns, exfiltration-shaped queries, action volume out of hours. The evidence pack in the deliverables shows what the trail looks like for the reference agent.
What is the shutdown control?
Every agent has a named owner, a review date and a documented way to pause it within minutes — who can do it, what users see, and how it is logged. Lifecycle rules suspend agents whose owner has left, whose connectors have changed or whose review has lapsed. An agent nobody can switch off is the single most common finding in the inventories we build.
How are agents tested before release?
Through development, test and production environments as Power Platform solutions, with a test plan that covers grounding accuracy against the intended sources, refusal of out-of-scope requests, resistance to prompt injection and the safety of every action, and with the results attached to the release record. The reference agent in the deliverables ships with its passed test plan as the template.
How long does the engagement take, and what do you need from us?
Six to eight weeks for a single tenant: inventory and classification, then the policy set, then the reference agent and its test plan, then the operating model and the readout. We need an executive sponsor, the Power Platform and Copilot Studio administrators (read access to start; write access for the reference agent in a non-production environment), the security lead for Purview and Sentinel decisions, and the makers of the agents in scope. Multi-tenant estates are scoped up front.
How does this relate to the Copilot readiness assessment and to agentic AI governance?
The Copilot readiness assessment scores the whole tenant on the eight TAR-8 surfaces and treats agents as surfaces 6 and 8. This engagement goes deep on agents alone. The agentic AI governance practice covers the wider program — Agent 365, the seven-layer framework, policy for agents built outside Copilot Studio. Most clients start with the assessment, take this engagement when agents are in production, and move to the vCAIO retainer to keep the registry alive.
How is it priced?
Fixed-scope, priced after a scoping call that confirms the number of agents, environments and tenants in scope; there is no rate card. Microsoft licensing — Copilot Studio capacity, Power Platform premium connectors, Sentinel ingestion — is quoted at Microsoft list price. Contracted engagement records for comparable governance work are published, redacted, in the EPC Group Evidence Center.
Related EPC Group services and references
- • Microsoft 365 Copilot Readiness Assessment (TAR-8)
- • Agentic AI governance and Agent 365
- • Copilot Studio agent development
- • Microsoft Copilot consulting (hub)
- • Power Platform Center of Excellence
- • AI governance consulting
- • Microsoft Entra ID consulting
- • TAR-8 — the eight-surface tenant AI readiness standard
- • EPC Group Evidence Center — contracted engagement records
Book the scoping call
Thirty minutes with the architect who will lead the engagement. Bring the list of agents you know about; we will tell you how to find the ones you do not, and what the first two weeks look like.
Before the October 19 / November 2 cut-overs, read the Copilot usage-based billing defaults on (Oct 19 / Nov 2, 2026): the 12-step spending-policy playbook.
Related reading
- The EPC Group Engagement Charter: Our Promise to Every Client
- EPC Group Marks FRBNY eDiscovery Role During TARP as Governance Discipline Powers 2026 Copilot
- "I Lied to You About the Send Actions." Vibe Slop, Part 2: When the Agent Tells You It Did Something It Didn't
- Chicago Microsoft Copilot Enterprise Consulting
- Dallas Microsoft Copilot Enterprise Consulting
