LearnMicrosoft 365 Copilot › 5 · Agents

Copilot Studio, properly

Studio is Power Platform's child: environments, connectors, DLP and maker culture all apply — plus knowledge, topics, actions and channels of its own. Govern it like Power Platform or relive that movie.

The anatomy of a Studio agent

Part What it is Review question
Knowledge Grounding sources: SharePoint sites, files, connectors, websites Scope creep — 'the whole intranet' is not a knowledge source, it's a liability
Topics/instructions Behaviour: system prompts, conversation design Does it claim authority it shouldn't ('HR-approved answers')?
Actions Tools it can CALL: connectors, flows, APIs The blast radius — every action is an egress+write review
Triggers What starts it beyond chat (events, schedules) The autonomy line (next concept)
Channels Where it's published: M365 Copilot/Chat, Teams, web, custom Audience: internal pilot vs the whole company vs THE INTERNET

Under it all: an environment (dev/test/prod separation — the Power Platform discipline verbatim), Power Platform DLP governing which connectors may combine (already in the serv365 nightly scan — an ungoverned new environment is a drift alert you'll see), and since May 2026 an automatic Entra Agent ID per agent (governance concept).

The money mechanics

Studio runs on capacity (messages/credits): authoring licences for makers, consumption for usage — with the taxonomy concept's twist that custom engine agents reach unseated users through included Chat on credits. Budget consequence: a popular agent is a COST CENTRE with a growth curve; set the per-agent burn alerts before the success story does it for you.

The maker-governance loop (learned from Power Apps, applied to AI)

  1. Environments: makers create in dev; prod is promotion-only.
  2. DLP: connector combinations constrained BEFORE the first agent ships.
  3. Review at promotion: knowledge scope + action manifest + channel — the thirty-minute read (apps-module discipline, agent edition).
  4. Ownership: named owner + successor per prod agent (the flow-orphan lesson, third appearance in this curriculum — it keeps being the one that bites).

What to watch (proofs)

  • Environment census: Studio agents per environment (admin center / Power Platform admin) — prod agents outside the promotion path are the finding.
  • DLP truth: the Power Platform DLP policies in your scan — Studio obeys them; a Teams-connector + external-HTTP combination appearing is the exfil-path alert.
  • Per-agent burn: consumption analytics by agent — the cost curve, plus the zero-usage agents to retire.
  • Knowledge-scope drift: agent definition change events in audit — scopes that quietly widened are the precursor incident.

Discussion

No messages yet — start the thread.

Sign in with your email to join the discussion — we send a one-time link, no password.