Tenzing logoTenzing

    Definition

    What is Copilot Studio governance?

    Definition

    Copilot Studio governance is the model that controls how custom agents built in Microsoft Copilot Studio are designed, approved, deployed and monitored. It covers who can build agents, what data and actions they can use, how they are reviewed before release and how their behaviour is evidenced in production.

    Last updated: 21 July 2026

    Key points

    • Copilot Studio agents can read data, take actions and call external systems. Governance sets the guardrails before they do.
    • Three practical tiers: Minimum Viable Security, Recommended and Enterprise-Ready. Each raises the bar on controls and evidence.
    • Core controls: environment strategy, maker permissions, data connections, DLP, human approval gates and monitoring.
    • It is distinct from Microsoft 365 Copilot governance because agents introduce build-time and run-time risk that Copilot alone does not.
    • Owners: security, platform, information governance and the business sponsor of each agent.

    Why Copilot Studio needs its own governance

    A Copilot Studio agent is a small application. It has knowledge sources, tools, actions and users. Left ungoverned, a citizen developer can build an agent that reads regulated data, connects to an external API and acts on behalf of hundreds of users. Governance decides what is allowed, who signs it off and how it is monitored.

    What Copilot Studio governance covers

    Governance is applied across the agent lifecycle rather than as a single control.

    • Environments: separate dev, test and production Power Platform environments with defined DLP policies.
    • Makers: role-based access to Copilot Studio and controlled use of premium connectors.
    • Design review: risk classification, data source review and approval gates before publish.
    • Data and actions: allow-listed connectors, sensitivity label enforcement and least-privilege service accounts.
    • Run-time: telemetry, prompt and response logging, escalation paths and content filters.
    • Change control: versioning, rollback and periodic re-review of live agents.

    The three governance tiers

    Tenzing's Agentic Governance Framework groups controls into Minimum Viable Security, Recommended and Enterprise-Ready. Most organisations start at Minimum Viable Security for early agents and move to Recommended for anything touching customer, financial or regulated data.

    Frequently asked questions

    How is Copilot Studio governance different from Microsoft 365 Copilot governance?

    Microsoft 365 Copilot uses the signed-in user's permissions and cannot take autonomous actions. Copilot Studio agents can call APIs, run flows and act on behalf of users. That extra capability needs build-time review, environment controls and run-time monitoring that standard Copilot governance does not require.

    Who should be allowed to build Copilot Studio agents?

    Set a maker policy. Most organisations restrict production agent building to a small trained group, allow prototyping in a sandboxed environment for a wider audience and require review before an agent moves to a shared or customer-facing environment.

    What controls prevent a Copilot Studio agent leaking data?

    Data Loss Prevention policies on the Power Platform environment, allow-listed connectors, sensitivity label enforcement, service accounts scoped to least privilege and monitoring of prompts and responses. The Agentic Governance Framework lists the specific controls per tier.

    Do we need a review board for Copilot Studio agents?

    For any agent that touches regulated data or customers, yes. A lightweight review board with security, information governance and the business sponsor is enough. For internal, low-risk agents a documented self-attestation and a periodic audit is often sufficient.

    Related reading

    Speak with Tenzing

    A 30-minute discovery call to review your Microsoft environment and set a safe path forward with Copilot and AI agents.

    Book a 30-minute discovery call