Beyond Cowork: AI Agent Governance in Microsoft 365
By | Published On: 20 August 2026 |

Microsoft Copilot Cowork was the moment AI stopped drafting and started doing. But Cowork is only one of the agents now working inside your Microsoft 365 estate, and most organisations have no idea how many others are already running, who built them, or what they can reach.

When Cowork went live, the conversation in most organisations was about what it could do. Draft the email, book the meeting, pull the recap together, post it into Teams, all with a human approving the important steps. We even wrote up five Cowork skills worth building, because the real prize was never a single clever task. It was standardising how work gets done.

That is genuinely exciting. It is also the moment when the ground shifted, and many organisations haven’t noticed yet.

Because Cowork isn’t a feature you switched on in isolation. It is the most visible member of a growing population of agents now operating inside your tenant, and the others are far quieter about their arrival.

 

From one assistant to a workforce of agents

For a couple of years, “AI in Microsoft 365” meant Copilot: a helpful assistant that responded when you asked. One person, one prompt, one answer. The blast radius of a bad response was small, because nothing actually happened until you made it happen.

That model has quietly been replaced.

You now have Cowork carrying out multi-step tasks on people’s behalf. You have makers across the business building their own agents in Copilot Studio. You have agents arriving bundled inside other software, and third-party agents connected through the wider ecosystem. Some were sanctioned by IT. Many were not. Most were created by well-meaning people solving a real problem in their own corner of the business, exactly as they were encouraged to.

Individually, each one is a small productivity win. Collectively, they are an estate. And an estate nobody is keeping a register of is not an asset, it’s a liability waiting for an audit.

 

Not sure where to start with Copilot or M365?

Book a free 30-minute consultation with our specialists.

We’ll help you uncover opportunities, quick wins and the right approach for change.

Gallagher
Konica Minolta
Johnson Controls
WH Smith
Main Line Health

 

The bit that actually changes the risk

Here is the shift that matters, and it is easy to miss because it sounds like a small upgrade.

Copilot reads your information and tells you things. Agents act on it.

An assistant that summarises the wrong document has embarrassed you. An agent that sends an email, updates a record, moves a file or posts in Teams based on the wrong document has done something, on your behalf, that you now have to unpick. The output isn’t a suggestion on your screen anymore. It’s an action in the world, with your name on it.

And every one of those agents operates with the permissions of the person who runs it. If a user can see it, the agent working for them can see it too, and increasingly, act on it. Which brings us to the problem most organisations were already sitting on, long before any of this could take action.

 

The oversharing problem you already had, now with hands

Ask almost any IT team about oversharing and you’ll get a knowing sigh.

The site that was shared with “everyone” in 2021 for one quick project and never locked down. The SharePoint library with inherited permissions nobody has reviewed. The sensitive spreadsheet sitting in a folder far more people can reach than should. For years these were latent risks. Nobody was likely to go looking, so nobody did.

Agents go looking. Not maliciously, just thoroughly. When an agent reaches across your content to complete a task, it surfaces whatever the user technically has access to, including all the things they can reach but were never really meant to. Oversharing stops being a theoretical exposure the moment something starts systematically reading across your tenant to be helpful.

This is why the honest answer to “should we roll agents out more widely?” is another question: do we actually know who can see what? If the permissions underneath are messy, giving capable agents free rein doesn’t create the mess. It just finds it, at speed, and acts on it.

If that landed a little too close to home, our Summer Reset guide to fixing your Microsoft 365 estate is a sensible place to start putting the house in order.

 

The hidden agent estate

There’s a second problem, and it’s about visibility rather than permissions.

Most organisations cannot answer three fairly basic questions about their own agents:

  • How many are there? Not Cowork, which you deliberately enabled, but the agents built by makers around the business, and the ones that arrived inside other tools.
  • Who owns each one? When the person who built an agent changes team or leaves, does anyone inherit it, or does it just keep running?
  • What can each one reach and do? What data does it touch, what actions can it take, and who approved that?

If those questions are hard to answer, you don’t have an AI strategy problem. You have an inventory problem. And you can’t govern, secure or cost-manage a population you can’t see. This is precisely the “hidden agent estate” we keep running into with clients, and it’s why so much of the current governance conversation has moved from how do we build agents to how do we run the ones we already have.

 

What “good” actually looks like

None of this is an argument for slamming the brakes on. The productivity gains are real, and the organisations that lock everything down out of fear will simply lose ground to the ones that move deliberately. The goal isn’t less agentic AI. It’s agentic AI you can see, own and trust.

In practice, that means a few things working together:

  • Visibility. A live picture of the agents running in your tenant, what they can access, and what they’re allowed to do, rather than a spreadsheet someone updated once in the spring.
  • Ownership. Every agent has a named owner and a lifecycle, so nothing keeps running unattended after its creator moves on.
  • Guardrails, not gates. Clear rules about what agents can be built, what data they can touch, and where human approval is required, set up so people can still move quickly inside safe boundaries.
  • A tidy foundation. Permissions, sensitivity labelling and sharing sorted out underneath, so an agent being thorough isn’t a risk.
  • Cost oversight. Agentic work is metered now, so someone needs a view of where the spend is going before it drifts.

That combination, visibility, ownership, guardrails, a clean foundation and cost control, is what turns a scattering of clever agents into an operating model you can actually stand behind.

 

Where to start

If you’ve enabled Cowork, or you know makers in your business are already building, the first move is not another pilot. It’s a straight look at where you stand: what’s running, what it can reach, and whether the ground underneath it is solid.

That’s exactly what our Governance and Readiness Assessment is built for. It gives you a clear picture of your agent estate and your data foundations, and a prioritised plan to close the gaps, so you can say yes to agents without losing control of them.

We’re also working through this in depth in our current webinar series on building an operating model for AI agents – from taming sprawl, to governance that still lets teams ship, to why an agent operations centre is fast becoming a thing organisations need rather than a nice-to-have.

 

Closing thoughts

Cowork was the headline, and rightly so. It’s the clearest sign yet that AI in Microsoft 365 has grown up from an assistant that helps you write into a workforce that gets things done.

But headlines have a habit of drawing the eye away from the quieter, more important story. The one worth paying attention to isn’t the agent you deliberately switched on and approved every step of. It’s all the others already working away in your tenant, with the permissions of whoever is running them, and no one keeping the register.

The organisations that win the next stretch won’t be the ones with the most agents. They’ll be the ones who can tell you, without hesitation, exactly what every one of them can see and do.

 

Share

Related Posts