Copilot Studio agent governance policy
Word document / 47 KB / 8 pages
Twelve numbered sections and two appendices, written to be adopted rather than admired. It covers who may build agents and in which environments, the approval gate before an agent talks to anyone outside the organisation, what an agent may be grounded on, who owns the credit budget, what has to be true before an autonomous action runs, and when an unused agent gets switched off. The clauses are specific enough to disagree with, which is the point. A policy nobody can argue with is a policy nobody has read.
- A completion table at the front for organisation, policy owner, effective date and review date
- An absolute prohibition on grounding an external-facing agent in tenant Graph data, and the reason it is absolute rather than advisory
- A mandatory monthly credit cap per agent, because Microsoft disables custom agents across the whole tenant at 125% of prepaid capacity
- Human-in-the-loop rules split by action class: read-only, reversible write, irreversible
- Testing and evidence before publication, including a measured cost per conversation rather than a forecast
- A roles table covering agent owner, environment admin, data owner, security and budget owner
- Agent register fields, and a publication approval record with signature lines
Who it is for. A platform lead or CoE who has been asked for an AI governance policy this quarter and does not want to start from an empty document.