Examine IT governance controls for agents
Governance for agents combines identity, licensing, billing, permissions, data protection, agent management, and lifecycle practices. These controls help organizations make agents available without expanding access to protected content.
Protect data with existing permissions
Agents in SharePoint use sites, pages, and document libraries as knowledge sources. When an agent responds, it applies the signed-in user's permissions to those sources. Access to an agent doesn't grant access to its underlying content.
SharePoint provides controls that also apply to agent knowledge, including site permissions, restricted access control, restricted content discovery, and Microsoft Purview Data Loss Prevention policies. Organizations should address oversharing and outdated permissions before making broad use of agents.
Control access and availability
Administrators and site owners can use several layers of control:
- Licensing and service plans determine whether licensed users can use Microsoft Copilot experiences in SharePoint.
- Pay-as-you-go policies grant eligible security groups consumption-based access to agents in SharePoint.
- Agent file permissions determine who can access or edit a specific
.agentfile. - Source permissions determine which knowledge an agent can use for each person.
- Site controls determine whether agent features are available and which agent opens from the site's Agent icon.
- Microsoft 365 admin center controls allow administrators to review and block agents for use in Microsoft Copilot.
Blocking an agent in Microsoft Copilot doesn't necessarily block the same agent in every host. Administrators should apply controls in each supported host and verify the current scope of those controls.
Manage the agent lifecycle
An agent can become inaccurate when its instructions, sources, or business context change. Organizations should define a lifecycle that includes:
- An accountable owner and intended audience.
- Approved knowledge sources and sharing settings.
- Testing for accuracy, citations, and permission behavior.
- Periodic review of instructions, sources, access, and usage.
- A process to update, block, or remove agents that are no longer needed.
Users should verify important responses against cited sources. Agent owners should also avoid placing secrets or instructions in an agent configuration when those details shouldn't be visible to people who can edit the agent.
Apply responsible AI practices
Agents can produce incomplete or incorrect responses. Governance should include user guidance, human review for consequential decisions, and a way to report problematic output. These practices complement technical controls and help users understand when an agent is appropriate for a task.