01 September 2026
Copilot Agents: extend Copilot without losing the plot
Declarative and custom-engine agents for Microsoft 365 Copilot. Registry, permissions, and Wave 0 before autonomy.
DIGITAL SKILL WORKS LTD / 12 PANES
Agents extend Microsoft 365 Copilot with knowledge, skills, and workflows. They are not chat skins. They retrieve, summarise, and can take actions. Steady before scale still applies: identity, owner, and least privilege before autonomy.
What it is
Learn defines agents for Microsoft 365 Copilot as specialised AI assistants that automate workflows and securely retrieve information from Microsoft 365 and other enterprise sources. Two build approaches:
- Declarative agents — custom instructions, knowledge, and actions on Copilot’s orchestrator and models.
- Custom engine agents — your orchestrator and models, integrated into Microsoft 365 channels.
Prebuilt Microsoft and partner agents cover common functions. Makers can build with low-code (including Agent Builder) or pro-code (Microsoft 365 Agents Toolkit and related tools). Agents appear in Copilot Chat, Teams, Outlook, Word, and related surfaces subject to admin policy.
What it does
Agents can answer from scoped knowledge, call APIs, update records, send mail, and run multi-step processes inside Microsoft 365. Admins manage inventory in the Microsoft 365 admin centre (Agent Registry / Copilot Control System): approve, publish, pin, block, and review requests. Users discover agents in the Agent Store only when allowed. Declarative agents inherit Copilot security, compliance, and Responsible AI requirements when they use Copilot’s infrastructure.
Why you should care
Board. Agents multiply surface area. Ask for a registry and owners, not a catalogue demo.
CISO. Tool access and delegated permissions are the new privilege problem. Shadow agents are still agents.
CFO. Pay-as-you-go and capacity packs can outrun seat forecasts. Meter before you open maker culture widely.
Adoption. Good agents change work design. Bad agents create ticket noise and trust loss.
How it maps to 12 Panes
- Pane 03 Horizon: watch Agent Store and Frontier agents.
- Pane 04 Security: least privilege for makers and agents; break-glass.
- Pane 05 GRC: agent register, DPIA triggers, literacy.
- Pane 06 Cost & Value: message capacity and PAYG.
- Pane 08–09: adoption and task redesign.
- Pane 12 Frontier: sandbox new agents with kill criteria.
Suggested actions
- Stand up agent inventory and ownership in admin centre before broad maker enablement.
- Define allowed agent types and sharing rules (org-wide vs specific groups).
- Require Security review for agents with actions or external connectors.
- Add agents to the AI register with retention and incident paths.
- Pilot one declarative agent in a single cohort; measure task time and error rate, not install counts.
Communication needed
Security, GRC, and FinOps before makers. Adoption and Comms for user expectations: what the agent may do, what needs human approval, how to report harm.
Benefits and risks
Benefits. Scoped automation inside familiar apps. Reuse of Copilot grounding and compliance for declarative agents. Central admin lifecycle.
Risks. Sprawl. Over-privileged actions. Unowned shared agents. PAYG surprise. Frontier agents mistaken for GA.