Executive Summary
- The problem: Power Platform AI agents became easy to build before most tenants made them safe to run. Citizen-built agents reach sensitive data, Teams channels, and shared credit pools faster than review processes designed for apps and flows can follow.
- The ROI opportunity: The return is scale without proportional risk: more agents reaching production, fewer demoted after incidents, predictable consumption, and audit evidence produced by the build itself rather than reconstructed afterward.
- What changed in 2026: Microsoft made agent governance a platform capability, adding a unified inventory, credit caps, agent security controls, and configuration-time risk assessment, and stopped maintaining the CoE Starter Kit.
- What is still missing: The model. The sequence, the gates, and the ownership map are yours to build.
- The first move for a CEO: Ask the CIO for two sets of names: who owns each governance console, and who approves an agent before it is published.
Power Platform’s founding promise is that anyone can build. For years, that meant apps and flows, but now, it means agents: software that reads company data, reasons over and acts on it, often built and published by people outside IT.
The risk is rarely carelessness. Building AI agents using Power Platform is now about as hard as building a canvas app, and review processes designed for apps and flows were never sized for software that acts. An agent can reach sensitive data and a Teams channel before anyone has asked who owns it.
2026 solved half of the problem. Microsoft made agent governance a first-class platform capability, with controls for agent security, risk, inventory, and spend. The other half remains. Tools are not a model, and a control nobody sequences is a setting nobody checks.
The platform closed the tooling gap; this guide closes the model gap. It walks the governed build path from foundation to operating cadence, places each 2026 control at its station, and dates every Microsoft claim.
What Can You Build with Power Platform AI Agents?
A Power Platform agent is, for practical purposes, a Copilot Studio agent. Copilot Studio is the authoring surface; the rest of the platform supplies its data, its hands, and its reach. Four building blocks matter at decision altitude:
Orchestration: Generative orchestration lets the agent choose among authored topics, knowledge sources, and actions instead of following a scripted tree. Microsoft’s 2026 Release Wave 1 plan adds multi-agent orchestration and evaluations.[1]
Grounding: Agents answer from sanctioned knowledge: SharePoint sites, Dataverse tables, public websites, and uploaded files. Grounding decides what an agent knows, and therefore what it can leak.
Actions: Connectors and agent flows let the agent create a ticket, update a record, or route an approval. This is where an assistant becomes an actor.
Channels: Agents publish to Teams, Microsoft 365 Copilot, websites, and other endpoints. The channel decides who can reach the agent.
The spectrum runs from makers to professional developers. Makers author in the canvas. Pro-code teams extend through custom connectors and Dataverse APIs, and the 2026 plan adds Dataverse MCP servers and a Python SDK.[1] Teams deciding whether a workload belongs in Copilot Studio or on a hyperscaler platform can weigh the trade-offs in comparison of enterprise AI agent platforms.
Three use-case shapes justify the effort. Internal assistants answer policy, IT, and HR questions against governed knowledge. Process front-ends handle intake, triage, and case creation before handing off to flows. Controlled customer-facing agents sit on websites, where exposure demands the strictest gates.
This guide assumes the engineering fundamentals: when a problem warrants an agent at all, the core design patterns, and what it takes to run one in production. Our guide on how to build an AI agent covers those in depth; this piece follows the Microsoft low-code route. Teams on Salesforce will find the equivalent path in the guide to building agents with Agentforce.
What Does Power Platform Governance Look Like in Practice?
Power Platform governance has two layers. The classic foundation covers environments, Managed Environments, DLP, and Entra identity. A Wave 1 agent layer adds agent security controls, configuration-time risk assessment, a unified inventory, credit caps, and governance agents.
The order matters: the agent layer sits on top of the classic one and inherits its weaknesses.
The Classic Layer still does most of the work. Environment strategy decides where agents are born. Managed Environments add sharing limits, usage insights, and maker guidance. Data loss prevention (DLP) policies sort connectors into business, non-business, and blocked groups. Entra ID supplies identity and conditional access, and Dataverse security roles scope what an agent’s data layer exposes. Microsoft’s own 2026 framing is zoned: streamlined “Green Zone” governance for citizen makers, rigorous controls for enterprise-wide solutions.[2]
The Agent Layer arrived with 2026 Release Wave 1, which rolls out from April to September 2026. The status column below is as of 30 September 2026. Items the release plan lists without a confirmed general-availability date are marked as planned.
| Control | What It Governs | Status |
|---|---|---|
Power Platform inventory |
Every Copilot Studio and Agent Builder agent, agent flow, app and flow across environments; queryable in the admin center, by API and via Azure Resource Graph |
Available |
Copilot Credit allocation and per-agent limits |
Prepaid credits assigned per environment; monthly consumption limits per agent |
Available |
Agent security admin controls |
Sensitivity labels on data access, external user permissions, network connectivity |
Wave 1 plan; confirm per tenant |
Real-time risk assessment |
Security and compliance issues surfaced during agent configuration, before deployment |
Wave 1 plan; confirm per tenant |
AI-powered governance agents |
Continuous tenant monitoring with proposed remediations |
Wave 1 plan; confirm per tenant |
Git integration and deploy from Git |
Application lifecycle management with full audit trails |
Wave 1 plan; confirm per tenant |
One currency warning belongs here: Microsoft stopped publishing release plans in September 2026. New Power Platform capabilities now appear on the AI at Work roadmap.[1] Teams that track feature status should move their watch lists accordingly.
“A robust governance process and controls should be adhered to when building these AI agents through the entire SDL, starting with designing, building, deploying, and monitoring agents after they’re deployed.”
– Rajamma Krishnamurthy, Principal PM Architect Manager, Employee Experience, Microsoft Digital
The table lists tools; it is not a model. The next section puts each control at its station.
What is the Governed Build Path for Copilot Studio Agents?
The governed build path has six steps: foundation, intake, build with rails, publication gate, graded rollout, and operating cadence. A named platform control enforces each step, so governance happens inside the build rather than after deployment.
The path fuses building and governing because the cautionary tales happen in the gap between them. Tying each step to a control means the path survives staff turnover and busy quarters.
| Step | What Happens | Enforcing Control | Owner |
|---|---|---|---|
Foundation before authoring |
Agents are born in designated maker environments, with DLP applied and data access scoped |
Environment strategy, Managed Environments, DLP policies |
Platform admin |
Intake |
Three questions answered: what the agent is for, whose data it touches, who owns it |
Intake record linked to the inventory |
CoE |
Build with the rails on |
Grounding limited to sanctioned sources; actions only through approved connectors; risk signals read at configuration |
Connector policies, risk assessment in Copilot Studio |
Maker |
Publication gate |
Test evidence attached, owner named, channel scope approved before anything goes live |
Publishing and sharing permissions |
CoE with the data owner |
Graded rollout |
Pilot group first; tenant-wide release only on evidence |
Sharing limits, security-group scoping |
CoE |
Operating state |
Inventory watched, credits capped, audit on, reviews scheduled |
Inventory, per-agent credit limits, Purview audit |
Platform admin and compliance |
Two steps carry most of the weight:
Foundation decides most of an agent’s risk before a single topic is written. An agent built in the default environment inherits that environment’s permissiveness. An agent built in a maker environment with DLP applied cannot reach a blocked connector, however creative its author.
The publication gate turns governance from a hope into a checkpoint. Publishing should require three artifacts: a test record, a named business owner and an approved channel scope. Risk assessment belongs one step earlier, at configuration, and it only works if makers must resolve what it flags rather than merely see it.
The other steps are cheap. Intake takes ten minutes; a pilot group costs two weeks. Both keep an unowned agent away from sensitive data, at a fraction of the cost of cleaning up after one.
Seeking a Governed Build Path in Your Tenant: Foundation, Gates, and the CoE Model?
How Does Copilot Governance Work Across Copilot Studio’s Admin Consoles?
Copilot governance spans consoles owned by different teams. Platform admins run the Power Platform admin center, compliance runs Purview, identity runs Entra, security runs its threat tooling, and Microsoft 365 admins run their own admin center. The governance model must match who owns each console.
Microsoft’s own guidance shows why. Prepaid Copilot Credits can be shared across products managed in both the Power Platform and Microsoft 365 admin centers. Organizations using both are told to review consumption in both.[3] The budget has two owners.
The fix is an ownership map. Fill it in for your tenant this week:
| Control Domain | Console | Owning Team | Can See | Cannot See | Escalates To |
|---|---|---|---|---|---|
Environments, DLP, sharing, agent credits |
Power Platform admin center |
Platform admin |
Agents, flows, connectors, consumption per environment |
Sensitivity of the data an agent is grounded in |
CoE lead |
Audit, sensitivity labels, AI data security |
Microsoft Purview |
Compliance |
Agent interactions, label policy, audit logs |
Environment design and DLP posture |
Chief risk or compliance officer |
Maker and agent identity, conditional access |
Microsoft Entra |
Identity |
Who and what authenticates, and from where |
What an agent does after sign-in |
CISO |
Threat detection, network posture |
Microsoft Defender and Sentinel |
Security operations |
Anomalies and incidents |
An agent’s business purpose |
CISO |
Tenant-wide agent availability, Microsoft 365 credit policies |
Microsoft 365 admin center |
Microsoft 365 admin |
Agents surfaced in Microsoft 365 Copilot |
Power Platform environment controls |
CIO |
Inside Copilot Studio, three settings deserve standing policy. The first is sharing: who may share an agent, with whom, and with editor or viewer rights. The second is whether generative features and web grounding are allowed per environment. The third is whether end users must authenticate. Each maps to a row above.
Most teams know governance is cross-team; few run it that way, with named owners and escalation paths.
What Should a Power Platform Center of Excellence Do After the CoE Starter Kit?
A Power Platform Center of Excellence is now a function, not a kit. In May 2026, Microsoft updated its guidance: the kit is no longer actively maintained, and its core capabilities now live in admin center features such as Inventory, Usage, Monitor, Actions, and Licensing.[4]
Existing installations still run, but general issues are no longer reviewed; security vulnerabilities still go to the Microsoft Security Response Center.[5] Teams still deploying the kit are building on tooling Microsoft no longer develops.
What survives is the part that was never software. The CoE is an organizational capability that outlives its tooling. Its agent-era charter has five parts:
Enablement with Gates: Training, templates, and sanctioned patterns on one side; the publication gate and review cadence on the other. Neither works without the other.
A Maker Community with Rules of Engagement: Office hours, a pattern library, and clear lines on what makers may publish without review.
Stewardship of the Ownership Map: The CoE keeps the map from the previous section current. It does not need to own every console; it needs to know who does.
Metrics That Matter: Agents in production versus abandoned, gate pass rates, time from intake to publication, and incident counts.
Migration Discipline: Retiring a tool is a project.
For Starter Kit estates, the migration note is short. First, inventory what the kit does for you today, including the custom flows and reports teams built on top of it. Next, map each function to its admin center successor or to Microsoft’s recommended building blocks: the Power Platform CLI, the Power Platform API, the inventory API, and the Power Platform for Admins V2 connector.[5] Then retire the kit deliberately, on a set date, rather than by neglect.
What Does AI Agent Governance Look Like for Low-Code Agents?
AI agent governance for low-code agents has three layers. Platform controls set boundaries, lifecycle gates decide what ships, and human judgment decides what stays human. Agents earn autonomy on evidence, with approval gates wherever they touch money, employment, care, or rights.
“Agents operate at different autonomy levels and across different trust boundaries. When the same controls are applied indiscriminately, organizations encounter two common failure modes.”
– Shiva Varma, Senior Director Analyst, Gartner
Gartner’s research explains why the layering matters. It predicts that by 2027, 40%[6] of enterprises will demote or decommission autonomous AI agents over governance gaps found only after production incidents. The root cause is treating governance as binary: either locked down or fully trusted. Over-restrict simple agents and makers route around you; under-restrict autonomous ones and incidents follow.
The remedy is proportional governance, and it maps cleanly onto citizen development. A Copilot Studio agent earns each stage on evidence:
| Stage | What the Agent May Do | Evidence Required to Reach This Stage |
|---|---|---|
Tested |
Runs in a maker environment for its builder and reviewers only |
Intake complete; owner named; golden question set passed |
Pilot |
Published to a named pilot group |
Pilot feedback reviewed; accuracy checked against the golden set |
Broadly available |
Published to its approved audience |
Production behavior record; monitoring and consumption caps in place |
Acting on systems |
Writes, sends, or updates records |
Explicit human approval for consequential actions; approval workflow with audit trail; security review |
This is the low-code form of a principle set out in our guide to building AI agents: autonomy is earned, not declared. It also follows trustworthy AI principles, which hold that automation drafts and flags while humans own judgment. Approval gates sit wherever an agent touches money, employment, care, or rights, and no test score promotes an agent past that line.
One honest concession: makers will not build formal evaluation suites. The CoE should supply a lightweight version instead: a golden question set per agent type, a one-page pilot checklist, and graduation criteria written down before the pilot starts. Copilot Studio’s evaluation capabilities, part of the 2026 wave, make this cheaper to run.[7]
For the board, placement matters. This platform layer sits under the enterprise AI governance framework rather than replacing it. It is how policy set at the top becomes enforceable in a maker’s environment.
How to Manage Power Platform Security and Agent Costs in Production?
Power Platform security for agents rests on least-privilege connections, data boundaries enforced by DLP and environment design, audit through Purview, and credit caps. Azure budgets send alerts but do not stop Copilot Studio consumption; only allocation limits do.
The scale argument for discipline is now measured. Microsoft’s Cyber Pulse report[8], drawn from its own telemetry, found that more than 80% of Fortune 500 companies run active agents built with low-code or no-code tools. It also found that 29% of employees have used unsanctioned agents for work.
Gartner[9] expects the average Fortune 500 enterprise to have over 150,000 agents in use by 2028, yet only 13% of organizations believe their agent governance is right. The agents are already in the estate; the open question is whether anyone governs them.
Cost is governance too. Copilot Credits can be allocated per environment and capped per agent each month. One detail catches finance teams out: Azure budgets and alerts send notifications but do not stop Copilot Studio consumption.[10] Only allocation limits do, and that is the difference between a program and an invoice.
Microsoft’s own documentation adds two more reasons to act. It now details credit controls for agents built with the GitHub Copilot harness.[10] AI Builder credits seeded in Power Platform licenses are removed in November 2026.[11]
The operating cadence is maintenance. It means a quarterly inventory review, cleanup of orphaned agents when their owners leave, and annual owner attestation. An ungoverned agent estate degrades by default.
Build Governed Power Platform Agents with a Proven Framework
Where Does Damco Fit in Building Governed Power Platform Agents?
Damco builds Power Platform AI agents with the governance model included. That means environment and DLP foundations, governed Copilot Studio delivery, CoE modernization from the Starter Kit to the admin center, and a framework layer grounded in its published Trustworthy AI doctrine.
Damco’s Microsoft-stack engineering practice builds agents the way this guide describes, because in practice building and governing cannot be separated. Engagements typically cover four areas:
Foundation: Environment strategy, Managed Environments, DLP and identity design, sized to how your makers work.
Governed Build Delivery: Copilot Studio agents built with the path’s gates in place, from intake to graded rollout.
CoE Modernization: Moving Starter Kit estates to the admin center model deliberately, with the ownership map and the metrics the agent era needs.
The Framework Layer: Autonomy levels, graduation criteria, and approval gates, applied as per trustworthy doctrine.
Behind each low-code decision sits the engineering discipline set out in our guide to building AI agents, backed by three decades of experience in enterprise delivery. Damco sells no governance tool: the controls are Microsoft’s, and the advice concerns how to sequence them.
References:
- [1]: Power Platform 2026 release wave 1 plan
- [2]: Governance and administration, 2026 release wave 1
- [3]: Govern Copilot Credit consumption
- [4]: What’s new in Power Platform guidance
- [5]: CoE Starter Kit transition to Power Platform admin center
- [6]: Gartner: Uniform governance across AI agents will lead to failure
- [7]: 2026 release wave 1 plans for Dynamics 365, Power Platform and Copilot Studio
- [8]: Microsoft Security
- [9]: Gartner: Six steps to manage AI agent sprawl
- [10]: Manage costs for GitHub Copilot harness agents
- [11]: AI Builder credits and Copilot Credits
Frequently Asked Questions
Yes. Copilot Studio is Power Platform's agent-building surface. Makers combine generative orchestration, grounding in SharePoint, Dataverse, and websites, actions through connectors and agent flows, and publication to Teams, Microsoft 365 Copilot, and web channels. Pro-code teams extend agents through custom connectors and Dataverse APIs. Building is the easy part; placing governance inside the build is what makes agents safe to scale.
Power Platform governance combines platform controls with an operating model. The controls include environment strategy, Managed Environments, DLP policies, and Entra identity. Since 2026 Release Wave 1, they also include agent-specific controls such as the unified inventory, credit caps, and configuration-time risk assessment. The operating model sets the sequence, the gates, and who owns each console.
Not actively. Microsoft updated its guidance in May 2026 to state that the CoE Starter Kit is no longer actively maintained. The kit remains available, and existing installations run, but general issues are no longer reviewed. Its core capabilities now live in the Power Platform admin center, through Inventory, Usage, Monitor, Actions, and Licensing.
Govern them along the build path. Build in scoped maker environments with DLP applied, run a short intake, read risk signals at configuration, and gate publication on test evidence and a named owner. Pilot before a tenant-wide release, and cap credits per agent. Because Copilot governance spans the Power Platform admin center, Purview, Entra, and security tooling, assign an owner to each console.
An AI agent governance framework sets how agents are bounded, released, and supervised. For Power Platform, it has three layers: platform controls set boundaries, lifecycle gates decide what ships, and human judgment governs any decision touching money, employment, care, or rights. Agents earn autonomy on evidence, level by level, rather than receiving it at launch.



