Knowledge for better technology decisions
Knowledge BaseAI FinOps & Governance

AI Governance · FinOps · Microsoft 365

AI Agent Governance: Who may build agents, who owns them - and who controls the costs?

Once early experiments expand into broader adoption, technical functionality alone is no longer enough. Organisations must govern data access, accountability, lifecycle, usage, cost, and business value together.

Governance is more than security.

Good agent governance creates reliable guardrails so organisations can develop, deploy, monitor, and, when necessary, retire AI agents in a controlled way.

  1. 01Start with the business outcome
  2. 02Align controls with risk and reach
  3. 03Assign ownership across the lifecycle
  4. 04Measure cost and business value together
01

Start with the desired outcome - not the agent

Before an agent is built, its intended value should be clear. Only then should the organisation decide which type of agent, knowledge sources, actions, and delivery channel are required.

EXAMPLE
An HR agent should answer recurring questions about leave, travel expenses, and internal policies, reducing response time within HR service operations.
  1. 01Which process or problem should be improved?
  2. 02Who will use the agent?
  3. 03Which tasks may it perform autonomously?
  4. 04Which data does it genuinely need?
  5. 05How will success be measured?
  6. 06What happens after an incorrect answer or action?
Why this order matters:

A clear use case helps prevent the creation of a technically interesting solution that later has neither a clear purpose nor an accountable business owner.

02

Not every agent needs the same controls

A personal agent with limited access has a different risk profile from an enterprise-wide agent that processes sensitive information or takes action in third-party systems. Microsoft describes a zoned governance model.

01

Personal productivity

Individual experiments and personal assistance with limited reach.

Governance levelFoundational guardrails and restricted sharing.
02

Team collaboration

Agents for departments or clearly defined user groups.

Governance levelStronger controls, managed deployment, and business ownership.
03

Enterprise managed

Critical, sensitive, or organisation-wide agents.

Governance levelFormal reviews, central management, and continuous monitoring.
PersonalTeamEnterpriseBroader reach = stronger governance

A small experiment does not automatically require the same approval process as a business-critical enterprise agent. Within the Microsoft environment, Environment Groups, rules, and Environment Routing can help makers begin in the appropriate environment from the outset.

03

Policy, process, and people must work together

Technical tools alone do not create effective governance. Policies set the framework, processes make it operational, and people take accountability.

POLICY

What is allowed?

Policies define the organisational framework.

  • Agent types and use cases
  • Data, connectors, and models
  • Sharing, publishing, and cost limits
PROCESS

How is it implemented?

Processes translate guardrails into repeatable operations.

  • Use-case and risk assessment
  • Testing, approval, and ALM
  • Monitoring, escalation, and retirement
PEOPLE

Who is accountable?

Governance requires authorised, capable, and accountable people.

  • Business and technical owners
  • IT, security, and privacy
  • Licence management, FinOps, and CoE
Practical principle:

Not every organisation needs a large new committee immediately. However, every production agent needs clearly assigned business and technical ownership.

04

Secure data access before adoption scales

An agent does not automatically solve existing permission problems. It can reveal them more quickly - or amplify their impact.

01

Knowledge sources

Is the content current, approved, and correctly classified?

02

Identity

Does the agent use the user's permissions or a technical identity?

03

Permissions

Are SharePoint, Dataverse, APIs, and third-party systems connected according to least privilege?

04

Protection rules

Which DLP, sensitivity label, Purview, and connector rules apply?

Assess early:

Confidential information must not unintentionally appear in answers or actions. This review belongs before broad adoption - not after a security incident.

05

Control connectors, channels, and sharing

Many agents do more than answer questions. They can start workflows, modify records, or interact with external systems. This increases both value and risk.

LOWER IMPACT

Provide information

The agent searches, summarises, or answers questions within a clearly defined information domain.

HIGHER IMPACT

Modify systems

The agent creates, approves, transfers, or deletes data and triggers further process steps.

  • Which connectors, tools, and external endpoints are used?
  • Which actions may the agent perform?
  • When is user confirmation required?
  • Through which channels is the agent available?
  • Who may use, share, or publish it?
  • How are users and the agent authenticated?

The more consequential the action, the more important testing, approval, logging, and a clearly defined rapid shutdown mechanism become.

06

Assign ownership across the full lifecycle

An agent is not finished when it is published. Knowledge, processes, permissions, models, and connected systems all change over time.

  1. 01

    Idea and assessment

    Is there a clear use case, an owner, and a measurable outcome?

  2. 02

    Development

    Is the agent being built in the correct environment and within the applicable guardrails?

  3. 03

    Testing and approval

    Have functionality, security, privacy, cost, and failure scenarios been assessed?

  4. 04

    Publication

    Who may use the agent, and through which channels?

  5. 05

    Operations and monitoring

    Does the agent remain reliable, secure, and economically viable?

  6. 06

    Change

    Who reviews new data sources, prompts, models, connectors, or actions?

  7. 07

    Retirement

    When will the agent be disabled, and how will connections and permissions be cleaned up?

Plan for succession:

If an owner leaves the organisation or changes role, the agent must not continue operating without appropriate business and technical oversight.

07

Connect inventory, monitoring, and reporting

An organisation can govern only what it knows exists. A central view should show which agents exist, who owns them, what they use, and how they behave in operation.

01

Inventory

What exists where, who owns it, and how is the agent configured?

02

Monitoring

How are usage, quality, errors, and technical health developing?

03

Security

Which data access, connectors, or configurations create risk?

04

Value

How do adoption, cost, and business value relate to one another?

Depending on the scenario, the Microsoft 365 admin center, Power Platform admin center, Microsoft Purview, and additional monitoring tools can contribute. Governance, security, operations, and cost owners need a shared, complete view.

08

Create a trusted place for agents

If employees do not know which agents have been officially approved, duplicate development, uncontrolled sharing, and shadow AI can emerge quickly.

TRUSTED FRONT DOOR

Microsoft Agent Store

A governed entry point for approved Microsoft-built, partner-built, and organisation-built agents.

  • Make trusted agents easier to find
  • Distinguish unapproved solutions
  • Reduce duplicate development
  • Make ownership and support transparent
Important:

An Agent Store does not replace governance. It is the visible access point for agents that have already been assessed and approved against defined criteria.

09

Consumption and cost are part of governance

An agent can be technically secure and still become economically unsustainable. For consumption-based models, cost ownership, monitoring, and response paths must be clear before broad deployment.

PLAN

Before rollout

Define credits, capacity, billing model, cost centre, budget, and thresholds.

CONTROL

During operation

Monitor actual consumption, unusual deviations, and cost per successful transaction.

DECIDE

Regularly

Scale, optimise, or retire based on quality, usage, cost, and value.

The Power Platform admin center provides capabilities for reviewing Copilot Studio capacity and consumption, including views at environment and agent level. Depending on the billing model, caps or consumption alerts can help manage cost.

Put the Estimator in context:

The Microsoft Copilot Credit Estimator supports an initial volume estimate. It does not replace monitoring actual usage or assessing real economic viability. Read the Estimator article →

10

Do not measure success by the number of agents

A large number of published agents is not evidence of a successful AI strategy. What matters is whether an agent makes a measurable contribution to a business outcome.

01Active and returning users
02Successfully completed transactions
03Reduced processing or waiting time
04Quality and satisfaction
05Error and escalation rates
06Cost per successful transaction

A frequently opened agent is not automatically valuable. Equally, an agent with only a few users can create substantial value if it improves an expensive or critical process. Governance should regularly reassess whether continued operation remains worthwhile.

✓

15 questions for production-ready agents

If several of these questions remain unanswered, the agent may be technically ready but not yet operationally ready for production.

  • Which specific outcome should the agent achieve?
  • Who is the business owner?
  • Who owns technology and operations?
  • Which governance zone or risk class applies to the agent?
  • Which users or groups may use it?
  • Which data sources and content does it use?
  • Which identity and permissions does it use?
  • Which connectors, tools, APIs, and actions are integrated?
  • Which channels and sharing options are permitted?
  • Which security, privacy, and compliance reviews are required?
  • How were quality, failure scenarios, and unintended actions tested?
  • Which credits, capacity, and costs can arise?
  • Which usage, quality, security, and cost metrics will be monitored?
  • What is the escalation and shutdown process?
  • When will the organisation review whether the agent is still needed and creating value?
RELATED READING

Estimating Copilot Credits: What the Microsoft Estimator can - and cannot - tell you

Estimate credit volume, identify cost drivers, and adjust the forecast using real consumption.

As of August 2026

Product capabilities and preview status can change. For a specific implementation, always review the latest documentation and your organisation's security, privacy, licensing, and compliance requirements.

According to Microsoft, the Microsoft 365 Agents Deployment Blueprint is primarily scoped to agents created through Agent Builder in the Microsoft 365 Copilot app. Not every capability or control described therefore applies unchanged to every agent type, harness, channel, or licensing scenario. This page provides an accessible professional overview and is not binding security, privacy, compliance, or licensing advice.