Skip to content
Agent 365 Governance

Agents appear faster than anyone can govern them.

From ungoverned agents to a governed operating model in 90 days. Governance, token economy control and pilots taken safely to production.

The situation right now

Users build their own agents in M365 Copilot, with Copilot Studio and in Foundry. Most organizations don't know what agents run in their tenant.

.

Growth in active agents in Microsoft 365 over a year

.

Rise in AI interaction costs ($0.04 → $1.20 per agentic task in an enterprise environment)

0%.

Of organizations report a rise in AI-related security incidents

"The question is no longer what AI can do. The question is how you keep it secure, observable and accountable when it starts acting on its own."

Microsoft Agent 365 documentation
Two risks

Two risks that can materialize fast.

Both are solvable with a working governance model.

Risk Governance

Shadow agents

Agents get created with users' own tools. They reach emails, documents and line-of-business systems without the owners knowing. Data leaks go unnoticed until an audit reveals them.

Concrete impact

A privacy breach, a notice from the data protection authority, and internal data misuse cases becoming more common.

Risk Costs

Surprise costs

Cowork and agents consume Copilot Credit tokens per task. Without budget limits and governance the monthly invoice can be a multiple of the forecast. One user can run hundreds of tasks a week.

Concrete impact

A surprise invoice, AI initiatives put on hold, and leadership's trust in follow-up projects lost.

Three phases · 90 days

Three phases. 90 days. One goal.

We go through the current state, build the governance model and take one agent to production in a controlled way. Every phase ends in a concrete delivery.

Weeks 1–3

Discovery & Baseline

We go through the tenant together with your team: which fundamentals are in order, which agents already exist, who owns them and what they are used for.

Kick-off and project plan Assessment of the technical foundation: Entra, Defender, Purview, Power Platform Agent discovery: Agent 365 Registry in use Stakeholder interviews: IT, Security, Compliance, business
Baseline report · Checkpoint for leadership
Weeks 4–7

Governance model

We build a governance model that describes: who may create agents, who approves actions, what they have access to and how costs are controlled.

Agent Governance Policy Token Budget Framework: limits, spending policies, alerts Entra, Purview and Defender configurations for Agent 365 Lifecycle processes: onboarding, attestation, retirement RACI and escalation paths
Governance document + configured controls
Weeks 8–13

Pilot & Roadmap

Together we pick one agent to take from pilot to production in a controlled way. The governance model gets real use and the roadmap builds on the lessons.

Pilot agent selection: business value, risk level, measurability Deployment to Agent 365: registration, identity, controls Dashboards and telemetry by role A 4-week monitored run with weekly reports A 12-month roadmap and a wrap-up workshop
Final report · Pilot agent in production · 12-month roadmap
Workshops

We start from a shared understanding.

Before we make decisions about the governance model, we go through together what is being built and with which tools. Six workshops in which the governance model takes shape.

IT · Security · Leadership
WK 1

Agent 365 overview

What Agent 365 is, how the agent registry works, which technologies and controls do what. A live demo in your tenant.

Half a day · demo + Q&A
IT · Business
WK 2

Agent builders compared

Copilot Studio, M365 Agent Builder, Foundry and GitHub Copilot agents. We break down which tool fits which use case.

Half a day · demo of 4 tools
IT · Business
WK 3

Copilot Studio hands-on

A practical demo: building an agent with low-code tools. What is possible, and what is not worth doing.

Half a day · guided hands-on
Finance · IT · Procurement
WK 5

Token economy and cost control

Copilot Credits, the drivers of consumption, where the invoice comes from. What this means for budgeting, and how the FinOps controls work.

2 hours · cost calculator demo
IT · Key stakeholders
WK 7

Building the governance model

The governance model into practice: roles, responsibilities, escalation paths and decision-making.

Half a day · decision-making
Leadership · IT · Business
WK 13

Wrap-up workshop

The closing summary: pilot results, lessons and the 12-month roadmap.

One day · decisions on what follows
Cost control

Token economy control runs through every phase.

Copilot Credits made Cowork and agents consumption-based. Without active control the monthly invoice runs away fast.

What we build together
Token Budget Framework

Per user, team and department. Hard limits, soft limits and alerts, tied into the Microsoft Cost Management tools.

Spending Policies

Who may consume, on which models, how much. Disable-by-default and approval paths for large budgets.

Model Selection rules

Which model for which task. Affordable models as the default, premium models for a justified reason.

Cost Allocation model

Costs to the right business unit. Showback now, chargeback later.

What you get in hand
A predictable monthly invoice

No surprise costs. Budget reports to leadership monthly.

Cost-per-outcome metrics

We don't measure user counts. We measure value produced per credit consumed.

A FinOps for AI practice

The same discipline as with Azure consumption. IT, finance and the business speak the same language.

Alerts & anomaly detection

Odd consumption spikes are caught in days, not at the end of the month.

The same governance model scales as Cowork use grows. The foundation is built once, and it supports the whole AI portfolio.

Results

Where you are after 90 days.

Full visibility into agents

You know what runs in the tenant, who owns it and what data gets touched. The shadow agents era is over.

A predictable monthly invoice

Token budgets, limits and alerts running. The bill shock risk is off the table.

A governance model & documentation

Who decides, approves, owns and monitors. Clear responsibilities and escalation paths.

One pilot agent in production

A governed agent that gives you a validated model and concrete metrics for what follows.

A 12-month roadmap

What gets built next, in what order, and who builds it. Decisions with reasoning behind them.

E7 readiness made clear

You know where you stand in relation to Microsoft 365 E7 and what a sensible way forward is.

Concrete deliverables

What you'll have in hand after 90 days.

Discovery
Baseline report: current state, risks, priorities
Foundation assessment: Entra, Purview and Defender status
Agent inventory: all current agents, owners, risks
Stakeholder map: who decides, uses, pays
Checkpoint meeting for leadership
Governance
A governance document ready for use
Agent Governance Policy: rules for creating and using agents
Token Budget Framework: budgets and limits per unit
Spending policies configured into the M365 environment
Lifecycle processes and RACI: IT, Security, Business, Finance
Pilot & Roadmap
A production pilot agent running, under governance
Dashboards and telemetry with role-based views
Pilot results report: lessons, optimizations, metrics
A 12-month roadmap and an E7 readiness assessment
A wrap-up workshop and final report
After the 90 days

Continuous Governance.

The governance model is in place, but agents live and grow. The continuation model keeps governance up to date, for a fixed monthly fee.

  • Agent registry oversight

    Approval of new agents, cleanup of ownerless agents and lifecycle decisions.

  • Token consumption optimization

    A monthly cost report, anomaly investigation and savings recommendations.

  • Governance model updates

    Microsoft's new features, policy updates and regulatory changes folded into the governance model.

  • Stakeholder support and quarterly review

    Support for decisions and escalations in everyday work. A quarterly workshop: results, lessons and the direction for the next three months.

When this fits

Does this sound familiar.

Your organization uses Copilot and agents are starting to appear in different teams.

IT needs visibility into the agents before the costs run away.

You want a governance model that enables scaling, not one that blocks it.

Insights

Related reading.

Getting started

Underway in 2 weeks.

Once the agreement is signed, kickoff happens within two weeks and the 90-day clock starts. In a first conversation, we'll nail down the goals and the sizing.