Building and customizing solutions using Microsoft 365 Copilot APIs and tools
Copilot Agents – Need for Organizational Ownership and Permission Delegation Model
Product
Microsoft Copilot / Copilot Studio / Agents
Category
Feature Request / Governance / Security
Description
Hello,
I would like to raise a functional and governance concern regarding the current permission model for Copilot agents.
Current Behavior
When a Copilot agent is developed and published:
- The creator (individual user account) becomes the sole owner.
- Only this creator can grant permission for others to install or use the agent.
Problem
This design introduces a significant operational and governance risk:
- If the creator leaves the organization, loses access, or changes role:
- No other user can grant permissions for the agent.
- The agent effectively becomes orphaned and unmanaged.
- Business continuity is impacted.
- This is not aligned with enterprise governance models, where assets must be owned and managed at team or organizational level.
- The agent effectively becomes orphaned and unmanaged.
- No other user can grant permissions for the agent.
Expected Behavior
Organizations should be able to:
Assign ownership to a group instead of an individual, such as:
- Security group
- Microsoft 365 group
- Distribution list
- Team (Teams / Entra ID)
- Multiple owners - Admin roles - Shared service accounts Transfer ownership: - From an individual to a group - From one user to another - Automatically upon user departure (lifecycle management) Ensure continuity: - Agents remain manageable and usable even if the original creator is no longer present
- Distribution list
- Microsoft 365 group
Suggested Enhancements
- Introduce an “Agent Ownership Model” similar to:
- SharePoint sites
- Power Automate flows
- Power Apps (co-owners concept)
- Enable:
- Co-owners / maintainers
- Organization-level ownership
- Admin override capability
- Provide integration with:
- Microsoft Entra ID groups
- Governance / lifecycle policies
- Microsoft Entra ID groups
- Organization-level ownership
- Co-owners / maintainers
- Power Automate flows
- SharePoint sites
Business Impact
Without this capability:
- Enterprises face governance gaps
- Risk of critical solution lock-in
- Increased operational dependency on individuals
- Reduced adoption of Copilot agents in enterprise scenarios
Use Case
In our organization:
- Agents are developed within teams (not individuals)
- They are intended to be used and maintained by:
- Multiple consultants
- Support teams
- Governance owners
- Support teams
- Multiple consultants
However, the current limitation prevents us from safely scaling agent usage.
Request
Please consider implementing:
- Group-based ownership
- Multi-owner permission delegation
- Ownership transfer capabilities
This is essential for enterprise-grade adoption and governance of Copilot agents.
Product
Microsoft Copilot / Copilot Studio / Agents
Category
Feature Request / Governance / Security
Description
Hello,
I would like to raise a functional and governance concern regarding the current permission model for Copilot agents.
Current Behavior
When a Copilot agent is developed and published:
- The creator (individual user account) becomes the sole owner.
- Only this creator can grant permission for others to install or use the agent.
Problem
This design introduces a significant operational and governance risk:
- If the creator leaves the organization, loses access, or changes role:
- No other user can grant permissions for the agent.
- The agent effectively becomes orphaned and unmanaged.
- Business continuity is impacted.
- This is not aligned with enterprise governance models, where assets must be owned and managed at team or organizational level.
- The agent effectively becomes orphaned and unmanaged.
- No other user can grant permissions for the agent.
Expected Behavior
Organizations should be able to:
Assign ownership to a group instead of an individual, such as:
- Security group
- Microsoft 365 group
- Distribution list
- Team (Teams / Entra ID)
- Multiple owners - Admin roles - Shared service accounts Transfer ownership: - From an individual to a group - From one user to another - Automatically upon user departure (lifecycle management) Ensure continuity: - Agents remain manageable and usable even if the original creator is no longer present
- Distribution list
- Microsoft 365 group
Suggested Enhancements
- Introduce an “Agent Ownership Model” similar to:
- SharePoint sites
- Power Automate flows
- Power Apps (co-owners concept)
- Enable:
- Co-owners / maintainers
- Organization-level ownership
- Admin override capability
- Provide integration with:
- Microsoft Entra ID groups
- Governance / lifecycle policies
- Microsoft Entra ID groups
- Organization-level ownership
- Co-owners / maintainers
- Power Automate flows
- SharePoint sites
Business Impact
Without this capability:
- Enterprises face governance gaps
- Risk of critical solution lock-in
- Increased operational dependency on individuals
- Reduced adoption of Copilot agents in enterprise scenarios
Use Case
In our organization:
- Agents are developed within teams (not individuals)
- They are intended to be used and maintained by:
- Multiple consultants
- Support teams
- Governance owners
- Support teams
- Multiple consultants
However, the current limitation prevents us from safely scaling agent usage.
Request
Please consider implementing:
- Group-based ownership
- Multi-owner permission delegation
- Ownership transfer capabilities
This is essential for enterprise-grade adoption and governance of Copilot agents.
Happy to provide further details or participate in discussions if needed.
Microsoft Copilot | Microsoft 365 Copilot | Development
2 answers
Sort by: Most helpful
-
Deleted
This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.
Comments have been turned off. Learn more
-
Deleted
This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.
Comments have been turned off. Learn more