Agent governance (Module B)

A live inventory of every Copilot Studio agent in your tenant, with owners, status and risk flags.

Agent governance — Module B — gives you a live inventory of every Copilot Studio agent (and legacy Power Virtual Agents bot) in your tenant, with its owner, status and any risk flags. It is built from read-only metadata: Copilot Insights catalogues agents but never reads the conversations they hold or the content they process.

What the inventory captures

Each agent appears as a row you can sort and filter. For every one, the inventory records the essentials you need to govern it:

  • Name and source — what the agent is called and the platform it lives on.
  • Created and status — when it appeared and whether it is draft, published or disabled.
  • Ownership — the accountable owner, where Microsoft exposes it.
  • Risk flags — the governance concerns described below.

Risk flags

Flags are the fastest way to triage a large estate. Sort by flag to bring the agents that need attention to the top.

FlagWhat it meansTypical action
No ownerAn orphaned agent with no accountable ownerAssign an owner or retire it
UnusedPublished but with little or no recent activityConfirm it still earns its place
Sensitive dataConnected to knowledge or data sources that may carry sensitive informationReview its scope and access
PublishedLive and reachable by usersConfirm the exposure is intended

A governance baseline over time

Every scan records the state of your agent estate, so Copilot Insights tracks a governance baseline you can watch move. New agents, newly orphaned ones and changes in flag counts show up scan over scan — turning ad-hoc clean-ups into an ongoing discipline. Your highest-priority fixes surface in Recommendations.

What live mode can and cannot see

In live mode, basic inventory is discovered through Microsoft Graph — reliably giving name, source, created date and status. Deeper detail such as owner, connected channels and knowledge sources depends on what Microsoft's APIs expose, and can be partial for some agent types. Where a value is unavailable, Copilot Insights shows it as unknown rather than guessing.

Read-only, always

Copilot Insights can see that an agent exists and how it is configured at a metadata level, but it cannot edit, publish, disable or delete it. Governance changes are made by your administrators in the Power Platform admin centre. See Security & privacy.

Where to go next

  • Start with any No owner or Sensitive data agents — usually your biggest risks.
  • Work through your prioritised Recommendations.
  • See the whole estate in context on the Overview dashboard.

Frequently asked questions

Why is an owner shown as unknown?

Microsoft's APIs do not expose owner and detail data consistently for every agent type. When we cannot read it reliably we show unknown rather than guess — the agent still counts in your inventory and flags.

Does Copilot Insights read what our agents say to users?

No. It inventories agents from metadata only and never accesses conversation content. See Security & privacy.

What counts as an agent?

Copilot Studio agents and legacy Power Virtual Agents bots discovered in your connected tenant. On Free the inventory is capped at 5 agents; paid plans lift the cap — see Plans & billing.