Home

Keep Copilot healthy: review, remove and retire access

Enabling a feature is only the start. Every licence, agent, connector, Cowork pilot and automation should have an owner, purpose, review date and clear end-of-life action.

Last reviewed 2026-09-05

Lifecycle health check

StageQuestions to ask
Before enablingWhat problem are we solving? Who owns it? Who needs access? What data is involved? What is the cost/risk? Which actions need human approval? What will we test before release? When will we review it?
While in useIs it being used? Is it producing value? Are costs within expectations? Are permissions and source documents still appropriate? Are approval gates still in the right places?
ReviewIs the owner still in post? Is the project active? Are all users still appropriate? Are sources current? Have evaluations or representative tests been rerun after material changes? Should access be reduced?
RetireRemove users or groups, revoke unnecessary connectors, archive agents or flows, reclaim licences where appropriate and record the decision.

What should be reviewed regularly?

At minimum: Microsoft 365 Copilot licences, Cowork access and spending, shared agents, work-grounded agents, connectors, Power Automate flows, Copilot Studio agents, privileged data sources and any pilot or temporary security groups.

Suggested minimum register

For shared or higher-risk capabilities, record: name, purpose, owner, users/group, data sources, permissions, connectors, allowed actions, human-approval gates, licence or credit dependency, risk level, test/evaluation evidence, date enabled, last reviewed, next review and retirement status. A Microsoft List is enough to start if no dedicated tooling exists.

Related guidance

Sources

Related