Keep Copilot healthy: review, remove and retire access
Enabling a feature is only the start. Every licence, agent, connector, Cowork pilot and automation should have an owner, purpose, review date and clear end-of-life action.
Last reviewed 2026-09-05
Lifecycle health check
| Stage | Questions to ask |
|---|---|
| Before enabling | What problem are we solving? Who owns it? Who needs access? What data is involved? What is the cost/risk? Which actions need human approval? What will we test before release? When will we review it? |
| While in use | Is it being used? Is it producing value? Are costs within expectations? Are permissions and source documents still appropriate? Are approval gates still in the right places? |
| Review | Is the owner still in post? Is the project active? Are all users still appropriate? Are sources current? Have evaluations or representative tests been rerun after material changes? Should access be reduced? |
| Retire | Remove users or groups, revoke unnecessary connectors, archive agents or flows, reclaim licences where appropriate and record the decision. |
What should be reviewed regularly?
At minimum: Microsoft 365 Copilot licences, Cowork access and spending, shared agents, work-grounded agents, connectors, Power Automate flows, Copilot Studio agents, privileged data sources and any pilot or temporary security groups.
Suggested minimum register
For shared or higher-risk capabilities, record: name, purpose, owner, users/group, data sources, permissions, connectors, allowed actions, human-approval gates, licence or credit dependency, risk level, test/evaluation evidence, date enabled, last reviewed, next review and retirement status. A Microsoft List is enough to start if no dedicated tooling exists.
Related guidance
Sources
- Microsoft 365 Copilot documentation — checked 2026-09-05
- Review the Copilot Studio implementation checklist — checked 2026-09-05
- Microsoft Copilot Studio roadmap: September 2026 governance and evaluation updates — checked 2026-09-05
