Home

For IT, admins and governance

Admins control many of the hidden doors users discover later. This page helps turn feature requests into proportionate enablement decisions with clear ownership, cost, permissions and review dates.

Last reviewed 2026-09-07

Before enabling something new

CheckAdmin question
PurposeWhat specific work problem is this solving?
AccessWhich named users or groups need it, and for how long?
DataWhat sources and sensitive information could it reach?
ConfigurationWhat tenant settings, connectors, models or dependencies are required?
CostIs there a licence, capacity or consumption dependency and what limit will apply?
OwnershipWho owns the capability and who takes over if they leave?
ReviewWhen will usage, permissions, value and risk be checked again?
RetirementHow will access, connectors, agents or flows be removed when no longer needed?

Choose proportionate safety controls rather than only enable/disable

ControlWhat it gives you
Read-only accessLets Copilot or an Agent use context without allowing it to change connected systems. A good default when the use case is research, summarisation or advice.
Narrow sources and permissionsLimits the blast radius by giving the capability only the sites, lists, data and users it genuinely needs.
Sandbox and test dataLets makers experiment without exposing live operational or sensitive information.
Designed execution identityPrevents shared Agents and flows from becoming an unintended extension of the maker's personal permissions.
Human approval gatesLets an Agent prepare or propose an action while requiring a person to approve selected tool calls or process steps before execution.
Evaluation before publishProvides evidence that representative and edge cases have been tested before other people depend on the Agent.
Pilot groups and spending limitsConstrains who can use a capability and how much usage-based spend can accumulate while value and risk are still being tested.
Review and retirement datesStops temporary access, Agents, connectors and automation from becoming permanent by accident.

Prefer scoped enablement

For higher-impact features, use pilot groups or tightly scoped access rather than broad tenant-wide enablement. Define success criteria, prohibited data, spending controls and a review date before the first user starts.

Awarding-organisation risk boundaries

Use extra caution where AI or automation could touch candidate data, safeguarding, HR, malpractice, appeals, complaints, reasonable adjustments, assessment decisions or regulatory evidence. Technical controls do not replace human accountability, policy or an appropriate DPIA/risk assessment where required.

Build review and offboarding into the grant

When enabling licences, agents, connectors, Cowork, automation or shared knowledge sources, capture an owner and next review date. Offboarding and project closure should trigger a check for licences, security-group membership, agent ownership, connectors, flows, shared sources and any continuing consumption.

Related guidance

Sources

Related