Run periodic access and lifecycle health checks
An awarding organisation periodically reviews Copilot licences, Cowork access, agents, connectors and automations to remove stale access, confirm owners and retire projects that have ended.
Where the action happens
Microsoft 365 admin / governance process
Product or feature needed
Lifecycle governance and health checks
AI required
No - governance task
Extra credits
No for the review itself
Technical skill
Medium to high
Risk level
Medium - reduces orphaned access, stale agents and unnecessary spend
Licence dependency
No additional licence required for the governance principle; specific admin tooling may vary.
Credit dependency
No for governance checks; the services being reviewed may consume credits.
UK availability
available
What it can do
- Prompts organisations to assign owners and review dates when features are enabled.
- Checks whether users, agents, connectors and automations are still needed.
- Supports offboarding when staff leave or projects end.
- Reviews costs, permissions, source currency and orphaned flows or agents.
Limitations
- The exact controls available depend on the Microsoft service and tenant.
- Health checks require named ownership and admin access to relevant reporting.
Prerequisites
- An inventory or register of higher-risk/shared AI capabilities is recommended.
Workarounds
Where automated inventory is unavailable, maintain a simple Microsoft List or controlled register with owner, purpose, users, sources, review date and retirement status.
No premium licensing needed. External dependency: Governance process.
Notes
Lifecycle model: Discover → Unlock → Enable → Use → Govern → Review → Retire.
Watch-outs for Advanced & governed
- Cowork has been generally available worldwide since 16 June 2026 for Microsoft 365 Copilot customers, but admins still control discoverability and must enable usage-based billing before users can run tasks.
- Cowork consumption is measured in Copilot Credits; organisations can set user or group limits and users can check approximate task cost with /cost.
- UK Cowork does not require Anthropic/Claude. Microsoft separates Cowork access from model availability; if Anthropic is disabled, Cowork users can continue with allowed non-Anthropic models such as GPT models.
- For UK organisations, model-provider choice should be recorded as a governance/configuration decision because Anthropic availability has separate admin and data-processing considerations.
- For Work IQ or other connected agent tools, start read-only where possible and enable write operations only for a justified use case with appropriate identity and approval controls.
- Treat Cowork access like any other temporary or role-based capability: record owner, purpose, limit and review date, and remove access when the user or project no longer needs it.
- Agent governance becomes more important as shared, action-taking and connected Agents accumulate; maintain an inventory before the estate becomes hard to understand.
- Use human approval or an equivalent controlled handoff before high-impact actions where the technology supports it, and keep human accountability for regulated AO decisions.
Sources
Last checked: 2026-09-05
Community feedback
Has your organisation tried this? Confirm whether it's possible, whether it's useful, and share any tips.
0
Confirmed possible
0
Reported not possible
0
Found it useful
0
Not useful
Loading feedback…
