Back to library
Advanced & governed: Cowork, enterprise automation and agent governanceMedium - reduces orphaned access, stale agents and unnecessary spend riskUpdated 5 SeptNo AI needed

Run periodic access and lifecycle health checks

An awarding organisation periodically reviews Copilot licences, Cowork access, agents, connectors and automations to remove stale access, confirm owners and retire projects that have ended.

Where the action happens

Microsoft 365 admin / governance process

Product or feature needed

Lifecycle governance and health checks

AI required

No - governance task

Extra credits

No for the review itself

Technical skill

Medium to high

Risk level

Medium - reduces orphaned access, stale agents and unnecessary spend

Licence dependency

No additional licence required for the governance principle; specific admin tooling may vary.

Credit dependency

No for governance checks; the services being reviewed may consume credits.

UK availability

available

What it can do

  • Prompts organisations to assign owners and review dates when features are enabled.
  • Checks whether users, agents, connectors and automations are still needed.
  • Supports offboarding when staff leave or projects end.
  • Reviews costs, permissions, source currency and orphaned flows or agents.

Limitations

  • The exact controls available depend on the Microsoft service and tenant.
  • Health checks require named ownership and admin access to relevant reporting.

Prerequisites

  • An inventory or register of higher-risk/shared AI capabilities is recommended.

Workarounds

  • Where automated inventory is unavailable, maintain a simple Microsoft List or controlled register with owner, purpose, users, sources, review date and retirement status.

    No premium licensing needed. External dependency: Governance process.

Notes

Lifecycle model: Discover → Unlock → Enable → Use → Govern → Review → Retire.

Watch-outs for Advanced & governed

  • Cowork has been generally available worldwide since 16 June 2026 for Microsoft 365 Copilot customers, but admins still control discoverability and must enable usage-based billing before users can run tasks.
  • Cowork consumption is measured in Copilot Credits; organisations can set user or group limits and users can check approximate task cost with /cost.
  • UK Cowork does not require Anthropic/Claude. Microsoft separates Cowork access from model availability; if Anthropic is disabled, Cowork users can continue with allowed non-Anthropic models such as GPT models.
  • For UK organisations, model-provider choice should be recorded as a governance/configuration decision because Anthropic availability has separate admin and data-processing considerations.
  • For Work IQ or other connected agent tools, start read-only where possible and enable write operations only for a justified use case with appropriate identity and approval controls.
  • Treat Cowork access like any other temporary or role-based capability: record owner, purpose, limit and review date, and remove access when the user or project no longer needs it.
  • Agent governance becomes more important as shared, action-taking and connected Agents accumulate; maintain an inventory before the estate becomes hard to understand.
  • Use human approval or an equivalent controlled handoff before high-impact actions where the technology supports it, and keep human accountability for regulated AO decisions.

Last checked: 2026-09-05

Disclaimer: Always follow your organisation's internal guidance and policies regarding AI usage. The suggestions in this guide have been created to the best of accuracy, but Microsoft licensing, pricing and feature availability change frequently — treat them as a planning baseline, not a procurement quote.

Community feedback

Has your organisation tried this? Confirm whether it's possible, whether it's useful, and share any tips.

0

Confirmed possible

0

Reported not possible

0

Found it useful

0

Not useful

Add your feedback

Used to verify feedback comes from a real organisation. Never displayed publicly.

Is this possible in practice?

Is it useful?

Loading feedback…