Copilot agents at work, explained
What Copilot Studio and the agent builders actually do, and the questions to ask before your organisation switches them on.
Jamie Owen Updated 26 Sept 2026 fast-moving: check a current source
Microsoft's agent platform is its fastest-moving Copilot area. Treat the specifics as a snapshot.
An agent, in Microsoft’s world as everywhere else, is an assistant that acts rather than only answers: it looks things up, follows a process, and takes steps in your systems on its own. Copilot is how most organisations will meet their first one, so it is worth knowing what the pieces are before somebody in your business builds one on a Friday afternoon.
Where they come from
Ready-made ones first. Microsoft includes agents in the Copilot experience, aimed at work like research and data analysis, and software vendors publish their own to sit alongside their products.
Then the built-in agent builder: a light way for anyone with a licence to make a simple agent out of written instructions and a few files, for example one that answers questions from your team’s policy documents. Genuinely useful, and exactly the kind of thing that spreads through a department before IT hears about it.
Copilot Studio is the full platform, and the one with a budget attached. Agents built there can reach into business systems through connectors, meaning ready-made links to another product such as Salesforce or your HR system. They can run multi-step workflows, hand work to one another, and be governed centrally. This is where “automate the intake process” projects live, and where the meter usually starts.
Microsoft’s pricing says people with the paid licence can build and use agents inside the organisation “at no additional cost” on its standard harness (the machinery between the model and the agent that decides what to call when), and that charges by consumption begin when an agent runs on the heavier GitHub Copilot harness. The GitHub Copilot version has been generally available since September 2026 for reasoning-heavy work. Charges also begin when an agent reaches beyond licensed colleagues: people without a licence, or anyone outside the organisation. Work out what a busy month would cost before a pilot turns into something the business depends on.
Cowork is the ready-made version of the same bargain: Microsoft’s own system, which it now calls “agentic” to set it apart from the agents above, handed a whole task and billed by the credit rather than built by you. What it does and what it costs is a page of its own.
The questions that matter more than the features
What can it reach? An agent pointed at a SharePoint site inherits every sharing mistake in that site. Its answers are only as private as the worst-shared file it can see. The reach now extends past Microsoft 365: federated connectors, generally available since September 2026, query outside systems live using the person’s own sign-in, without copying the data into Microsoft’s index.
What happens when it reads something malicious? Prompt injection, where instructions hidden inside a document or an email get followed as though you had typed them yourself, applies to Copilot agents exactly as it does everywhere else. An agent wired into mail and business systems is a more interesting target than a chatbot.
Who owns it once the person who built it changes job? An unowned agent answering policy questions from a document that stopped being true in March is a small governance failure on a timer. Since July 2026 every new Copilot Studio agent gets its own identity in Microsoft Entra, the directory that holds your staff accounts, so IT can control it the way it controls an account. That helps. It still does not assign anyone to keep the answers true.
Microsoft has been building out the administrator’s side of this through 2026, most visibly Agent 365, which it calls “the centralized control plane for managing agents”: an inventory of every agent in the organisation, with controls and usage reporting for each. That tells you two things. The tooling exists, and enough organisations lost track of their agents to make it necessary.
Treat every agent as a small system with an owner, a data scope, and a review date. The build tools make creation easy; nothing makes maintenance automatic.
If you are the person who has to make this safe at scale, the rollout guide covers where agents fit into a wider Copilot deployment.
Sources
Everything above was checked against these on 26 Sept 2026. Providers change things without notice. If a detail matters to a decision, follow the link.