If every agent build waits for review, Microsoft's numbers say the queue is holding adoption down: its internal maker count grew about tenfold once software approved low-risk builds and rejected high-risk ones. In its Customer Zero guide published October 8, 2026, Microsoft Digital reports active makers rising "from around 2,000 to 20,000 a month," about 150,000 personal development environments under governance, and "measured maker friction" falling from roughly 50% to 5%. The triage agent it credits, the Risk-O-Meter, sorts each submission green, yellow or red. The guide never says what puts a build in each bucket. That rubric is the part you would need to copy, and you will have to write it yourself.
Read the numbers as Microsoft's own claims about its own tenant. The guide gives no time window for the tenfold growth ("since we've put these efforts in place") and no definition of how friction was measured. They are still the most specific operating data any large company has published on letting thousands of employees build agents.
What Did Microsoft Actually Build?
Microsoft runs three building surfaces, each matched to a risk owner, and sends people to the cheapest one that does the job. The guide lays them out:
| Surface | Who builds | What it does | Who owns the risk |
|---|---|---|---|
| Microsoft 365 Copilot Agent Builder | Any knowledge worker | Information retrieval only | The platform ("intrinsic") |
| Copilot Studio | Citizen developers, business and Power Platform teams | Task completion, actions | The administrator ("configurable") |
| Foundry and Agent Toolkit | Software engineers, architects | Workflow automation | The organization ("explicit") |
Three internal agents automate the review work. The Risk-O-Meter "auto-classifies submissions as green, yellow, or red based on their risk profile," then auto-approves, auto-declines or routes the build to the right reviewer. An Action-O-Meter "applies the same logic to new connectors and MCP servers." A Friction Meter "surfaces maker pain as a first-class metric." Agents that sit idle hit "a 60-day inactivity threshold that triggers alerts and automated cleanup."
Everything around those agents is ordinary Power Platform and Microsoft 365 configuration. Copilot Studio builds are governed at the environment level, with data loss prevention policies set by the tenant admins and the Office of the CISO. Most employees get a pre-approved subset of connectors. Sharing is capped by purpose. Above all of it sits Agent 365, which Microsoft calls "the control plane for agents."
The scale behind that control plane is large. A companion Inside Track post from August 6 says Microsoft Digital has "visibility into more than 500,000 agents" through Agent 365, and that ownerless agents can keep running after their builders leave the company.
Why Did Over-Control Count as a Risk?
Microsoft's guide treats excessive control as a risk category of its own, because it moves the work somewhere you cannot see it. The guide's wording: "Over-restriction doesn't eliminate risk, but redirects it to shadow AI." A builder who waits three weeks for a review on a FAQ bot will paste the FAQ into a consumer chatbot instead.
The failures it lists are the ones most enterprise programs are living through now:
- People reached for the most powerful tool because it looked like "the safest choice," which added complexity a simple agent never needed.
- The wrong tool dragged in the wrong model. The guide says builders ended up "using something more complex and expensive instead of a lower-cost model that's ideal for a simpler scenario."
- Builders hit compliance reviews they didn't expect, and projects slowed while they learned the process.
- Some promising ideas were abandoned before they delivered anything.
- Agents sprawled, which forced ownership rules, a lifecycle policy and the 60-day cleanup.
The second item is really a cost problem. When the only sanctioned path for a Q&A agent runs through a pro-code platform, every Q&A agent inherits a pro-code model budget. Routing people to Agent Builder first is how Microsoft kept retrieval agents off the expensive tier.
The strongest objection deserves a hearing. Microsoft is selling the tools it describes, and a vendor's internal case study will always find that its products worked. The guide's three meters are internal agents, and Microsoft offers no product a customer can switch on to get them. What a customer can buy is the plumbing underneath. That makes the honest takeaway narrower than the headline numbers: the operating model is copyable, the triage logic is not shipped.
What Can You Copy Today, and What Do You Have to Write?
Most of Microsoft's setup is documented configuration you can turn on this quarter. The triage rubric is the exception.
Start with what ships. Environment routing sends new makers in Copilot Studio, Power Apps and Power Automate into their own personal developer environment instead of the shared default. The guide doesn't name the setting, but it is the documented way to end up with a personal environment per maker, which is what 150,000 governed personal environments implies. Every routed environment is a managed environment, preconfigured to block sharing with security groups and to cap sharing at five individuals. The developer environment inherits your tenant-level data policies. Routing is a premium governance feature, and anyone running an app or flow in a managed developer environment needs a premium license, so price that before you switch it on for everyone.
Those data policies are your enforcement layer. They can require Entra ID authentication, block knowledge sources (local files, SharePoint and OneDrive, public websites), block the HTTP request node, block skills, block publishing channels and block event triggers. Enforcement applies in every tenant, and the per-agent exemption is gone. One detail matters for the Action-O-Meter half of the model: blocking a Power Platform connector "also blocks access to tools in connected MCP servers," since those servers connect through connectors.
The 60-day cleanup is also partly built in. Power Platform's automatic cleanup disables personal developer environments that are managed environments after 60 days of inactivity, warns at day 53 and day 57, and deletes 15 days after disabling. Unmanaged developer environments use 30 days. You cannot turn the mechanism off. A scheduled flow running daily counts as activity, so a forgotten agent on a timer will never age out. Your own sweep has to cover that case.
The rubric is what you write. Nothing in the guide says what makes a build green, so here is a starting version assembled from the data-policy levers above. It is this publication's proposal; Microsoft has published nothing like it.
- Green (auto-approve): retrieval only, Entra ID authentication on, knowledge limited to sources the builder can already read, published only to Teams and Microsoft 365, shared with a handful of named people.
- Yellow (route to one reviewer): any action connector from the approved list, any public-website knowledge source, sharing with a security group, or any event trigger.
- Red (auto-decline with a path forward): no authentication, HTTP requests to unlisted endpoints, an unapproved connector or MCP server, or a public channel. A decline should name the fix or the next tier, or the builder leaves for shadow AI.
The Action-O-Meter equivalent is an allow-list with an owner. Every new connector or MCP server goes through one security review, once, and then becomes available to every green build.
How Do You Know the Program Is Working?
Measure maker friction alongside agent count, because a rising count can hide a falling success rate. Microsoft's Friction Meter treats "maker pain as a first-class metric," and the 50% to 5% drop is the number it chose to lead with. The guide doesn't define it, so define yours: the share of builds that are abandoned, or that wait longer than an agreed number of days, between first save and first publish.
Agent count also needs a second number beside it. In a CIO.com piece on agent savings, Glokal AI's Jeet Pattanaik worked a hypothetical service desk where an agent closes 40% of 10,000 monthly tickets for a paper saving of €60,000. After 15% of those tickets reopen and about €15,000 goes on checking the agent's work, the real saving is about €36,000, roughly 60% of the promise. Track how much of the agents' closed work comes back.
On inventory, Microsoft's cloud adoption guidance says every agent should be "recorded in a single organizational inventory" with owner, purpose, platform and access scope, and recommends starting with an "audit-based model" before tightening controls. If you don't license Agent 365, it points you to Entra Agent ID as the authoritative source for identities and ownership.
The registry has a price. Agent 365 lists at $15 per user per month, paid yearly, and is included in Microsoft 365 E7. Licensing attaches to the human: at the May 1, 2026 launch, agents acting on behalf of a licensed user were covered without a license of their own. Budget it per builder population, and check whether your makers sit inside or outside the E7 estate before you assume it is already paid for.
What to Do Before Your Next Governance Review
This Week:
- Pull last quarter's agent submissions and sort them by hand into green, yellow and red using the rubric above. If more than half land in yellow, your connector allow-list is too short.
- Ask your Power Platform admin whether environment routing is on. If makers still land in the default environment, that is where your unowned agents live.
- Write down your current median time from first save to first publish. That is your friction baseline.
This Month:
- Turn on environment routing for new Copilot Studio makers, scoped to one security group first, and check that tenant data policies apply to the routed environments.
- Run one security review per high-demand connector and MCP server, and publish the approved list where builders will find it before they ask.
- Add a sweep for agents with no owner or no human use in 60 days, including scheduled ones the platform's own cleanup counts as active.
Before Your Next Microsoft Renewal:
- Price Agent 365 against your actual builder population, and ask your account team in writing whether the triage agents Microsoft described will ever ship as a product.
The Bottom Line
The model Microsoft describes is the low-code governance pattern many IT teams already run for Power Apps: give everyone a sandbox, police the edges with policy, and delete what nobody touches. Agents raise the stakes because they act, and the guide's tiers split exactly there. Retrieval gets waved through and actions get reviewed. Microsoft published the outcome and kept the scoring logic, so the rubric your security lead signs is the piece of this you own. Get a first version on paper before the review queue grows past the builders waiting in it.
Continue Reading
- Human-in-the-Loop for AI Agents: Most Approval Gates Rubber-Stamp
- Microsoft Agent 365 Ships: The $99 SKU Is Not Your Bill
- The 44% Visibility Gap: Enterprise's Hidden AI Agent Crisis
- Okta vs Entra Agent ID vs SailPoint: Two Issue, One Governs
- Agent Audit Logging: Platform Logs Miss the Decision You Must Prove
- Microsoft's New Copilot Bills Autopilot Outside the $30 Seat
- Microsoft's MXC Agent Containers Ship Before Intune Can Manage Them
