Blogs

From Power Platform Governance to Agent Governance

Written by Kenneth Nicasens | Aug 10, 2026, 11:04:30 AM

Power Platform governance used to be a fairly clear conversation.

  • Who can create apps?

  • Who can create flows?

  • Which environments do we need?

  • Which connectors are allowed?

  • How do we avoid wild growth?

Important questions. Still relevant today.
But they are no longer enough.
Because AI changed the playing field.

With Microsoft 365 Copilot, Copilot Studio and agents, governance is no longer only about what people build. It is about what digital coworkers can access, understand, decide and do.

And that is a very different conversation.

The First Governance Challenge: Apps and Flows

For years, Power Platform governance focused on enablement with control.

Most organisations wanted the same thing: give business users the ability to solve problems, without creating chaos.

That meant putting structure around Environments, Data Loss Prevention policies, Connectors, Dataverse security, Solution lifecycle management, Application ownership, Flow monitoring, Support models, Maker enablement

The goal was never to block innovation. At least, it should not have been.

Good governance creates confidence. It gives people a safe space to build. It helps IT, security and the business speak the same language.

Bad governance says: “No, unless approved.”
Good governance says: “Yes, within clear boundaries.”

That mindset matters even more now.

AI Makes Governance Broader

Microsoft 365 Copilot introduced a new reality.

Copilot does not live inside one app. It works across Outlook, Teams, SharePoint, OneDrive, meetings, chats, documents and Microsoft Graph.

That means the quality of Copilot depends heavily on the quality of your Microsoft 365 environment.

  • If permissions are messy, Copilot reflects that.

  • If documents have no owner, Copilot finds them anyway.

  • If old content is still available, Copilot may use it.

  • If teams overshare information, AI makes that oversharing more visible.

So the governance question changes.

It is no longer only:

“Can this user build an app?”

It becomes:

“Should this user, Copilot or agent have access to this information, and what should it be allowed to do with it?”

That is the real shift.

From Citizen Developers to Agent Builders

Power Platform gave us citizen developers.

AI gives us agent builders.

That sounds like a small evolution, but it is not.

An app follows predefined logic.
A flow executes predefined steps.
An agent can reason, interact, retrieve information, call tools, and take action.

That means the risk profile changes.

With agents, we need to think about which data sources the agent can use, which actions the agent can perform, who owns the agent, who maintains the knowledge behind it, how usage is monitored, when human approval is required, how the agent is retired when it is no longer needed

This is where Power Platform governance and Microsoft 365 governance start blending together.

A Copilot Studio agent may use SharePoint as knowledge. It may trigger Power Automate flows. It may work inside Teams. It may connect to business systems. It may act on behalf of a user.

So who governs it?

  • Power Platform admins?

  • Microsoft 365 admins?

  • Security?

  • Compliance?

  • The business owner?

The answer is probably: all of them.

And that means we need an operating model, not just a technical configuration.

The Same Wild Growth, But Faster

Every Power Platform governance conversation eventually touches the same fear: wild growth.

  • Too many apps.

  • Too many flows.

  • No ownership.

  • No documentation.

  • No lifecycle.

  • No monitoring.

Now replace “apps and flows” with “agents”.

The same problem appears again, but faster.

Because agents are easier to create, more powerful, and often closer to sensitive business data.

That does not mean we should block them.

It means we need to govern them properly from the start.

The organisations that learned how to govern Power Platform already have an advantage. They understand environment strategies, DLP, ownership, adoption, lifecycle management, ...

Agent governance builds on those same principles.
But it extends them.

Enter Agent 365

This is where Microsoft Agent 365 becomes interesting.

Agent 365 is not about creating another governance document that nobody reads. The value is in visibility and control.

  •  Which agents exist?

  • Who owns them?

  • Where do they run?

  • Which identities do they use?

  • Which data can they access?

  • Which tools can they call?

  • Are they still needed?

  • Are they behaving as expected?

Without that visibility, agent adoption becomes the next version of shadow IT.

Or maybe better: shadow AI.

Agent 365 gives organisations a way to observe, govern and secure agents across the ecosystem. Not only agents created in one tool, but a broader agent landscape.

That matters because the future will not be one Copilot.

It will be many agents.

  • Personal agents.

  • Team agents.

  • Department agents.

  • Enterprise agents.

  • Agents with delegated user access.

  • Agents with their own identity.

  • Agents that collaborate with other agents.

At that scale, governance cannot be manual.

Three Levels of Agent Governance

A useful way to think about this is in zones.

Level 1: Personal Productivity

These are agents that help individuals.

  • Meeting preparation.

  • Research.

  • Summaries.

  • Personal task support.

The governance here should be light. Focus on awareness, training, responsible use and data handling.

Do not over-engineer this layer.

Level 2: Team Productivity

These agents support a team or department.

  • HR knowledge agents.

  • Project assistants.

  • Sales support agents.

  • Service desk intake agents.

Now ownership becomes important. So does knowledge quality, access control, usage monitoring and support.

This is where governance needs more structure.

Level 3: Enterprise Agents

These agents support business-critical processes.

  • Case management.

  • Procurement.

  • Customer service.

  • Incident handling.

  • Autonomous workflow orchestration.

Here governance must be strict.

  • Security review.

  • Lifecycle management.

  • Monitoring.

  • Human-in-the-loop controls.

  • Auditability.

  • Clear ownership.

  • Fallback procedures.

The more autonomy an agent gets, the stronger the governance needs to be.

Trust first. Autonomy later.

Governance and Adoption Belong Together

One mistake I often see is treating governance and adoption as separate tracks.

They are not.

If governance is too heavy, people avoid it.
If adoption runs without governance, chaos follows.
If security blocks everything, innovation moves into the shadows.

The balance is the hard part.

Power Platform taught us that successful governance is not only about policies. It is also about community, training, guidance, reusable patterns and support.

The same applies to AI.

People need to understand:

  • What Copilot can and cannot do
  • What data it can use
  • When not to use AI
  • How to validate output
  • How to design agents responsibly
  • When human approval is required
  • How to report issues

AI literacy becomes part of governance.

Not as a training checkbox, but as a real adoption capability.

The Bigger Shift

Power Platform governance started as a conversation about apps, flows and environments. Today it becomes something much broader. It is about governing an ecosystem where humans, copilots and agents work side by side.

This is not a replacement of Power Platform governance.
It is the next layer.

The Real Question

The question is not whether organisations should allow Copilot or agents.

They already are.

The real question is whether organisations can create enough trust to scale them safely.

Because AI without governance becomes risk.
Governance without adoption becomes resistance.
But governance with adoption becomes acceleration.

Power Platform governance was the training ground. It taught us how to enable innovation while keeping control. Now we need to apply that same thinking to Microsoft 365 Copilot, Copilot Studio and Agent 365.

Not to slow things down.

To make sure we can safely speed things up.

Governance is no longer just about controlling what people build. It is about enabling humans and digital coworkers to work together responsibly.

 

Need a clear view of your AI governance readiness?

This assessment helps you define the next steps for stronger AI agent governance.  Take the AI Agent Governance Assessment.