Copilot Playbook
Copilot Playbook/Copilot Studio/The Copilot Studio Agent Engagement
Updated August 28, 2026
Engagement Guide · Seven Phases, Priced and Staffed

The Copilot Studio Agent Engagement

Seven phases from the first conversation to the retainer — what must be true in the tenant at each step, what the meter costs, which controls to set before launch, and what you are still being paid for two years later. For the customers you actually have: Business Premium, zero Copilot seats. The agent is never done, and that is the commercial argument.

Prepared by Ken Lince — Sr. Director, Cloud Engineering, TD SYNNEX · Practice guidance — not a statement of work, and not a pricing model

How to use this

Sections 2 through 8 are the seven phases in delivery order — each one states what you do, what you do not do, what has to be true in the tenant, and what it produces. Sections 9 through 12 are the reference material you reach for mid-engagement: the limits and silent failures, the Agent 365 trigger logic, and the free toolchain. Nothing here is argued. Where you want the reasoning, the evidence and its weaknesses — the Gartner cancellation data, the margin-trap case, the full source apparatus — the long-form background reference carries all of it, section by section.


1 · The Answer, On One Page

Your customer is on Business Premium, has bought zero Copilot seats, and wants an agent. Everything below assumes that as the starting condition.

The seat is not a gate

Start with zero Copilot seats. Copilot Chat is included with any Microsoft 365 or Office 365 subscription, and agents that use the customer's own data are billed on metered consumption. The seat is a capability upgrade you sell later on evidence, not an entry ticket you demand first on faith.

The plumbing swaps — it does not vanish

You still assess what you ground in. But an agent's blast radius is 25 named SharePoint sites, not the tenant graph — and every control involved is Power Platform configuration, reachable on Business Premium. No E-SKU, no SharePoint Advanced Management licence wall.

The meter is the recurring service

A flat monthly fee over a metered cost base is a margin trap. You do not fix it by pricing around the meter. You fix it by selling the management of the meter — estimate, cap, monitor, true‑up. Section 6.

7
Phases, first conversation to managed AgentOps
Two of them happen before anyone signs a build SOW
5
Copilot Credits per agent action MS list
Not the 25 the channel blogs repeat — a 5× over-quote
125%
Of prepaid capacity, at which custom agents are disabled
No user-facing warning. Your users find out first
90
Days between sponsor reviews once the agent is live
Microsoft's published rhythm — measure, review, scale or retire

1.1 · The three ways partners lose this deal

FAILURE 1

Starting at the build

The build is the part that is project-shaped, easiest to quote, and most competitive. Gartner's three named causes of agentic-project cancellation — escalating costs, unclear business value, inadequate risk controls — are phases 4, 2 and 1 skipped, in that order.

FAILURE 2

Gating on a Copilot seat

“Sell seats → prove adoption → then talk about agents” puts a per-seat commitment in front of a conversation the customer is already entitled to have. For most SMBs it is the reason the conversation never starts.

FAILURE 3

Flat fee over a moving cost base

The invoice is flat; prompts, actions and background runs are not. This is the most likely way to lose money on an agent that is working perfectly — and it is entirely a phase 4 failure.

1.2 · The seven phases at a glance

Read across, not down. Paper names the shape of the commercial instrument, never a rate — rates live in section 10 of the Frontier Partner Playbook. Week ranges for phases 2–5 are the build-side clock published in section 4 of the Ops Companion; phases 0, 1 and 6 have no equivalent there.

PhaseElapsedPaperWhat must be true in the tenantDetail
0 · Standing and visibilityOne conversation, 30–60 minNone. If you are writing paper here you have mistimed itAny Microsoft 365 or Office 365 subscription. No Copilot seat§2
1 · Agent governance baseline1–2 weeksFixed-fee assessment. Short-form — not the build SOWPower Platform admin access, plus AI Administrator or Global Reader. Nothing needs buying§3
2 · Candidate and baseline1–2 weeks · Weeks 1–2Assessment, or the first phase of the SOWNothing new. The constraint is organisational — somebody has to own the process§4
3 · Prerequisites and harness2 weeks · Weeks 2–4SOWA Dataverse environment, production or sandbox — trial and developer are not eligible for pay-as-you-go. A DLP policy separating Business from Non-Business connectors§5, §9
4 · Economics2–3 days, inside phase 3. It gates the quoteNone of its own — its output is the number the build SOW is written aroundCopilot Credit capacity packs. Per-agent monthly caps configured before launch§6
5 · Build and deployWeeks 4–8 simple, 4–14 complexSOW. The retainer is signed here, not laterCapacity live. On the GitHub Copilot harness your own dev and QA consume the customer's credits before publish§7
6 · Managed AgentOpsIndefinite. 90-day cycleRetainer — a managed services agreement, not a renewal of the buildCapacity and caps under active management. Agent 365 only when a trigger fires§8, §10
Phase 4 is the one you skip

Every other phase has an obvious owner and an obvious moment. Economics does not: it sits between the design work and the quote, produces no deliverable the customer asked for, and is the easiest thing to defer. So partners defer it — quote build labour, sign, ship, and let the customer meet the monthly run rate on a Microsoft invoice they were never shown a forecast for. The estimate takes days, the tooling is free and published by Microsoft, and the cap that prevents the worst outcome is a setting nobody has to buy.

↑ Contents

2 · Phase 0 · Standing and Visibility

P0Standing and visibility30–60 min · no paper · $0
Purpose
Establish that an agent conversation is available today, at their current licensing, and find the one workflow worth naming. This is the conversation you are already entitled to have with every Microsoft 365 customer on your base.
Do
  • Ask the six questions below.
  • State the licensing position plainly — see the line in section 12. Read Microsoft's own sentence rather than paraphrasing it.
  • If shadow AI is the visible symptom, run the discovery-led opening in the Shadow AI Assessment Guide instead.
Do not
  • Quote anything. You do not yet know the harness, and the harness sets the price.
  • Demo a prebuilt agent as if it were the deliverable. It wins the room and then becomes the scope. Section 7.
  • Promise a Copilot seat is unnecessary in perpetuity. It is unnecessary to start. Say that instead.
Output
A named candidate workflow with a named owner · a decision on whether to run the phase 1 assessment · nothing signed.

2.1 · The six opening questions

The first two decide whether phase 1 has a finding in it. The last two decide whether phase 2 has an owner. If neither pair produces a satisfying answer, this is an education conversation, not a deal.

  1. “Who here has already built an agent?” In most SMB tenants the honest answer is “several people, in Copilot Chat or Teams or Agent Builder, and nobody wrote them down.” That is the phase 1 finding, and it is live rather than theoretical.
  2. “What happens to an agent when the person who made it leaves?” Risks 5 and 10 in section 3 — dormant and orphaned agents — are unfixable without a named owner, and no build-time control creates one.
  3. “Do you have a Power Platform DLP policy separating Business from Non-Business connectors?” If not, the agent's real safety boundary does not exist yet. That is a phase 3 deliverable you have just scoped in one question.
  4. “Has anyone ever set a spend cap on any of this?” Nobody has. It is the day-one control almost nobody sets — and it costs nothing.
  5. “If I could automate exactly one process, which one would you name?” Phase 2 needs one named workflow, not a portfolio. A customer who names three has not chosen.
  6. “Who owns that process, and can they give me two hours?” If the process owner is not available, phase 2 has no baseline, and the renewal conversation two years out has no evidence in it.
Closing Phase 0

“You do not need to buy a Copilot seat to start this. Microsoft's own documentation says Copilot Chat is included with the subscription you already have, and agents that use your data are billed on usage instead of per person.

What I would like to do first is find out what is already running in here. There are almost certainly agents in this tenant that nobody inventoried, and some of them will be running with their maker's permissions rather than the user's. That is a two-week fixed-fee piece of work, it needs nothing purchased, and what it finds decides whether we build anything at all.”

↑ Contents

3 · Phase 1 · The Agent Governance Baseline

This is the assessment that earns the rest of the engagement. It audits what already exists. Section 5 prepares to build something new. Collapse the two and you have given away the billable assessment.

P1Agent governance baseline1–2 wks · fixed fee · no purchase
Access
Power Platform administrator, plus AI Administrator or Global Reader for view-only. Microsoft explicitly recommends the least-privileged role over Global Admin. Nothing needs buying by the customer.
Do
  • Run Agent Inventory from the Copilot Agent Kit — tenant-wide registry of every custom agent with its features, authentication mode, credential mode, sharing scope and owner.
  • Run the Agent Review Tool anti-pattern scan.
  • Audit the three blast-radius settings in 3.1 on every agent found.
  • Score the tenant against Microsoft's ten misconfigurations in 3.2.
Do not
  • Fix anything. Remediating during the assessment teaches the customer remediation is free and destroys your before-and-after.
  • Promise Advanced Hunting. That detection path moved behind an Agent 365 licence on 1 July 2026 — see the note below.
Output
An agent registry with an owner column · a findings list against the ten misconfigurations · the named-owner rule as a policy the customer signs · the baseline that every later drift diff is measured against.

3.1 · Three settings decide the blast radius

Microsoft's framing is that agents are secure by default and makers change those defaults “for valid scenarios without knowing the risk.” Copilot Studio runs an automatic security scan and warns the maker before publishing. It warns. It does not stop them.

SettingSecure defaultThe dangerous valueWhat it means
Authentication mode Authenticate with Microsoft No authenticationAnyone who has the link can interact with the agent
Credentials to use (connectors and flows) End user credentials Maker-provided credentialsEvery user of the agent operates with the maker's permissions, not their own
Sharing scope Shared with no one Shared with everyone in the organisationNo access boundary
AUDIT FIRST The middle row

Maker-provided credentials is the agent-era open SharePoint site

Permanent privilege escalation for every person who invokes the agent, configured by a single dropdown, with a publish-time warning as the only friction.

And it is invisible to every Copilot readiness report the channel currently sells. Data Access Governance does not see it. SharePoint Advanced Management does not see it. It lives in Power Platform — and it is the exact setting that inverts the 25-site containment argument in section 1. Flip it, and every invoker inherits the maker's permissions across the whole tenant.

3.2 · Microsoft's top ten — the checklist, already written

Published by Microsoft's security organisation in February 2026. This is the phase 1 checklist and nobody in the channel had to invent it.

#MisconfigurationConsequence
1Broad organisational sharingUnintended access, expanded attack surface
2Missing authenticationPublic exposure, unauthorised access
3Risky HTTP request actionsGovernance bypass, insecure communications
4Email-based data exfiltrationData leakage via prompt injection
5Dormant agents and connectionsHidden attack surface, stale privileged access
6Author (maker) authenticationPrivilege escalation, separation-of-duties bypass
7Hardcoded credentialsCredential leakage, unauthorised system access
8Model Context Protocol (MCP) toolsUndocumented access paths, unintended interactions
9Generative orchestration lacking instructionsPrompt abuse, behaviour drift, unintended actions
10Orphaned agentsLack of governance, outdated logic, unmanaged access

Items 5 and 10 are the argument for the retainer, and they come from Microsoft's security organisation rather than its marketing. A dormant agent and an orphaned agent are not build defects — at build time neither condition exists. They come into being through the passage of time and the movement of people, and the only thing that finds them is a recurring review. Section 8.

The detection method Microsoft recommends is no longer free

The February blog directs readers to Advanced Hunting community queries in the AI Agents folder of the security portal. On 1 July 2026 that path moved behind a Microsoft Agent 365 licence — Microsoft published the risk list in February and licensed its recommended detection method five months later. Section 10 covers the transition.

The checklist is still free to read and still free to run — just not Microsoft's way. The no-licence path is the Copilot Agent Kit: Agent Inventory for the registry, Agent Review Tool for the anti-pattern scan. Both free and open source, from Microsoft's Power CAT team. Section 11 has the links.

3.3 · Why this is a better wedge than the Copilot readiness assessment

It runs where the alternative cannot

The tenant-wide Copilot readiness path needs an E-SKU base that Business Premium does not provide — Copilot Readiness Engagement, section 9. This needs Power Platform admin access and a Global Reader role.

It finds live defects, not exposure

An oversharing report describes what could happen. An agent running on maker credentials with no authentication is something that is happening, today, with a name attached to it.

The customer has bought nothing

No Copilot seats, no capacity packs, no governance licence. It is sellable into the tenant at its current licensing, which is what makes it phase 1 rather than a post-sale activity.

↑ Contents

4 · Phase 2 · Candidate and Baseline

This phase sits before the build sections for one reason: the baseline cannot be captured retroactively. A partner who reaches the end of a build and then starts thinking about measurement has already lost the argument they will need at renewal.

P2Candidate and baseline1–2 wks · Weeks 1–2
Purpose
One named workflow, one named process owner, and the number you will be judged against. The constraint here is organisational, not licensing.
Do
  • Pick one high-volume workflow. Microsoft's own expansion rhythm is one workflow per quarter, not a portfolio at once.
  • Map it to one of the four value drivers in 4.1 and take the “before” measurement now.
  • Agree the attribution discount and the hourly rate with the sponsor, in phase 2. See 4.2 — this is the highest-leverage thing in the phase.
  • Confirm the measurement surface loads in this tenant before you promise a report from it.
Do not
  • Present a theoretical time-savings slide. Microsoft names it as a credibility failure — 4.3.
  • Accept “we'll work out the metrics after go-live.” There is no after; the baseline is gone.
Output
A named workflow with a named owner · a signed-off baseline measurement · agreed values for the multiplier, the hourly rate and the attribution discount · the KPI set for the 90-day review.

4.1 · Four value drivers, each with Microsoft's own formula

You do not have to defend a home-made ROI model in front of a sceptical finance person. The model is Microsoft's, the defaults are sourced, and the report computes it.

Value driverWhat it measuresHow to price it
EfficiencyProductive hours your team gets back, reinvested in higher-value workProductive hours returned × fully loaded productive-hour value
QualityError reduction, consistency and compliance(Error rate before − error rate after) × volume × cost per error
RevenueTop-line lift from retained, expanded or new businessConversion or deflection delta × volume × unit revenue × attribution discount
StrategicDecision velocity, employee confidence, optionality and resilienceOption premium on capability + retention value of talent + resilience value

Agent Assisted Hours — the published formula

Agent Assisted Hours = (Knowledge references + Weighted sessions without knowledge references) × Time savings multiplier ÷ 60Microsoft Learn — Measure the impact of your agents
Two constants own the renewal conversation

Whoever configures the hourly rate and the multipliers decides what number appears on the sponsor's slide every quarter. That is not administrative trivia — it is defensible, recurring, billable judgement work performed inside Microsoft's own report, not a spreadsheet you have to defend line by line.

The same logic applies to the attribution discount in the revenue formula. It is Microsoft conceding, in its own published method, that attribution is contestable. Agreeing the discount with the sponsor up front converts the hardest conversation at renewal into a parameter that was settled in phase 2.

4.2 · Where each metric is actually read

Value driverMetricsWhere to read them
EfficiencyHours saved, Agent Assisted Hours, Agent Assisted Value, cycle time, touchless rate, cost per transactionCopilot Studio Savings calculator; Copilot Studio agents report (Viva Insights)
QualityResolution rate, first-contact resolution, escalation rate, abandon rate, groundedness, instruction-following scoreCopilot Studio Analytics; Copilot Agent Kit rubrics
RevenueConversion lift, retention delta, cross-sell rate, advisor capacityCopilot business impact report (Viva Insights)
StrategicNew capabilities shipped, workflows redesigned, employee sentiment on AI, talent signalsCopilot Studio custom metrics; Viva Glint Copilot Impact Survey
Check before you promise — open test TT-4

Several of those surfaces live in Viva Insights advanced and analyst templates. Whether they are reachable in a Business Premium tenant, and what licensing they demand, is not established. If they are not reachable the formula still stands, but you compute it by hand from Copilot Studio Analytics — more work, weaker artefact.

Also unconfirmed: whether the hourly rate and multipliers are editable in an SMB tenant. That is the difference between owning the renewal conversation and watching a default number appear. Section 13.

4.3 · The three failure patterns — and the slide they retire

PATTERN 1

Measurement that stops at pilot

Instrumentation is strong during the pilot, then drifts as the agent moves to production. Microsoft's fix: embed measurement in the deployment workflow itself, so every production agent keeps emitting the signals the review depends on.

PATTERN 2

Activity that doesn't tie to outcomes

Sessions and user counts show usage; they are not value. Every KPI has to trace back to one of the four value drivers, or it is decoration.

PATTERN 3

The time-savings trap

“Claiming value based on theoretical time savings alone undermines credibility.” Build a chain of evidence from adoption, through operational KPIs, to business outcomes.

Pattern 3 is aimed squarely at the channel's current pitch. The “X hours per week × headcount × salary” slide is the thing Microsoft is warning against — and you can now retire it internally with a vendor citation rather than an opinion.

↑ Contents

5 · Phase 3 · Prerequisites and Harness

Section 3 audited what exists. This is what has to be in place before anything new is published — five layers in dependency order, and one choice that sets the price of everything after it.

P3Prerequisites and harness2 wks · Weeks 2–4 · SOW
Must be true
A Power Platform environment with Dataverse, production or sandbox — trial and developer environments are not eligible for pay-as-you-go and carry one-fifth the throughput (section 9). A DLP policy separating Business from Non-Business connectors. Managed Environments if you need sharing limits or pipelines — and read the open licensing question in section 13 before you assume that is free.
Do
  • Work the five layers in 5.2, in order.
  • Name the harness and write it into the SOW. 5.1.
  • Read the trap list in section 9 to the customer before they classify anything or plan a promotion path.
Do not
  • Build in the default environment. It is open to every licensed user in the tenant.
  • Silently block connectors. Governance that gets bypassed is not governance — use an approval flow (Power Shield) instead.
Output
A zoned environment model · a DLP data policy · a named harness in the SOW · the 25 grounding sites chosen and assessed · a named accountable owner for every agent.

5.1 · Choose the harness — it sets capability, publishing and the bill

A harness is the runtime between your agent design and the model: it decides when to call the model, what to send it, how to interpret the answer, and which tools to call. Microsoft lists four things it determines. Three are capability questions a maker cares about. The fourth is how your usage is billed — and that one is the partner's problem, not the maker's.

ConsiderationGitHub Copilot harnessStandard harnessCopilot chat harness
Best forComplex, multi-step business processesRule-based agents and structured conversationsExtending M365 Copilot Chat with enterprise knowledge
How it worksReasons through a goal on its own, step by stepFollows the topics and rules you defineConnects enterprise knowledge to M365 Copilot Chat
Recovers from problemsRetries and finds alternative paths automaticallyFollows the paths you've builtNot a focus
Works with filesCreates, edits and reasons over Word, Excel, PowerPoint and PDFNot a focusNot a focus
Skills and memoryYesNot a focusNot a focus
PublishingInternal teams or external customersInternal teams or external customersInternal teams only
BillingUsage-based — starts when you start buildingCopilot Credits per the rate card, after publishConsumption, or included in Microsoft 365 Copilot licences
Sounds like

“Answer questions from our policy documents”

Copilot chat harness. Knowledge grounding, internal only, billed as consumption or covered by a Copilot licence. Narrow reach, no file creation, no retry.

Sounds like

“Read invoices, match them to POs, route the exceptions”

GitHub Copilot harness. Different capability set, different failure modes, and a meter that runs during your own development. Needs a build-burn clause — section 6.

The line to remember

A partner who quotes without naming the harness has not scoped the work. Name it in design, write it into the SOW, and treat a request to change it mid-build as the scope change it is — because it moves both the capability and the invoice.

5.2 · The five layers, in dependency order

  1. Who can make an agent at all. Restrict environment creation. Decide who holds a maker role. Adopt the zoned model Microsoft describes at maturity level 300 — environments designated safe, supported and IT managed, each with different controls. Present the zoned model as a named deliverable: it is one of the few governance artefacts a non-technical sponsor can actually picture.
  2. What the agent can connect to. A Power Platform DLP data policy separating Business from Non-Business connectors is the agent's real safety boundary; Microsoft names failing to treat it as one a universal anti-pattern. Restrict raw HTTP actions and unreviewed MCP tools by policy — risks 3 and 8. Prefer an approval workflow (Power Shield) over a silent block.
  3. Who the agent acts as. End-user credentials, authentication on — the two settings from section 3. For an agent that acts on its own rather than as a signed-in user, it gets its own identity in Entra, making it a new principal subject to conditional access and identity governance. Microsoft also recommends PIM for just-in-time activation of the AI Administrator and Search Administrator roles.
  4. What it can read. Scope the 25 SharePoint sites deliberately and assess those. Microsoft frames knowledge readiness as four dimensions: source scope, permissions, source authority and ownership. Source authority is the one nobody checks — not can the agent read this but is this approved, current, and the version the business actually follows. An agent grounded in a superseded policy is confidently, fluently wrong, and no permissions review catches it.
  5. What is recorded, and who owns it. Purview treats agents as auditable entities — interactions auditable, prompts and responses discoverable, retention applying to AI prompts and outputs. How much of that is reachable on Business Premium is an open question that guide leaves open too. Then the cheapest control on the list: a named accountable owner for every agent. Risks 5 and 10 are unfixable without one.
↑ Contents

6 · Phase 4 · Economics — The Skipped One

This is the spine of the guide. It resolves the margin trap, it takes two to three days, and it is the phase that turns a metered cost base from a risk into the recurring service.

P4Economics2–3 days · gates the quote
Purpose
Produce the run-rate number the build SOW is written around, and set the controls that stop the worst outcome. It has no paper of its own — its output is a figure in someone else's paper.
Do
  • Run Microsoft's Copilot Studio agent usage estimator against the actual design — harness, orchestration mode, knowledge sources, tools.
  • Choose prepaid capacity packs or pay-as-you-go, deliberately (6.1).
  • Set a per-agent monthly cap on every agent, before launch (6.4).
  • Put the build-burn clause in the SOW if the harness is GitHub Copilot (6.5).
Do not
  • Quote from a channel blog. Several state an agent action costs 25+ credits. Microsoft says 5. Budgeting on the blog number over-quotes the run rate by 5×, loses on price, and never tells you why.
  • Present the estimate as a guarantee. A single prompt can bill on three meters. The gap between estimate and invoice is not a flaw to apologise for — it is the service.
Output
A forecast the customer has seen and signed · a capacity mechanism chosen · per-agent caps set · a monthly true-up defined as a billable deliverable with an artefact attached.

6.1 · Vocabulary, and how credits are actually bought

The billing unit is the Copilot Credit. Capacity is pooled at the tenant and allocable per environment. Channel material still talking about “messages” is working from pre-rename documentation — though the older vocabulary survives inside Microsoft's own tables, where the tenant billing capability column still reads “prepaid message packs.” The terms map; the material around them usually does not.

Default

Prepaid capacity packs

A pooled tenant allocation, allocable per environment, managed in the Power Platform admin center.

Subject to overage enforcement — see 6.3. This is where the 125% kill switch lives.

The escape hatch

Pay-as-you-go

Enabled by linking an Azure subscription billing plan to the environment. Overage bills to the Azure subscription instead.

Enforcement does not apply. A genuine architectural choice with a commercial consequence — decide it here, not after the first outage.

6.2 · The rate card

Agent featureBilling rateUsed by a Microsoft 365 Copilot licensed user
Classic answer1 Copilot CreditNo charge
Generative answer2 Copilot CreditsNo charge
Agent action5 Copilot CreditsNo charge (Computer-Using Agents excluded)
Tenant graph grounding for messages10 Copilot CreditsNo charge
Agent flow actions, per 100 actions13 Copilot CreditsNo charge, only via the “When an agent calls the flow” trigger
Text and generative AI tools — basic, per 10 responses1 Copilot CreditNo charge
Text and generative AI tools — standard, per 10 responses15 Copilot CreditsNo charge
Text and generative AI tools — premium, per 10 responses100 Copilot CreditsNo charge
Content processing tools, per page8 Copilot CreditsNo charge
Non-obvious arithmetic — 1

One interaction can bill on several meters at once. Microsoft's own example: a tenant-graph-grounded agent may spend 12 credits on a single complex prompt — 10 for the grounding, 2 for the generative answer. Nobody quoting per-conversation gets this right by intuition.

Non-obvious arithmetic — 2

Reasoning models bill twice. Copilot Studio bills the feature rate for the operation plus the premium text-and-generative-AI-tools rate for the reasoning model's token usage. Swapping in a reasoning model is a pricing decision disguised as a quality decision — the single biggest silent cost driver in the platform.

6.3 · Overage enforcement — the thing that will burn you

This is not a billing footnote. It is a service-availability event with no user-facing warning, and it belongs in the managed-service agreement.

Custom agentsAgent flows
Trigger125% of prepaid capacityPrepaid capacity fully consumed (100%)
What happensCustom agents are disabled. An ongoing conversation is not interrupted; every subsequent attempt to invoke the agent is rejectedNew flow runs cannot start. Runs already in progress complete. The agent remains available for everything else
Who is toldEmail to the tenant's designated administrator, plus a post in the Power Platform admin centerFlow authors see a design-time warning in the Copilot Studio designer
What the user sees“There is a billing issue.” or “This agent is currently unavailable. It has reached its usage limit.”Nothing obvious. The agent still answers — it just stops doing things
ResetWhen capacity is increased or resetMonthly, when prepaid credits renew
READ TOGETHER Notification row and user row

The people who find out first are the customer's users

The admin gets an email; nobody is watching that mailbox at the moment it matters. If you are selling a managed service over this platform, detecting the 125% event before the customer does is a large part of what you are actually being paid for.

The flow column is worse in one specific way: a partial failure is harder to detect than a dead one. The agent answers normally and silently stops completing actions. Nobody raises a ticket for an agent that is still talking.

6.4 · The day-one control almost nobody sets

Per-agent monthly consumption limits. They cost nothing, take minutes, and convert an uncontrolled tenant-wide kill switch into a per-agent budget. Microsoft's own framing is that they cap usage before enforcement is triggered. Set them during phase 4, on every agent, before launch.

Power Platform admin center → Licensing → Copilot Studio → Manage Agents → set monthly limit per agent
Power Platform admin center → Licensing → Copilot Studio → Environments → actual consumption per environment (the true-up grid)

6.5 · The four-step loop — this is the recurring service

1

Estimate

Run the estimator against the actual design — harness, orchestration mode, knowledge sources, tools. Produce a forecast the customer has seen and signed off, not a number they discover later.

Phase 4, before the SOW
2

Cap

Set the per-agent monthly limit in the admin center. This is the control that turns a possible outage into a known ceiling, and the one most partners never touch.

Before launch · every agent
3

Monitor

Consumption details per environment in the admin center; per-agent consumption on the agent's Monitor page. Watch the trend, not the total — the 125% event is a slope, and it is visible weeks before it lands.

Recurring
4

True-up

Reconcile forecast against actual, reallocate capacity between environments, adjust the caps, and tell the customer what changed and why.

Monthly · billable · has an artefact

Four steps, recurring, tool-supported, and every one of them is labour and judgement rather than a licence resale. That is the answer to the margin trap: you do not fix a metered cost base by pricing around it, you fix it by selling the management of the meter. What to charge is settled in section 10 of the Frontier Partner Playbook, not here.

6.6 · The build-burn clause

Billing starts when you start building. Unlike the standard harness, which starts billing after publish, the GitHub Copilot harness charges credits from the moment you start building. Experiences such as creating an automated solution with natural language, previewing and testing the agent, and generating and creating agent evaluations all consume credits.Microsoft Learn — Overview of usage-based billing (GitHub Copilot harness)

Read that as a partner. On this harness your own development, testing and QA consume the customer's credits, before anything is published and before anything works. Every SOW that selects the GitHub Copilot harness needs a clause naming who funds development consumption, and a cap on it. Almost none in the channel currently have one.

How big is the burn? Nobody has published a number — which makes the clause a warning rather than a negotiating position. One afternoon of testing would convert it into a figure; see TT-2 in section 13.

↑ Contents

7 · Phase 5 · Build and Deploy

The part that looks like the project, and the part most at risk of commoditisation. Prebuilt agent galleries already do a large share of it. That is an argument for this engagement shape, not a threat to it.

P5Build and deployWks 4–8 simple · 4–14 complex
Must be true
Capacity packs live. Caps set. Harness named in the SOW. Knowledge sources reconfigured per environment — ALM does not carry them (section 9).
Do
  • Sign the retainer here, not later. The moment the agent works is the moment the never-done argument is easiest to make and hardest to make again.
  • Reground any prebuilt or POC agent in the customer's real data before it goes live.
  • Load-test against launch traffic, not pilot traffic — the capacity trap in section 9.
Do not
  • Promote a developer-environment pilot straight to production. One-fifth the throughput, and it passes anyway.
  • Let a synthetic-data POC become the production agent. Microsoft's own warning, not an opinion.
Output
A live agent, capped, instrumented against the phase 2 baseline, with an owner — and a signed managed services agreement.

7.1 · Buying the first 80% — what arrives, and what does not

A prebuilt agent gallery is an AI use case gallery: production-intent use cases with case study, demo and proof-of-concept actions, filterable by industry and solution area. The reasoning below applies to any such vendor. ExampleUnifyCloud's CloudAtlas AI Factory is on the TD SYNNEX line card and resellable today — stated on the line card's authority, not a public source. Confirm current availability with your rep before quoting it.

What arrives from the gallery

A working agent pattern

Tested logic for a recognisable business problem. A demo you can put in front of a customer this week, and POC scaffolding behind it. Someone else's solved version of the hard design questions.

This is real value and it compresses weeks. A partner who dismisses it is competing on labour against someone who is not.

What you must still do

Everything tenant-specific

None of it transfers, because none of it is about the agent — it is about the customer.

And every item on that list is a section of this guide. The last mile is not an afterthought to the build. It is the engagement.

What the gallery cannot knowWhere it is handled
The customer's SharePoint permissions state, and which 25 sites the agent should ground in§5
Sensitivity labels that make knowledge silently unreadable, and password-protected files that index as Ready§9
Which harness it targets, and therefore when billing starts§5, §6
Capacity, rate limits, and whether the pilot environment can carry launch-day traffic§9
Credit run rate, per-agent caps, and who is watching for the 125% event§6
The baseline, and who configures the measurement constants§4
Existing ungoverned agents already in the tenant§3
The process the agent encodes, and who owns it when the business changes it§8
The line

80% of the way there is 80% of the build, not 80% of the engagement. The gallery gets you a working demo. The last mile is what makes it survive contact with your tenant, and what keeps it alive afterwards.”

7.2 · Two cautions

Caution 1

A prebuilt agent inherits drift on day one

It was built against someone else's data, someone else's process and someone else's permissions model. All six ageing sources in section 8 start running the moment it lands.

And one question has no published answer for any vendor: when the vendor updates a gallery template, what happens to an instance already deployed in a customer tenant? That is the versioning question the entire never-done thesis turns on. Ask it before the first deployment, not after.

Caution 2

Speed cuts both ways

A proof of concept in days wins the room. It becomes a trap the moment it turns into the production agent without being regrounded in real data — and this is Microsoft's own warning: proof-of-concept ideation on synthetic data “increases the risk of agents not performing as expected in production environments.”

Use the gallery to win the room. Reground it before it goes live.

7.3 · Five questions to put to any prebuilt-agent vendor

  1. Which harness do the packaged agents target? Determines the billing model and whether build burn reaches the customer — §5, §6.
  2. How are they delivered — solution import, template, or managed deployment? Does the ALM knowledge gap apply, meaning knowledge sources must be reconfigured per environment?
  3. When you update a template, what happens to a deployed instance? The versioning question above.
  4. Does the agent arrive instrumented? Is there a baseline and a measurement surface, or does the partner add that — §4?
  5. What is the commercial shape for partners — per POC, subscription, or bundled with an assessment?

None of the five have publicly documented answers for any vendor reviewed here. Asking them is a five-minute call that changes what you can safely commit to.

Where other vendors sit

AvePoint AgentPulse serves readiness and steady state — discovery, inventory, policy enforcement, cost insight, backup and recovery for Copilot Studio agents — where a gallery accelerates the build. They compose; they do not compete.

Commoditisation is the argument, not the threat

A productised 80% collapses build labour as a revenue line. You cannot bill hours for work a gallery already did, and pretending otherwise loses to whoever stops pretending first. What is left to charge for is the assessment ahead of the build, the last mile through it, and the operations after it — phases 1, 2, 3, 4 and 6. The gallery compresses phase 5, and phase 5 was always the most competitive part.

↑ Contents

8 · Phase 6 · Managed AgentOps

Where it stops being a project. The claim is not a sales position invented here — Microsoft says it in four places, none of them a marketing page, and two of the ten security risks in section 3 are failures that cannot exist until time has passed.

P6Managed AgentOpsIndefinite · 90-day cycle · retainer
Cadence
Measure against baseline for 90 days → sponsor review → scale it or retire it → pick the next high-volume workflow. Microsoft's own published expansion rhythm.
Monthly
  • The true-up from section 6 — forecast versus actual, capacity reallocated, caps adjusted, a written note of what changed and why.
  • Agent Inventory re-run and diffed against the phase 1 baseline — not a fresh audit.
  • Consumption trend per environment and per agent, watched as a slope.
Quarterly
  • Regression run of the golden prompt set (the only detection for model drift).
  • Source-authority review of the 25 grounding sites.
  • Sponsor review against the phase 2 baseline, with the four value drivers.
Do not
  • Sell attendance. A managed service that cannot fill in the last two columns of the failure register in 8.2 is selling attendance, not operations.
  • Wait for an alert on model drift. There isn't one. It has to be a calendar item.

8.1 · Table 1 — the six ways an agent ages

A taxonomy is only useful if each entry comes with a way of seeing it. The third column is what turns this from a slide into a service.

DriftWhat actually changesHow you detect it
Data driftThe grounding corpus ages. Content is moved, renamed, superseded or archived; the agent keeps citing itSource-authority review against the 25 sites; citation analysis in Copilot Studio Analytics; groundedness scored against a rubric
Model driftThe model underneath the agent changes. Microsoft names model drift as a risk in its own build guidance — and the customer does not choose the versionA regression run of the golden prompt set on a schedule. This is the one with no alert, so it has to be a calendar item
Connector driftThe agent is only as good as what it reaches through, and connectors, APIs and MCP tools change under itAgent Review Tool anti-pattern scan; DLP policy review; action failure rates in the Agent Insights Hub
Permission driftTenant ACLs move. Sharing scope, credential mode or authentication gets changed by a maker after go-liveAgent Inventory re-run against the phase 1 baseline — a diff, not a fresh audit
Process driftThe business changes the workflow the agent encodes. The agent does not know, and nothing errorsOnly the sponsor review catches this. It is why the 90-day cadence has a human in it
Cost driftVolume grows, or a reasoning model is swapped in and the agent starts billing on two metersConsumption trend per environment and per agent; the true-up step in §6
Model drift is the sharp one

Five of the six originate with the customer or their content. Model drift originates with Microsoft. The reasoning underneath the agent can change without the customer asking for it, and the agent's behaviour can change with it.

Whether the customer has recourse is a product question this research has not settled. The narrower claim is sufficient: there is no alert for it. If nobody re-runs a known set of prompts on a schedule, a behaviour change arrives as a user complaint months later, and by then nobody can say when it started.

8.2 · Table 2 — the failure register

This is the artefact. Named failure, the surface it becomes visible on, the free tool that shows it, and who is accountable. Fill in the fourth column for a live customer; every row you cannot fill is the retainer.

Named failureDetection surfaceFree toolAccountable owner
The 125% kill — custom agents disabled at 125% of prepaid capacityAdmin email and an admin center post. Users find out by the agent breakingConsumption trend in the admin center; per-agent caps set in advancePartner — this is an availability event in the managed-service agreement
Partial flow enforcement — flows blocked at capacity while the agent keeps answeringDesign-time warning to flow authors only. No user-visible signalAgent flow actions line in the consumption details gridPartner
Dormant agents (top-10 risk #5) — stale privileged access nobody is watchingNothing. Dormancy has no eventAgent Inventory; Compliance Hub thresholds and SLA timersPartner, on the review cadence
Orphaned agents (top-10 risk #10) — no active owner, so no review cycle reaches themNothing, by definitionAgent Inventory ownership field; the named-owner rule from §5Customer names the owner; partner enforces that one exists
Knowledge rot — stale corpus, 4–6 hour sync, ALM not carrying knowledge across environmentsSilent. Answers get quietly worseAgent Debugger for what was actually retrieved; Conversation Analyzer; rubric-graded groundednessCustomer owns content currency; partner owns detecting that it slipped
Configuration regression — a maker flips authentication, credentials or sharing after go-livePublish-time security scan warns the maker, and only the makerAgent Review Tool; Agent Inventory diffed against the baselinePartner

Every tool in the third column is free and open source, from Microsoft's Power CAT team. That is the commercial argument as well as the technical one: the tooling costs nothing, so the margin is entirely in the labour and the judgement. A partner who says “we license a governance platform” is beaten by one who says “we run the Compliance Hub, we set the thresholds, we own the SLA timer.”

8.3 · Microsoft's own support for the thesis

WhereWhat it says
Agent development lifecycleFive phases: discovery, experimentation, build, deploy, and operational steady state — continuously monitoring, evaluating and adjusting. There is no “complete” phase. The lifecycle ends in a state, not an event.
Measure the impact of your agents“Operate an expansion rhythm, treating the program as recurring quarterly work” — pick a workflow, build, measure against baseline for 90 days, review with the sponsor, scale or retire. A recurring-revenue contract shape written by the vendor.
Agentic AI maturity modelTreating Responsible AI as a one-time review is a named anti-pattern: “Bias, misuse, and trust drift typically appear after go-live, not before.” Microsoft names the resulting behaviour the “panic and switch things off” response pattern.
Agent development lifecycleDrift named in the build guidance itself: minimise the time between experimentation and build “to reduce the risk of model or data drift.” And POC ideation on synthetic data “increases the risk of agents not performing as expected in production environments.”
Two tierings, two axes — do not conflate them

Microsoft's maturity model separates agents into personal productivity, departmental or team, and mission-critical, and names applying one set of controls to all three an anti-pattern — it over-restricts productivity agents, driving shadow AI, while under-governing the mission-critical ones. That is a tiering of the agents. The three AgentOps tiers in section 10 of the Frontier Partner Playbook are a tiering of the service you sell. Use Microsoft's to decide how hard to govern a given agent; use the playbook's to decide what to charge for governing it.

↑ Contents

9 · Limits, Traps and Capacity

Reference material for phase 3 and phase 5. The traps have one property in common: nothing errors. The status says Ready. The agent answers. The answer is just missing something.

9.1 · Three traps that report success

Trap 1 — sensitivity labels silently remove knowledge

Labelled and password-protected documents cannot be indexed

Microsoft's wording is unambiguous: you cannot index documents that use sensitivity labels of confidential or highly confidential, or that are password protected. If you add them, “they show as ready for use but don't provide responses.”

A customer who has done classification well — exactly the mature customer you want — gets an agent that answers nothing about its most important content, with no error anywhere to explain why.

The inverse is a genuinely useful control. Labelling is a cheap, reliable way to hold content out of an agent, it needs no extra tooling, and it works on Business Premium. Used deliberately it is a feature; discovered accidentally it is a failed pilot.

Trap 2 — ALM does not carry knowledge

Importing an agent does not bring its knowledge processing with it

Microsoft states it for every unstructured knowledge source type: ALM “isn't supported for this feature. Importing agents doesn't result in automated knowledge source processing.”

This breaks the clean dev → test → prod story every governance conversation depends on. Say it out loud in the design phase rather than discovering it on promotion day. Plan for knowledge sources to be reconfigured per environment, and budget for it.

Trap 3 — the agent is never reading live data

Knowledge synchronisation is four to six hours

Across OneDrive, SharePoint upload, Salesforce, Confluence, ServiceNow and Zendesk sources, Microsoft gives the same figure. Whatever the demo implied, the agent is answering from a corpus that is up to six hours stale.

Fine for policy documents, wrong for anything with a deadline attached. If the workflow needs current data it needs an action against a live system, not a knowledge source — which is a different harness conversation and a different price.

9.2 · The capacity trap — why pilots pass and launches fail

Generative AI rate limits are set per Dataverse environment and scale with how much capacity the tenant owns.

Quota per Dataverse environmentTenant billing capability
50 RPM / 1,000 RPH1–10 prepaid packs
80 RPM / 1,600 RPH11–50 prepaid packs
100 RPM / 2,000 RPH51–150 prepaid packs
10 RPM / 200 RPHTrial or developer environments
100 RPM / 2,000 RPHPay-as-you-go environments
100 RPM / 2,000 RPHMicrosoft 365 Copilot users
READ ROW 4 Against row 1

A developer-environment pilot has one-fifth the throughput of the environment it launches into

And it passes anyway, because six testers never approach ten requests a minute. Launch day puts a hundred people on it inside an hour, and the user-visible symptom is a failure notice when they send a message.

Estimate peak traffic windows, not monthly averages. Monthly volume can look entirely comfortable while a Monday-morning spike breaks the agent. Rate-limit increases can be requested, but the path runs through support and is not guaranteed.

9.3 · Structural limits worth knowing before you scope

None of these are traps — they are documented, findable and hard. They are here because a partner who meets one mid-build is having a scope conversation instead of a design one.

LimitValue
Knowledge sources per agent500 across all types
SharePoint site URLs per agent, generative orchestration25
Instructions for a Copilot agent8,000 characters
Topics per agent (Dataverse environments)1,000
Trigger phrases per topic200
Skills per agent100
SharePoint lists15 lists, up to 35,000 rows across them
SharePoint list query depthFirst 2,048 rows only
Maximum file size512 MB — but 7 MB for generative answers without a Copilot licence in tenant (200 MB with one, and tenant graph grounding with semantic search on)
The 7 MB row is a licensing decision wearing a technical costume

Without a Microsoft 365 Copilot licence in the same tenant, generative answers can only use SharePoint files under 7 MB. Nothing errors. The agent simply does not know things. This is the first appearance of the pattern that runs through this whole page: the failures that matter in Copilot Studio are usually silent.

↑ Contents

10 · Agent 365 — Trigger Logic

Agent 365 is the escalation, not the entry ticket. This section is the qualification logic — what to use before it, and the four conditions that turn the dial up. Where it sits commercially is settled in section 10 of the Frontier Partner Playbook.

10.1 · What changed on 1 July 2026

Effective July 1, 2026, AI agent security capabilities for Microsoft Copilot Studio and Microsoft Foundry agents require a Microsoft Agent 365 license. These capabilities are no longer covered by existing Defender for Cloud Apps or Defender for Cloud licenses.Microsoft Learn — Transition Copilot Studio and Foundry agent security capabilities to Microsoft Agent 365

For Copilot Studio agents, a tenant without an eligible licence lost agent discovery and posture, agent threat detection and real-time protection, and investigation of agent activity in Advanced Hunting.

Three further changes break things quietly:

ChangeConsequence
Tenants configured to Block on existing Agent 365 real-time protection rules stopped blocking on 1 July 2026To resume blocking, rules must be redefined under the new policy experience. A control that was enforcing is now not enforcing, and nothing announced it in the tenant.
The AIAgentsInfo Advanced Hunting table is deprecated in favour of AgentsInfoSaved queries, custom detections and workbooks referencing the old table need updating
The AI Agents sub-tab under Cloud Assets was removed for all customersLicensed or not, that navigation path is gone
One boundary Microsoft has not drawn, so neither will this guide

The same transition document also states: “Real-time protection for Microsoft Copilot Studio through Defender for Cloud Apps remains unchanged for tenants that continue using this experience. No action is required.”

That sits awkwardly beside the headline, and reconciling the two would require drawing a line Microsoft has not drawn. Treat the exact boundary as unresolved. If a customer depends on Copilot Studio real-time protection through Defender for Cloud Apps, confirm their specific configuration rather than reasoning from either sentence alone.

10.2 · The overlap map — what an SMB actually needs on day one

The jobAgent 365Free or included alternative
Tenant-wide agent inventoryAgent registry — broadest coverage, including non-Microsoft platforms via registry syncCopilot Agent Kit → Agent Inventory; Power Platform inventory
Ownerless and dormant agent detection“Agents without owners” card, rules-based lifecycle enforcementAgent Inventory + a review cadence
Configuration risk / anti-pattern scanAgents-at-risk, aggregated from Entra, Defender and PurviewAgent Review Tool; the built-in publish-time security scan
Policy enforcement, SLA timers, quarantineRules-based lifecycle policy, approval flow, blockingCompliance Hub — thresholds, risk levels, SLA timers, quarantine and delete
Connector / DLP boundaryPurview and Entra integrationPower Platform DLP data policies; Power Shield for approval workflow
Runtime analytics and telemetryAgent run-time, active users, trending agentsAgent Insights Hub; Copilot Studio Analytics
Debugging a bad conversationAgent Debugger — step-by-step decisions, timing, token usage
Business value measurementAgent run-time hoursCopilot Studio agents report; Savings calculator; Agent Value in the Kit
Threat detection, real-time protection, Advanced Hunting over agent activityAgent 365 only, since 1 July 2026No free equivalent. This is the genuine gap.
The positioning

Read the last row against all the others. Almost everything an SMB needs on day one is free — inventory, anti-pattern scanning, compliance policy with SLA timers, debugging, analytics and value measurement are all in the Copilot Agent Kit at zero licence cost, plus Power Platform DLP. What is genuinely Agent 365-only is the security-operations layer.

A partner who tells an SMB they need a per-user governance licence before they can govern a single agent is wrong on the facts, and has priced themselves out of the first engagement. Lead with the free baseline in section 3. Earn the right to the next conversation.

10.3 · Four honest triggers

TRIGGER 1

Agent count outgrows a human

The registry stops being a spreadsheet job. Ownerless and dormant agents — risks 5 and 10 — are the tell that the count has crossed the line.

TRIGGER 2

An agent gets autonomy or its own identity

Once an agent acts on its own rather than as a signed-in user it is a new principal in the tenant, and Entra-backed identity governance stops being optional.

TRIGGER 3

Agents appear from platforms you do not control

SharePoint agents, Agent Builder, or non-Microsoft platforms. Registry sync is the only thing that sees across all of them — the Copilot Agent Kit does not.

TRIGGER 4

A regulatory or contractual obligation

Where the customer must demonstrate detection and response over agent activity, not just configuration hygiene. After 1 July 2026 that is Agent 365 or nothing.

10.4 · The sales mechanic, and the two numbers to resolve first

Agent 365 admin-led trials are 25 seats for 30 days. The admin center shows a banner with remaining trial days, and admins with billing permissions can view details and purchase directly from it. That is a natural paid discovery engagement: run the registry across the tenant, produce the findings, and let the expiry force a decision that would otherwise drift. Do not let it lapse silently — a trial that ends with nobody watching is worse than never having run one, because the customer now believes they looked.

Resolve in writing before this goes near a proposal

Is it purchasable on Business Premium? Microsoft Learn says Agent 365 “works best when using Microsoft E5 as a pre-requisite.” That is hedged language, not a requirement statement. Channel aggregators claim an SMB path under 300 seats. Those are not the same claim — and this is the exact failure mode the Copilot Readiness Engagement, section 9 documents with SAM: two readings of one hedged licensing page, in opposite directions, both wrong to act on.

Who counts as a licensed user? Microsoft states at least one user must hold a qualifying licence to enable Agent 365. What is not established is whether that means every user who interacts, every maker, or only the governing admins. A sixty-person company with one help-desk agent everybody talks to is either three licences or sixty — a twentyfold difference in the same deployment. Get it from your distributor or Microsoft in writing, for the specific deployment shape. There is no shame in telling the customer you are confirming it; the alternative is guessing on their invoice.

Design the service so the licence cannot absorb it

Microsoft published an agent risk list in February and licensed its recommended detection method in July. Assume more of this surface becomes licensed over time, and build the service so the labour and the judgement are the product — those are the parts that do not get absorbed into a SKU.

↑ Contents

11 · The Toolchain Register

Everything below already exists, most of it is free, and almost all of it is published by Microsoft. This is tools you use; the long-form guide's reference library is sources cited. They overlap and they are not the same list.

11.1 · If you bookmark one link

11.2 · The AgentOps console, at zero licence cost

11.3 · Phase 4 runs on these

11.4 · Planning, limits and lifecycle

11.5 · Assessment, measurement and training

↑ Contents

12 · Language — Lines and Objections

12.1 · The whole licensing conversation, in five sentences

Say this

“Copilot Chat is included with the Microsoft 365 subscription you already have. If you want an agent that uses your own data, that is billed on usage rather than per person — so you do not need to buy a Copilot seat to start.

What that costs is a real number and I am going to forecast it for you before you sign anything, and cap it before we launch. The seat is a capability upgrade we can look at later, on evidence, once we know what the agent is actually worth to you.”

12.2 · The four objections that actually end deals

ObjectionThe answer
“Don't we need Copilot licences first?”No. Copilot Chat is included with any Microsoft 365 or Office 365 subscription and agents are billed on metered consumption. Read Microsoft's sentence aloud — it lands better verbatim than paraphrased.
“We can't afford the readiness work.”You are thinking of the tenant-wide Copilot readiness programme, which you cannot license on Business Premium anyway. An agent's blast radius is 25 named sites and three Power Platform settings — a task, not a programme. But be honest about the limit: oversharing inside those 25 sites is not fixed by scoping the agent. What shrinks is amplification.
“Why am I still paying you after it's built?”Three answers, in order of strength. One: the meter — nobody is watching for the 125% event, and your users find out by the agent breaking. Two: Microsoft's own security list names two failures (dormant and orphaned agents) that cannot exist at build time and are only found by a recurring review. Three: the model underneath your agent can change without you asking, and there is no alert for it.
“Can't we just buy a prebuilt agent?”Yes, and you probably should — it compresses weeks. 80% of the way there is 80% of the build, not 80% of the engagement. Then walk the last-mile table in section 7.

12.3 · Where the containment argument stops

BE FAIR Or lose the room

Reduced, not eliminated

With end-user credentials — the secure default — the agent resolves the signed-in user's own permissions. A genuinely overshared site inside those 25 remains reachable by exactly the people who could already reach it. The oversharing defect is not fixed by scoping the agent.

What shrinks is amplification: a machine surfacing something a user could technically open but would never have found. That shrinks from tenant-wide to 25 named sites — the difference between a programme and a task.

And it shrinks only while the credential setting holds. Flip it to maker-provided credentials and the whole argument inverts. That setting is the first thing section 3 audits, and it is the reason section 3 exists.

↑ Contents

13 · Claims Discipline and the Open Register

13.1 · Do not repeat these

  1. “An autonomous agent action costs 25+ credits.” Several 2026 channel blogs say so. Microsoft Learn says an agent action is 5. Budgeting on the blog number over-quotes the run rate by 5×.
  2. “Capacity packs can be bought with no Azure subscription at all.” Circulating in the channel and not asserted here. What Microsoft Learn states is narrower: prepaid credits are managed through the Power Platform admin center, and it is pay-as-you-go that requires linking an Azure subscription billing plan.
  3. “Agent 365 requires E5.” Microsoft's wording is “works best when using Microsoft E5 as a pre-requisite” — hedged, not a requirement. Do not convert the hedge into either a yes or a no.
  4. Any SMB Copilot Studio outcome number you cannot attribute. Vivid figures circulate — a boutique retailer cutting tickets by two thirds, a solo practice recovering nine hours a week — and they trace to marketing blogs with no named customer. Laundering an unattributed number into a benchmark is precisely the time-savings trap Microsoft names in section 4.
  5. GitHub Copilot credit complaints as evidence about Copilot Studio. Different product, different meter. Admissible for exactly one thing: how customers react when metered AI billing surprises them. The reaction is not a renegotiation — it is a loss of trust in whoever sold it.
There is no audited SMB Copilot Studio case study

None was located for this guide. What exists is a Microsoft enterprise self-reference and a set of unattributed channel numbers. The honest version is more useful in front of a partner than a borrowed number would be:

“There is no audited SMB case study yet. That is exactly why you instrument the baseline before you build — because you are going to be it.”

13.2 · The open register — confirm these before you quote

None of these has been tested for this guide. Each is cheap. A section resting on an open test ships with the uncertainty stated, or it does not ship — it never ships with a guess.

#What is unknownWhat it gatesWhat would settle it
TT-1Can you buy Copilot Credit capacity and publish a working agent to Copilot Chat in a Business Premium tenant with zero Copilot seats, without hitting an undocumented licensing wall?§1 — the page's central claimRun it once end to end and record every point a licence is requested
TT-2How many credits does a trivial agent consume on the GitHub Copilot harness before publish?§6 — turns the build-burn clause from a warning into a numberBuild one, preview and test normally, read the Monitor page before publishing
TT-3When a Confidential-labelled document fails to index, does any signal reach the maker, the user, or the debugger?§9 — the trap listAdd one, wait for Ready, ask a question only it can answer, record all three surfaces
TT-4Is the Copilot Studio agents report reachable in an SMB tenant, and is the default hourly rate editable there?§4 — the measurement argumentOpen it in a Business Premium tenant; record the licence demanded and whether the calculator accepts a change
TT-5Do Managed Environments — needed for sharing limits and pipelines — require premium per-user licensing across the tenant, and does a Copilot Studio standalone licence qualify?§5 — the most likely wall on the no-seat pathCurrent Power Platform Licensing Guide, read against a distributor quote, in writing
TT-6How many agents already exist in a real SMB tenant, and how many use maker credentials, no authentication, or have no owner?§3 — whether the wedge is real or theoreticalRun Agent Inventory across three tenants; tabulate auth mode, credential mode, sharing scope, owner
TT-7Is Agent 365 purchasable on Business Premium?§10CSP price list or distributor catalogue, for the specific tenant
TT-8Who needs an Agent 365 licence — every user who interacts, every maker, or only governing admins? A twentyfold spread on the same deployment§10 — the most important number to resolve before quotingDistributor or Microsoft, in writing, for the specific deployment shape
TT-9Does one Agent 365 licence enable tenant-wide observe and govern, given Microsoft states at least one licensed user enables it?§10Run the 25-seat trial and check what registry coverage a single assigned licence produces

TT-1, TT-7 and TT-8 are the three most likely to repeat a known failure. The Copilot Readiness Engagement, section 9 documents what happens when one hedged Microsoft licensing page gets read two ways: two internally consistent conclusions, in opposite directions, both wrong to act on.

13.3 · Provenance legend

This page carries one currency figure — Microsoft's default $72 hourly rate in the Agent Assisted Value formula. Everything else about consumption is expressed in Copilot Credits, which are a unit of usage rather than money and need no provenance tag.

MS list Microsoft-published price, documented entitlement, or a constant Microsoft publishes in its own formula Survey named analyst or survey Range corroborated only by resellers or aggregators Model editorial model — a construction, not a citation
↑ Contents

14 · The Room — 60 Minutes

A working session for a partner team, not a customer pitch. It decides which phase of the arc your practice is currently giving away, and which open test you run first. Every visual it needs is already on this page — run it from the page, no deck.

1What good looks like0–10 min

Say: “Before we talk about anything we build, here is a complete engagement from the first conversation to the retainer. Seven phases. I want to know which of these we currently do and which we give away.”

Show: the seven-phase table in §1.2. Walk it across, not down. Spend the time on the Paper and What must be true columns — everyone in the room already understands the build.

Do: have each person privately mark the phases they have personally delivered and been paid for in the last year. Do not collect them yet.

Bridge: “Now let's see where the money actually was.”
2The two phases ahead of the paper10–20 min

Say: “Phases 0 and 1 happen before the build worklist even starts, and both are billable. If our engagements begin at Discover, we have handed the assessment away and started at the most competitive part.”

Show: the three blast-radius settings and Microsoft's ten misconfigurations — §3. The point to land: maker-provided credentials is invisible to every Copilot readiness report we currently sell.

Do: collect the marks from stop 1. Count how many people have been paid for phase 1. In most rooms the answer is nobody.

Bridge: “The objection to selling that assessment is always licensing. Let's kill it.”
3The seat you don't need, and the plumbing swap20–32 min

Say: “We have been gating the agent conversation behind a Copilot seat purchase. Microsoft's own documentation says we don't have to.” Read the line in §12.1 aloud — verbatim beats paraphrase.

Show: the licensing strip in §1, then immediately the limit in §12.3: amplification shrinks, oversharing does not, and the whole argument inverts on one credential setting.

Do: name a real customer in the room who is on Business Premium with no Copilot seats. Ask what has been stopping the agent conversation with them. That is the test case.

Bridge: “So we can start. Which means we now own a bill we have never had to forecast.”
4The meter, and the phase we skip32–44 min

Say: “We sell a flat monthly fee over a cost base that moves. That is the trap. Phase 4 is how we get out of it, and phase 4 is the one we skip.”

Show: the rate card and the overage table — §6.2 and §6.3. Land three things: an agent action is 5 credits and not the 25 the blogs say; a single prompt can bill on three meters; at 125% the customer's users find out by the agent breaking.

Do: open the Power Platform admin center on screen and navigate to Licensing → Copilot Studio → Manage Agents. Ask who in the room has ever set a per-agent cap. Then walk the four-step loop in §6.5 as the recurring deliverable.

Bridge: “That loop only makes sense if the work never ends. It doesn't — and Microsoft says so.”
5The agent is never done44–54 min

Say: “This is not our recurring-revenue pitch. It is Microsoft's lifecycle, Microsoft's ninety-day rhythm, and Microsoft's security organisation naming two failures that cannot exist until time has passed.”

Show: the six drifts and the failure register — §8.1 and §8.2. Dwell on model drift: the one change that originates with Microsoft, and the one with no alert.

Do: take the failure register and fill in the fourth column for one live customer. If the room cannot name an accountable owner for each row, that gap is the retainer.

Bridge: “Last ten minutes. Two decisions, and they leave the room with names on them.”
6The decision54–60 min

Say: “Two things get decided before we leave. Which phase we stop giving away, and which tenant test we run this month.”

Decision one: pick a single phase from §1.2 to productise first. Phase 1 is the usual answer, because it needs no purchase from the customer. Name the owner and the first customer.

Decision two: pick one open test from §13.2 and put a date on it. TT-1 validates whether we can start at all; TT-6 tells us whether phase 1 is a real wedge; TT-8 changes what we tell customers about Agent 365. All three are cheap.

Leave with: one phase named, one owner, one customer, one test, one date.
↑ Contents

15 · Related Guides

15.1 · Run it on yourself first

You are the first tenant. Run phase 1 against your own Power Platform environments before you sell it — Agent Inventory takes an afternoon, and the findings from your own tenant are the only ones you can show without a customer's permission. That is also the honest answer to the missing case study in section 13.

15.2 · Where this sits

↑ Contents