Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Agents need different levels of oversight. Match the depth of governance to the risk each agent poses to enable low-risk work quickly, and reserve heavier controls for agents that can cause real harm. This article describes a three-tier model, lists the controls for each tier, and shows how the tiers align with the transformation patterns.
Match oversight to risk
A single governance checklist applied to every agent fails in both directions. It over-governs simple agents, which adds friction and slows adoption. It under-governs complex agents, which leaves gaps and creates liability. A uniform process feels fair, but it treats a meeting-notes summarizer and a system that moves money as if they're the same thing.
The clearest risk signal is the assist-to-execute line. An agent that drafts a paragraph, suggests an answer, or summarizes a document assists a person who stays in the loop and owns the outcome. An agent that updates a customer record, submits a ticket, or moves money executes a change in a system of record. Assistive agents carry limited risk. Agents that act autonomously, touch sensitive data, or face customers, carry more. Sort every agent by what it does, not by how impressive it looks.
Three risk tiers
Use three tiers. Each tier defines the controls an agent needs before it ships and the patterns that typically fit that tier. Start an agent in the tier that fits its behavior, and move to a higher tier as its scope or autonomy grows.
Tier 1: Low risk (individual productivity agents)
Tier 1 covers agents that assist one person or a small team with everyday work, such as summarizing, drafting, and searching. These agents don't take consequential actions on their own.
Required controls:
- A named owner who is accountable for the agent
- Basic monitoring of usage and errors
- A standard release checklist
- Self-service deployment within published guardrails
Keep the path light so people can build and adopt without waiting on a committee.
Tier 2: Medium risk (expert-knowledge and internal service agents)
Tier 2 covers agents that answer domain questions or run internal services where a wrong answer can mislead people or disrupt operations. Accurate, current information matters most at this level.
Required controls:
- A named owner, plus a domain-expert validator who confirms the agent's answers are correct
- Knowledge-quality monitoring that watches for stale or wrong content
- A formal release gate with review before the agent goes live
- Accuracy tracking and feedback loops so quality improves over time
Tier 3: High risk (business-critical and external-facing agents)
Tier 3 covers agents embedded in core processes or facing customers, where a failure hits revenue, compliance, or trust. These agents execute consequential actions and often act with autonomy.
Required controls:
- A named owner, plus a formal process owner accountable for the business process
- Production-grade service-level-agreement (SLA) monitoring
- A security review and a responsible AI assessment before release
- A decision-rights framework that sets what the agent may decide alone and what needs a human
- An incident-response plan for when the agent behaves incorrectly
- A quarterly maturity review
Keep these agents closely governed as they scale.
Move quickly and stay accountable
Release gates and audit logs help teams move fast and stay accountable. A release gate is a checkpoint that an agent passes before it reaches production. Its scope depends on the agent's tier. An audit log records what the agent did, who it acted for, and which data it used, so teams can answer questions later. Together, release gates and audit logs help teams ship within guardrails and keep a clear record of accountability. Microsoft Purview provides audit of agent actions to support this record.
Important
Governance is never finished. Compliance is continuous. Risk tiers, controls, and decision rights evolve as agents gain new capabilities and as regulations change. Don't wait for governance to feel complete before you ship. Publish the guardrails, let teams build within them, and refine as you learn.
Integrate with existing governance
Don't build a parallel governance universe for agents. Your organization already governs technology, and a separate agent regime creates duplicate work, conflicting rules, and gaps. Connect the Center of Excellence (CoE) to the governance bodies you already have:
- Security and compliance, for risk, data handling, and audit.
- Cloud and IT governance, for infrastructure and operations.
- A Power Platform or low-code CoE, for citizen-developer practices.
- Microsoft 365 governance, for productivity and collaboration data.
- A responsible AI council, for fairness, transparency, and accountability.
The CoE fills the gaps that agents create rather than replacing governance bodies. Agents introduce new questions about ownership, lifecycle, decision rights, and monitoring that existing governance wasn't designed to answer. Bring those gaps to the right governance body, and let each body expand its scope to cover agents.
Next step
With risk tiers and governance controls in place, protect your agents by establishing the right identity, access, and data protection model.
Related information
- Why does an enterprise need Agent 365?
- Observability and Agent 365
- Agent management in Microsoft 365 admin center
- Secure AI agents at scale using Microsoft Agent 365
- Copilot Studio security and governance key concepts
- Responsible AI FAQs for Copilot Studio
- Build agents with Copilot Studio and Agent 365
- Manage your Copilot Studio projects
- Rubrics refinement in Copilot Agent Kit
- Copilot Control System security and governance