{"id":23618,"date":"2026-05-21T09:00:00","date_gmt":"2026-05-21T16:00:00","guid":{"rendered":"https:\/\/www.microsoft.com\/insidetrack\/blog\/?p=23618"},"modified":"2026-05-22T11:05:32","modified_gmt":"2026-05-22T18:05:32","slug":"governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/insidetrack\/blog\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\/","title":{"rendered":"Governing AI agents at scale: Lessons from our journey at Microsoft"},"content":{"rendered":"\n<nav\n\tclass=\"wp-block-inside-track-in-post-navigation\"\t>\n\t<button class=\"in-page-block__button\" aria-expanded=\"false\" aria-controls=\"in-page-block__list\">\n\t\tWhat this guide contains\t<\/button>\n\n\t<ul id=\"in-page-block__list\">\n\t\t\t\t\t<li class=\" \" style=\"\">\n\t\t\t\t<a class=\"\" data-id=\"introduction\" href=\"#introduction\" style=\"\">Introduction<\/a>\n\t\t\t<\/li>\n\t\t\t\t\t<li class=\" \" style=\"\">\n\t\t\t\t<a class=\"\" data-id=\"chapter-1\" href=\"#chapter-1\" style=\"\">Chapter 1: Building your agent governance strategy<\/a>\n\t\t\t<\/li>\n\t\t\t\t\t<li class=\" \" style=\"\">\n\t\t\t\t<a class=\"\" data-id=\"chapter-2\" href=\"#chapter-2\" style=\"\">Chapter 2: Establishing a solid data foundation for agent governance<\/a>\n\t\t\t<\/li>\n\t\t\t\t\t<li class=\" \" style=\"\">\n\t\t\t\t<a class=\"\" data-id=\"chapter-3\" href=\"#chapter-3\" style=\"\">Chapter 3: A matrixed approach to agent governance<\/a>\n\t\t\t<\/li>\n\t\t\t\t\t<li class=\" \" style=\"\">\n\t\t\t\t<a class=\"\" data-id=\"chapter-4\" href=\"#chapter-4\" style=\"\">Chapter 4: Tracking, impact, and value<\/a>\n\t\t\t<\/li>\n\t\t\t\t\t<li class=\" \" style=\"\">\n\t\t\t\t<a class=\"\" data-id=\"conclusion\" href=\"#conclusion\" style=\"\">Conclusion: Governing the frontier<\/a>\n\t\t\t<\/li>\n\t\t\t<\/ul>\n<\/nav>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"introduction\">Empowering employees and protecting your organization through agent governance<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Welcome to the agentic frontier<\/strong><\/p>\n\n\n\n<aside class=\"wp-block-group aside-for-guide has-white-200-background-color has-background has-global-padding is-content-justification-right is-layout-constrained wp-container-core-group-is-layout-3f1abf08 wp-block-group-is-layout-constrained\" style=\"border-radius:10px;padding-top:var(--wp--preset--spacing--spacing-12);padding-right:var(--wp--preset--spacing--spacing-12);padding-bottom:var(--wp--preset--spacing--spacing-12);padding-left:var(--wp--preset--spacing--spacing-12)\">\n<div class=\"wp-block-group is-nowrap is-layout-flex wp-container-core-group-is-layout-298f84b7 wp-block-group-is-layout-flex\" style=\"margin-top:0;margin-bottom:0;padding-top:0;padding-bottom:0\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"132\" height=\"132\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2025\/10\/Engage-with-our-experts_blogs.png\" alt=\"\" class=\"wp-image-20636\" style=\"width:48px\"\/><\/figure>\n\n\n\n<p class=\"has-body-lg-font-size wp-block-paragraph\"><strong>Engage with our experts!<\/strong><\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"margin-top:var(--wp--preset--spacing--spacing-4)\">Customers or Microsoft account team representatives from Fortune 500 companies are welcome to <a href=\"mailto:msitstaff@microsoft.com\">request a virtual engagement<\/a> on this topic with experts from our Microsoft Digital team.<\/p>\n<\/aside>\n\n\n\n<p class=\"wp-block-paragraph\">Agents are expanding the frontier of enterprise AI. By creating tools that surface knowledge, take actions, and even reinvent workflows, organizations can apply the power of AI to business processes in new and innovative ways.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But this shift raises questions for business and IT leaders: How do you get the benefits of agents without putting your organization and employees at risk? How do you encourage citizen developers to create agents freely while maintaining control, security, privacy, and compliance?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At Microsoft Digital, the company\u2019s IT organization, we\u2019re putting practical governance structures in place to ensure our internal agents are useful, safe, and properly scoped. Through a deliberate strategy of empowerment with established guardrails, we\u2019re unlocking the potential of agentic transformation while maintaining the trust that defines our work.<\/p>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-48e64321 wp-block-group-is-layout-constrained\" style=\"border-radius:10px;padding-top:var(--wp--preset--spacing--spacing-12);padding-right:var(--wp--preset--spacing--spacing-12);padding-bottom:var(--wp--preset--spacing--spacing-12);padding-left:var(--wp--preset--spacing--spacing-12)\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex has-1-columns\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"56\" height=\"58\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-read-and-prepare.png\" alt=\"\" class=\"wp-image-23639\" style=\"width:48px\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"margin-top:var(--wp--preset--spacing--spacing-4);margin-bottom:var(--wp--preset--spacing--spacing-4)\"><strong><strong>Read and prepare<\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"margin-top:var(--wp--preset--spacing--spacing-4);margin-bottom:var(--wp--preset--spacing--spacing-4)\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/becoming-a-frontier-firm-a-guide-for-deploying-ai-agents-based-on-our-experience-at-microsoft\/\" type=\"link\" id=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/becoming-a-frontier-firm-a-guide-for-deploying-ai-agents-based-on-our-experience-at-microsoft\/\">Check out our complete guide to deploying and adopting agents across the enterprise, based on our own experience here at Microsoft.<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">The AI maturity model and frontier transformation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Agentic AI has made a new operational model possible, one that blends machine intelligence with human judgment, creating AI-operated, human-led teams.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We call organizations that enact this model Frontier Firms.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As organizations move toward this new operational state, they progress from foundational AI assistance through escalating levels of agentic maturity and complexity. First, humans operate with help from an AI assistant like Microsoft 365 Copilot. Then, human-agent teams work together. But the future lies with humans leading teams of agent users: AI agents that perform core labor with relative autonomy.<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-0e3b43d4 wp-block-columns-is-layout-flex has-3-columns\" style=\"padding-top:0;padding-right:0;padding-bottom:0;padding-left:0\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:100%\">\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"688\" height=\"860\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Pattern-1_blue.jpg\" alt=\"Pattern 1: Human with assistant\u2014every employee has an AI assistant that helps them work better and faster.\" class=\"wp-image-23640\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Pattern-1_blue.jpg 688w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Pattern-1_blue-240x300.jpg 240w\" sizes=\"auto, (max-width: 688px) 100vw, 688px\" \/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:100%\">\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"688\" height=\"860\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Pattern-2_blue.jpg\" alt=\"Pattern 2: Human-agent teams\u2014agents join teams as \u201cdigital colleagues,\u201d taking on specific tasks at human direction.\" class=\"wp-image-23641\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Pattern-2_blue.jpg 688w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Pattern-2_blue-240x300.jpg 240w\" sizes=\"auto, (max-width: 688px) 100vw, 688px\" \/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:100%\">\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"688\" height=\"860\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Pattern-3_blue.jpg\" alt=\"Pattern 3: Human-led, agent-operated\u2014humans set direction, and agents execute business processes and workflows, checking in as needed.\" class=\"wp-image-23642\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Pattern-3_blue.jpg 688w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Pattern-3_blue-240x300.jpg 240w\" sizes=\"auto, (max-width: 688px) 100vw, 688px\" \/><\/figure>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Capturing the benefits of this model relies on many factors, but in our experience as Microsoft Digital, two main tenets are instrumental to a successful transformation:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Empowering employees and teams to create and experiment with their own agents<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Properly governing those agents to protect the enterprise<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s a balance. If you set agent builders free without the proper guardrails, you risk data overexposure, agent sprawl, and security vulnerabilities. However, being too restrictive about governance stifles individual imagination, workflow reinvention, and innovation that can come from agentic AI.<\/p>\n\n\n\n<div class=\"wp-block-group has-light-blue-to-light-green-gradient-background has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-10685bb4 wp-block-group-is-layout-constrained\" style=\"padding-right:0;padding-left:var(--wp--preset--spacing--spacing-20)\">\n<div class=\"wp-block-group has-white-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-ff4033b8 wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<figure class=\"wp-block-image alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Brian-Fielder_blue.png\" alt=\"A photo of Fielder.\" class=\"wp-image-23620\" style=\"width:150px\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Brian-Fielder_blue.png 500w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Brian-Fielder_blue-300x300.png 300w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Brian-Fielder_blue-150x150.png 150w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n\n\n\n<p class=\"has-body-xl-font-size wp-block-paragraph\" style=\"margin-top:0;margin-bottom:var(--wp--preset--spacing--spacing-4);font-style:normal;font-weight:600\"><em><em>\u201cAt Microsoft, we\u2019ve moved beyond envisioning the agentic future into operating within it every day. Our experience as Customer Zero gives us a unique perspective on what it takes to govern AI agents at scale, turning early lessons into proven practices that help organizations innovate with confidence.\u201d<\/em><\/em><\/p>\n\n\n\n<p class=\"has-gray-800-color has-text-color has-link-color has-body-lg-font-size wp-elements-17c5c1b5224a796886ee3c6c0017cdac wp-block-paragraph\" style=\"margin-top:0;margin-bottom:var(--wp--preset--spacing--spacing-4)\"><strong><strong>Brian Fielder, vice president, Microsoft Digital<\/strong><\/strong><\/p>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019re here to help you find the right balance for your organization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This guide shares what we\u2019ve learned along the way. As you read, you\u2019ll follow our journey as Customer Zero at Microsoft, and you\u2019ll gain access to tips and resources that we\u2019ve assembled to help you apply our expertise to your own agent governance practice.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Every organization is different, and your experience will differ from ours in terms of risk tolerance, technical capability, resourcing, and more. This guide highlights some principles and best practices you can apply to your own business context, needs, and objectives.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cAt Microsoft, we\u2019ve moved beyond envisioning the agentic future into operating within it every day,\u201d says Brian Fielder, vice president of Microsoft Digital. \u201cOur experience as Customer Zero gives us a unique perspective on what it takes to govern AI agents at scale, turning early lessons into proven practices that help organizations innovate with confidence.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now is the time to seize this opportunity. Follow along to start your own journey toward frontier transformation and capture the benefits of trusted, connected agentic intelligence.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Learn from our experience governing agents<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Within Microsoft Digital, we\u2019ve been acting as Customer Zero for frontier transformation by creating the tools, infrastructure, and processes that power agents at Microsoft.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our goal is to make it easy for employees to engage with agentic tools freely and adaptably while maintaining safety and responsibility. The path to this objective relies on a three-pronged approach to governance:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Embedded governance functionality:<\/strong> Agent creation and publishing tools should incorporate good guidance, governance, and guardrails out of the box, making agents people create essentially self-governing.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>IT oversight:<\/strong> This is a new space and a new way of working, so it isn\u2019t feasible for all agents to self-govern at this point. As an IT organization, we fill gaps in governance through reviews and oversight. We establish risk-based policies around types of agents, exposure and sharing, and other pivots.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>User education:<\/strong> It\u2019s almost impossible to predict every governance gap and need, so educating our users helps them avoid accidentally increasing risk. Our Agents at Microsoft team and individual change managers are the guides for these efforts. Employees can also refer to resources like Microsoft Learn courses and the Agent Builders SharePoint hub.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Throughout this journey, we\u2019ve empowered our employees to create all kinds of agents, ranging from simple personal tools built by people working in every function, with every level of technical skill, all the way to AI-powered enterprise tools designed by professional developers for use across lines of business and even the entire company.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As part of the process, we\u2019ve incorporated guardrails to ensure less technical employees are limited to tools that simply retrieve enterprise knowledge, such as SharePoint Agent Builder or Copilot Studio, while software engineers get the full power of any tool they need that can take action or automate workflows, including Microsoft Foundry and Microsoft 365 Agent Toolkit.<\/p>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background is-layout-grid wp-container-core-group-is-layout-532df69b wp-block-group-is-layout-grid\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\"><strong>SharePoint<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Lowest level of difficulty<\/li>\n\n\n\n<li class=\"wp-block-list-item\">For all roles<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Function: information-retrieval only<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Microsoft 365 content<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Light governance<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Lowest risk<\/li>\n<\/ul>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\"><strong>Copilot Studio Agent Builder<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Low difficulty<\/li>\n\n\n\n<li class=\"wp-block-list-item\">For all roles<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Function: information-retrieval only<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Microsoft 365 content and web sources<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Light governance<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Low risk<\/li>\n<\/ul>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\"><strong>Copilot Studio (full)<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Low to moderate difficulty<\/li>\n\n\n\n<li class=\"wp-block-list-item\">For all roles<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Function: task completion<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Microsoft 365 content + connectors to external channels<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Advanced governance<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Higher potential for risk<\/li>\n<\/ul>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\"><strong>Agent Toolkit, Foundry<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Highest difficulty<\/li>\n\n\n\n<li class=\"wp-block-list-item\">For developers<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Function: workflow automation<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Multiple internal and external channels<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Advanced governance<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Highest potential for risk<\/li>\n<\/ul>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Over the course of this journey, we\u2019ve learned valuable lessons about effective agent governance, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">How to build an impactful but flexible governance strategy<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Strategies for creating an AI-ready data ecosystem<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Ways to apply appropriate policies and controls for highly diverse agents<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Approaches for tracking the impact and value of agents<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"chapter-1\">Chapter 1: Building your agent governance strategy<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Thinking through your organizational needs and building a framework to govern agents<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As we\u2019ve incorporated agents into different aspects of our organization, we\u2019ve also deepened their involvement in employees\u2019 daily workflows and core business processes. Because of this, we\u2019re diligent about the governance guardrails and policies that protect our organization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ve accumulated a wealth of knowledge and insights in this area through our efforts governing Microsoft 365 Copilot. Based on this experience, some of the key priorities that we made sure to adhere to included:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Effectively applying controls to ensure users and apps don\u2019t get access to privileged information<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Preventing employees from creating agents that violate company policies<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Balancing the freedom for employees to share their creations with the need to prevent agent sprawl<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Delineating which agents are authoritative and applicable for enterprise functions and which ones are meant for employees\u2019 own personal use.<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Inventorying agents to provide lifecycle management<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Securing and protecting confidential data while respecting our responsible AI principles: Fairness, reliability and safety, privacy and security, transparency, accountability, and inclusiveness<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Unlocking telemetry that enables us to govern agents effectively<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">By focusing on each of these dimensions, our governance team has centered its efforts on the value these agents provide to the company while also ensuring organizational safety and trust. To realize this value, we emphasize three key principles that help protect both our employees and the organization:<\/p>\n\n\n\n<div class=\"wp-block-group is-layout-grid wp-container-core-group-is-layout-988b637e wp-block-group-is-layout-grid\">\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-2065403a wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"58\" height=\"60\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-security-icon.png\" alt=\"\" class=\"wp-image-23643\" style=\"width:48px\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Security<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ve established standards for data classification, policies for handling confidential information, and other security measures to protect data from unauthorized access, misuse, and disclosures. <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/microsoft-purview\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Purview powers these capabilities<\/a> through data labeling, rights management, and data loss prevention.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-2065403a wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"58\" height=\"60\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-privacy-icon.png\" alt=\"\" class=\"wp-image-23644\" style=\"width:48px\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Privacy<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Privacy compliance measures keep personal data protected and ensure agents adhere to regulatory frameworks in the regions where we operate. We conduct regular privacy assessments for all applications, including high-impact agents.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-2065403a wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"58\" height=\"60\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-regulation-icon.png\" alt=\"\" class=\"wp-image-23645\" style=\"width:48px\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Regulation<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Regulatory compliance assessments ensure agents meet prevailing legal standards. Our legal and compliance teams carefully monitor AI guidelines, regulations, and laws as they evolve so we can understand and incorporate them into these assessments.<\/p>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">We incorporated elements of our tenant\u2019s minimum bar for governance into how we secure agents. Those include Microsoft Purview Information Protection, a functional inventory, activity logging, lifecycle management, and the ability to properly isolate agents so that they don\u2019t cross data boundaries.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our overarching tenant governance strategy is to govern items like documents and data at the container level. However, within a SharePoint site, for example, the added functionality of agents demands that we introduce further controls like sharing limits, breadth of knowledge sources, agent metadata, and information about an agent\u2019s behaviors.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Turning priorities into principles<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To operationalize governance, we developed six principles that guide our approach to agents. They form the governance foundation for a wide matrix of agent creation and usage opportunities.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>We ensure a strong data hygiene foundation<\/strong> so we can trust our data estate as employees build and use agents.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>We empower employees to build personal agents <\/strong>that can access permitted services and data sources to help automate and accelerate their tasks.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>We empower teams and lines of business to build agents<\/strong> with known lower-risk patterns to accelerate impact.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>We provide a smooth release path for engineering teams<\/strong> to develop agents designed for enterprise functions so they can access all the services and sources they need. This includes the same software development lifecycle (SDLC) reviews and certifications as other enterprise software, which we outline in Chapter 3.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>We accelerate innovation<\/strong> through agent and automation templates while maintaining an AI Center of Excellence (CoE) to help teams think through their opportunities.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>We reimagine employee experiences and task execution <\/strong>to simplify and optimize productivity.<\/li>\n<\/ol>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-48e64321 wp-block-group-is-layout-constrained\" style=\"border-radius:10px;padding-top:var(--wp--preset--spacing--spacing-12);padding-right:var(--wp--preset--spacing--spacing-12);padding-bottom:var(--wp--preset--spacing--spacing-12);padding-left:var(--wp--preset--spacing--spacing-12)\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex has-1-columns\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"56\" height=\"58\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-read-and-prepare.png\" alt=\"\" class=\"wp-image-23639\" style=\"width:48px\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"margin-top:var(--wp--preset--spacing--spacing-4);margin-bottom:var(--wp--preset--spacing--spacing-4)\"><strong><strong>Read and prepare<\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"margin-top:var(--wp--preset--spacing--spacing-4);margin-bottom:var(--wp--preset--spacing--spacing-4)\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/powering-the-technical-veracity-of-ai-at-microsoft-with-a-center-of-excellence\/\" type=\"link\" id=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/powering-the-technical-veracity-of-ai-at-microsoft-with-a-center-of-excellence\/\">Powering the technical veracity of AI at Microsoft with a Center of Excellence.<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Securing control through agent lifecycles<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">As we strategized to operationalize good governance, agent lifecycles became one of our most crucial tools. We superimposed the enterprise lifecycle on top of these policies, with both user-based and attestation-based lifecycles.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This means we treat agents owned by individual employees like any other user app and delete them when they leave the organization. Meanwhile, we ensure that agents owned by teams have a lifecycle that\u2019s defined by the tenant and tied to attestation, our internal enterprise SDLC, and accountability confirmations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This approach helps us combat sprawl by eliminating agents that no longer serve a purpose. It provides a solid foundation for more fine-tuned, matrixed policies and practices.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Governing amid real-time technology acceleration<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">One recent development illustrates how the rapid advancement of AI technology requires us to stay ahead of policy for new features.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Model Context Protocol (MCP) adds new capabilities, but also new risks and challenges. It&#8217;s a simple standard that lets AI systems communicate with the right tools and data without custom integration work. Instead of building a new connection or API every time, teams plug into a common pattern.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That standardization delivers speed and flexibility, but it also changes the security equation. <a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/protecting-ai-conversations-at-microsoft-with-model-context-protocol-security-and-governance\/\">We\u2019ve extended our security and governance practices to account for MCP servers.<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our practices and policies help us govern agents effectively in this new environment. First, we assess security across four layers: Applications and agents, the AI platform, data, and infrastructure. We establish a secure-by-default strategy by positioning every remote MCP server behind our API gateway and establishing practices for vetting, identity management, automation that slows agents at the right moments, context trimming, and server isolation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As you define policies for governing your own agentic ecosystem, you can take inspiration from our process. Start by asking questions about what you want to accomplish and what you want to protect, then move on to establishing your most important priorities. From there, you can cement those priorities into policies.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Learning from our approach to agent governance strategy<\/h3>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background is-layout-grid wp-container-core-group-is-layout-f14c24dc wp-block-group-is-layout-grid\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:0;padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:0\">\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"39\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-match-policies.png\" alt=\"\" class=\"wp-image-23622\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Match policies to progress on your AI journey<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The complexity of agent governance depends on the maturity of your organization and where you are in your adoption journey. Start slowly to let that maturity grow over time.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"40\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-strong-policy-framework.png\" alt=\"\" class=\"wp-image-23623\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">A strong policy framework is the foundation<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Lean on existing app governance policies, then layer agent-specific structures on top.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"40\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-take-your-cues.png\" alt=\"\" class=\"wp-image-23624\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Take your cues from established standards<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Global regulations around privacy, security, and responsible AI provide a good baseline for establishing governance policies. Assign teams to work through these regulations and incorporate their insights into your agent governance strategy.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"41\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-comfort-level-with-risk.png\" alt=\"\" class=\"wp-image-23625\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Decide on your comfort level with risk<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Bring cross-disciplinary experts together from across your organization to determine what level of risk is acceptable for different agents and their use cases. Put guardrails in place for low-risk scenarios and establish processes for supporting more complex or sensitive use cases. Evaluate what data sources agents can extract information from. Establish whether users have shared sensitive data sources.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"40\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-change-is-constant.png\" alt=\"\" class=\"wp-image-23626\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Change is constant<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Plan to reassess and revise your governance structure regularly. Agents are evolving rapidly, as is the tooling surrounding them, so maintaining good governance policies will be an ongoing practice.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"39\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-governance-value-driver.png\" alt=\"\" class=\"wp-image-23627\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Governance is a value driver for employees<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Governance isn\u2019t just about protecting your organization. It also provides the right patterns to make sure your employees are getting value from agents. Establish strong measures of business value and a robust methodology for management and assessment of agents through ongoing tracking. This kind of observation and telemetry is foundational and should be a key part of your governance efforts.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-container-core-group-is-layout-7db9d80f wp-block-group-is-layout-constrained\" style=\"padding-right:0;padding-left:0\">\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-container-core-group-is-layout-639b5052 wp-block-group-is-layout-constrained\" style=\"padding-top:0;padding-right:0;padding-bottom:0;padding-left:0\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"50\" height=\"50\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-Key-takeaways.png\" alt=\"\" class=\"wp-image-23628\" style=\"width:48px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h2 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Key takeaways<\/h2>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Use these tips based on what we learned here at Microsoft to build your strategy for agent governance at your company:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Establish a cross-disciplinary agent Center of Excellence<\/strong><strong>. <\/strong>Bring together stakeholders across the organization to define priorities, goals, and shared practices for agent adoption.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Right-size oversight based on risk.<\/strong> Determine your organization\u2019s risk tolerance and define which agents require more or less involvement from IT, security, and compliance teams.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Operationalize agent oversight and management.<\/strong> Establish an oversight model and implement tools that help manage agents at scale.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Establish change management and adoption. <\/strong>Determine and implement a strategy for driving adoption to educate and empower employees.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Create a centralized governance and information hub<\/strong><strong>.<\/strong> Provide employees and agent builders with a single place to find guidance, standards, and governance information.<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"50\" height=\"50\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-Learn-more.png\" alt=\"\" class=\"wp-image-23629\" style=\"width:48px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h2 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Learn more<\/h2>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>How we did it at Microsoft<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list is-style-list-no-bullets\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/protecting-ai-conversations-at-microsoft-with-model-context-protocol-security-and-governance\/\">Find out how we\u2019re protecting AI conversations at Microsoft with MCP security and governance.<\/a> This post outlines how we&#8217;re streamlining MCP governance through secure-by-default architecture, automation, and inventory.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/becoming-a-frontier-firm-our-it-playbook-for-the-ai-era\/\">Explore our IT playbook for the AI era and learn how we\u2019re becoming a Frontier Firm.<\/a> This article shares our journey as an IT organization in support of this new operating model.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/the-agentic-future-how-were-becoming-an-ai-first-frontier-firm-at-microsoft\/\">Discover how Microsoft is becoming an AI-first Frontier Firm.<\/a> This story shares how we\u2019re approaching the idea of an agentic future.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/enterprise-ai-maturity-in-five-steps-our-guide-for-it-leaders\/\">Read our five-step guide for IT leaders who want to drive greater AI maturity.<\/a> This resource can help you chart a course through AI maturity to reimagine what&#8217;s possible for the enterprise.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/how-were-tackling-microsoft-365-copilot-governance-internally-at-microsoft\/\">Learn from our experience tackling Microsoft 365 Copilot governance.<\/a> This guide details our governance efforts for Microsoft 365 Copilot and can serve as a starting point for agentic governance.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Further guidance for you<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list is-style-list-no-bullets\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/security-for-ai\/agent-365-security\" target=\"_blank\" rel=\"noreferrer noopener\">Secure your agents at scale with Microsoft Agent 365 guidance<\/a> for unified identity, compliance, and control across platforms.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/en-us\/ai\/responsible-ai?msockid=3702b47881576ac600afa2e6809f6b09\" target=\"_blank\" rel=\"noreferrer noopener\">Learn about the responsible AI policies and practices<\/a> that guide our use of AI at Microsoft.<\/li>\n<\/ul>\n<\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"chapter-2\">Chapter 2: Establishing a solid data foundation for agent governance<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Setting agents up for success using a secure, robust data foundation<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Operating according to an escalating maturity model means we\u2019ve done the foundational work to secure and govern our data estate for Microsoft 365 Copilot. Many of the same principles apply to agents, with the added complexity of incorporating additional data sources.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To lead these efforts, <a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/harnessing-ai-how-a-data-council-is-powering-our-unified-data-strategy-at-microsoft\/\">we established a cross-functional team of data professionals within our AI CoE<\/a>. This team is mostly comprised of Microsoft Digital employees who support corporate functions like Corporate, External, and Legal Affairs (CELA) and Global Workplace Services. Together with our AI CoE, <a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/transforming-our-data-culture-with-ai-ready-data\/\">this team helped us define what it means to have AI-ready data<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In essence, AI-ready data just means information we\u2019ve certified for AI workloads. We certify those data sources using Microsoft Purview to identify defects in our core data products, and we\u2019ve also built AI-powered assessments to certify which data lakes are AI-ready.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In most ways, governance is tool-agnostic and rooted in basic principles. With robust data labeling, data hygiene, and permissions in place alongside our AI tools, which respect labels by default, we can confidently give every employee the ability to build basic agents and trust in our governance guardrails. For decades, the challenge of data analysts and engineers was maintaining a consistently reliable source of truth despite inconsistent data quality, insufficient governance, and years of collecting data in silos. <a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-fabric\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Fabric<\/a> and <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/microsoft-purview\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Purview<\/a> can help resolve these issues.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019re embracing a more balanced, federated approach to data management today. We call this approach a data mesh. Rather than allowing unchecked decentralization or forcing all our data into a single centralized system, the data mesh formalizes domain ownership while embedding governance, quality, and interoperability directly into shared platforms.<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"1009\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Harnessing-AI-infographic_blue-1024x1009.jpg\" alt=\"Graphic shows our data mesh architecture surrounded by the platform services layer and the data management zones layer.\" class=\"wp-image-23646\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Harnessing-AI-infographic_blue-1024x1009.jpg 1024w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Harnessing-AI-infographic_blue-300x296.jpg 300w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Harnessing-AI-infographic_blue-768x756.jpg 768w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Harnessing-AI-infographic_blue-1536x1513.jpg 1536w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Harnessing-AI-infographic_blue.jpg 2003w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Our data mesh architecture helps us preserve trust and establish a strong governance foundation while preventing data from becoming siloed.<\/figcaption><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.33%\">\n<p class=\"wp-block-paragraph\"><strong>The data mesh<\/strong> connects and distributes, data products across domains, enabling shared data access and compute while scaling beyond centralized architectures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Platform services<\/strong> are standardized blueprints that embed security, interoperability, policies, standards, and core capabilities &#8212; providing guardrails that enable speed without fragmentation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Data management zones <\/strong>provide centralized governance capabilities for policy enforcement, lineage, observability, compliance, and enterprise-width trust.<\/p>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">With this approach, our domain teams publish data as well-defined, discoverable products, while common standards for security, metadata, and compliance are enforced through automation rather than manual processes. This model preserves enterprise trust and consistency without sacrificing speed or autonomy. By adopting a data mesh mindset, we can scale analytics and AI more effectively across the organization while still keeping ownership closely connected to the business focus.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Confidentiality labels, the practical framework for data protection<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To operate according to Zero Trust principles, we needed a coherent system that lets us see, label, and protect data. Otherwise, the burden of data loss prevention would fall solely on employees, who would have to exercise individual discretion whenever they decided how to house and share potentially sensitive content.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With labeling, it\u2019s important to strike a balance between the depth necessary for supporting an array of data governance controls and the simplicity to ensure labeling isn\u2019t burdensome for users.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We decided on four overarching labels for container and file classification, each with its own sub-labels. The highest-level schema looks like this:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Highly confidential<\/strong>: We only share our most critical data with named recipients.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Confidential: <\/strong>Any items crucial to achieving our goals feature limited distribution.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>General<\/strong>: Employees can share daily work&#8211;like personal settings and postal codes&#8211;internally throughout Microsoft.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Public<\/strong>: We share unrestricted data meant for public consumption freely. That includes information like publicly released source code and openly announced financials.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">For our risk tolerance and organizational needs, we made the decision to protect data designated confidential or higher. As a result, we contain data flows to their tenants and only trust suitable storage destinations for content. That suitability depends on a storage location\u2019s ability to gate which connectors can work with particular source data and sensitivity labels.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The administrators responsible for workspaces like SharePoint sites set default labels. These labels serve as a foundation for appropriate access and circulation for objects within those containers. It takes the burden of labeling off of employees. The sensitivity labels that administrators apply map to several different categories of policies that can anticipate and help to mitigate data loss and risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They communicate four key areas:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Breadth of availability:<\/strong> Labels determine whether the workspace is broadly available internally or is a private site.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>External permissions:<\/strong> We administer guest allowance via the group\u2019s classification, allowing specified partners to access teams when appropriate.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Sharing guidelines:<\/strong> We tie important governance policies to the container\u2019s label. For example, can an employee share this workspace outside of Microsoft? Is this group limited to a specific division or team? Is it restricted to specific people? The label establishes these rules.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Conditional access:<\/strong> While we haven\u2019t implemented this policy at Microsoft, tying identity and device verification to container labels can introduce additional governance controls.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Within Microsoft Digital, we\u2019ve put a lot of thought into how each of our labels aligns with relevant policies. You can see more of the logic behind our sensitivity labels and their policies in this graphic:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"2003\" height=\"1426\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Container-sensitivity-labels-table_blue.jpg\" alt=\"A chart shows the different types of data container labels and what level of access is given for each one. \" class=\"wp-image-23647\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Container-sensitivity-labels-table_blue.jpg 2003w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Container-sensitivity-labels-table_blue-300x214.jpg 300w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Container-sensitivity-labels-table_blue-1024x729.jpg 1024w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Container-sensitivity-labels-table_blue-768x547.jpg 768w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Container-sensitivity-labels-table_blue-1536x1094.jpg 1536w\" sizes=\"auto, (max-width: 2003px) 100vw, 2003px\" \/><figcaption class=\"wp-element-caption\">Our Microsoft Digital schema clearly lays out what each container sensitivity label means and how it affects content.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">If a container owner needs different policies for a set of files to provide greater external access, they can self-service new groups without accidentally violating our governance practices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At Microsoft, we use Microsoft Purview, which is our suite of data estate management tools, but you can use your tool of choice to apply labels in your environment. Microsoft tools will respect them. Microsoft Purview helps us accomplish three important tasks: mapping our labeling structure onto the relevant policies, verifying them against our standards, and backstopping self-service data loss prevention practices through automation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Automation is particularly useful. We\u2019ve configured <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/solutions\/information-protection\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Purview Information Protection<\/a> to scan automatically for wayward credentials, malicious user behaviors, and other sensitive information in items without the proper protections. When Purview detects a violation, our governance team receives alerts that prompt them to contain the risk by upgrading an item\u2019s sensitivity label or requiring employees to remedy the issue.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The result is a system that allows flexibility for employees to self-manage their digital workspaces while providing guardrails that help our governance experts take appropriate actions without overtaxing their time and resources.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our approach within Microsoft Digital is just one way to create an AI-ready data estate, but aspects of our story will hold true for almost any organization. Consider establishing a body to take over responsibility for AI-ready data, developing your primary goals for AI-ready data, unifying your data estate, and implementing a system of confidentiality labels.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Learning from our approach to agent governance strategy<\/h3>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background is-layout-grid wp-container-core-group-is-layout-f14c24dc wp-block-group-is-layout-grid\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:0;padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:0\">\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"40\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-define-responsiblity.png\" alt=\"\" class=\"wp-image-23648\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Define the responsibility for AI-ready data<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Identify and assign enterprise data owners to implement and oversee the processes that guarantee data quality.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"37\" height=\"40\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-create-intuitive-labels.png\" alt=\"\" class=\"wp-image-23649\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Create intuitive labels<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Your employees will be the ones applying labels, so make those labels intuitive. For example, \u201chighly confidential\u201d is easy to understand, while \u201cbusiness-critical\u201d could be interpreted in many ways from a sensitivity standpoint.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"40\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-dont-overwhelm.png\" alt=\"\" class=\"wp-image-23650\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Don\u2019t overwhelm your users<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Make labeling simple and intuitive to ensure it isn\u2019t overwhelming. Employees should have a limited set of choices to keep things comprehensible.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"41\" height=\"40\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-use-existing-defaults.png\" alt=\"\" class=\"wp-image-23651\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Use existing defaults<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Identify the security needs and regulatory compliance that are specific to your organization and use built-in governance controls available through Microsoft tools.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-container-core-group-is-layout-7db9d80f wp-block-group-is-layout-constrained\" style=\"padding-right:0;padding-left:0\">\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-container-core-group-is-layout-639b5052 wp-block-group-is-layout-constrained\" style=\"padding-top:0;padding-right:0;padding-bottom:0;padding-left:0\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"50\" height=\"50\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-Key-takeaways.png\" alt=\"\" class=\"wp-image-23628\" style=\"width:48px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h2 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Key takeaways<\/h2>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">You can use these tips based on what we learned here at Microsoft to tackle agent governance at your company:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Establish a cross-functional data council. <\/strong>Form a data council to help promote a culture of AI-ready data with professionals from all relevant disciplines, including human resources, legal, security, IT, and anyone else who can share relevant expertise.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Certify datasets for AI workloads<\/strong>. Limit agents to datasets that have been certified as \u201cAI-ready\u201d to minimize hallucinations and reasoning errors.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Define your labeling parameters<\/strong>. Keep the number of labels to five main labels with five sub-labels each. The fewer you use, the better.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Align your sensitivity labels with policies. <\/strong>Consider how your labels line up with breadth of availability, external permissions, sharing guidelines, and conditional access.<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"50\" height=\"50\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-Learn-more.png\" alt=\"\" class=\"wp-image-23629\" style=\"width:48px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h2 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Learn more<\/h2>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>How we did it at Microsoft<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list is-style-list-no-bullets\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/transforming-our-data-culture-with-ai-ready-data\/\">Follow our journey as we transform our data culture with AI-ready data.<\/a> This story highlights how we\u2019re using Microsoft Fabric and Microsoft Purview to revolutionize our approach to data governance and AI readiness here at Microsoft.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/harnessing-ai-how-a-data-council-is-powering-our-unified-data-strategy-at-microsoft\/\">Discover how a data council is powering our unified data strategy at Microsoft.<\/a> This post tells the story of how the Microsoft Digital Data Council is leading our efforts to adopt an AI-ready data strategy.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/conditioning-our-unstructured-data-for-ai-at-microsoft\/\">See how we&#8217;re conditioning our unstructured data for AI at Microsoft.<\/a> This article explains our internal strategies for handling unstructured data, which can be surfaced by AI agents.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Further guidance for you<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list is-style-list-no-bullets\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/cloud-adoption-framework\/ai-agents\/governance-security-across-organization\" target=\"_blank\" rel=\"noreferrer noopener\">Learn about governance and security for agents<\/a> and how to keep your AI initiatives secure across your organization.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/cloud-adoption-framework\/ai-agents\/responsible-ai-across-organization\" target=\"_blank\" rel=\"noreferrer noopener\">Establish responsible AI policies for AI agents<\/a> to support ethical, transparent, and accountable AI agent deployment across your organization.<\/li>\n<\/ul>\n<\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"chapter-3\">Chapter 3: A matrixed approach to agent governance<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Governing different types of agents for different contexts, built with different toolsets<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our customers have expressed a strong desire to start building agents, but they\u2019re concerned about where to begin and how to manage those agents once they\u2019re built. They worry about persistent problems such as hallucinations and agent sprawl. These concerns are especially pronounced on IT teams.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During our Customer Zero journey, we\u2019ve learned that the diversity of agent types and creation methods means there\u2019s no one-size-fits-all approach to governance. Generalized approaches will only get you so far.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ve found it helpful to think about different kinds of agents along an escalating spectrum of development complexity:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"622\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Agent-Controls-Model-infographic_blue-REV.jpg\" alt=\"The Microsoft Digital agent controls model, spanning citizen, partnered, and professional development models and their relevant tools.\" class=\"wp-image-23827\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Agent-Controls-Model-infographic_blue-REV.jpg 1024w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Agent-Controls-Model-infographic_blue-REV-300x182.jpg 300w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Agent-Controls-Model-infographic_blue-REV-768x467.jpg 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">The agent controls model we\u2019ve developed at Microsoft Digital spans different agent-building methods for different kinds of creators using a spectrum of tools.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">There\u2019s an entire matrix of different parameters that apply to an agent at any level of this spectrum, and they all require different policies. Those parameters include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Level of reach<\/strong>: Personal agents, limited sharing (like development environments or team boundaries), or enterprise-wide distribution<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Agent-building tool<\/strong>: <a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/unlocking-knowledge-through-intelligence-lessons-learned-using-sharepoint-agents-at-microsoft\/\">SharePoint agent builder<\/a>, Agent Builder in Microsoft 365 Copilot, <a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/unlocking-enterprise-ai-extensibility-at-microsoft-with-microsoft-copilot-studio\/\">Microsoft Copilot Studio<\/a>, or tools geared to more professional developers (such as Microsoft Foundry or Microsoft 365 Agent Toolkit)<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Knowledge sources and content accuracy<\/strong>: Public sites, SharePoint and OneDrive, directly uploaded files, enterprise apps and systems, or third-party knowledge bases<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"605\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Agents-What-to-build-and-where_blue-REV.jpg\" alt=\"An overview of the range of agent-building tools and our matrixed approach to governing them across different parameters.\" class=\"wp-image-23828\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Agents-What-to-build-and-where_blue-REV.jpg 1024w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Agents-What-to-build-and-where_blue-REV-300x177.jpg 300w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Agents-What-to-build-and-where_blue-REV-768x454.jpg 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Our matrixed approach to agent creation and governance spans a wide array of tools, knowledge sources, actions, channels, and more.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Each of these parameters creates a pivot that we need to govern, and we\u2019ve carefully assembled a set of policies and controls to account for them. As our understanding and use of agents advances, we\u2019re continually updating how we match their characteristics and capabilities with relevant policies and any applicable reviews.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Within Microsoft Digital, we\u2019ve adopted a risk-based approach that helps us establish a matrixed model for agent governance. The foundational idea is that we identify potential harms for each kind of agent, then assign policies for the level of review and oversight they require.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, simple agents that can only read and present data tend to be low risk. Because their access is tied to their creators\u2019 identities and access, our data governance structures and guardrails can prevent overexposure. But for agents that have capabilities like writing data, taking action, or creating items, more reviews are necessary.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">A matrix of agent governance policies, pivoted by parameter<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The following matrix enumerates the factors that determine how we govern different kinds of agents created using different tools. This matrix helps our employees understand the agent creation process and helps us maintain safety and control.<\/p>\n\n\n\n<div class=\"wp-block-group is-layout-grid wp-container-core-group-is-layout-b757edec wp-block-group-is-layout-grid\">\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-ef8af98e wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<p class=\"wp-block-paragraph\"><strong>SharePoint agent builder<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>What users can build:<\/em> <strong>Knowledge-only agents<\/strong><br>These agents reason over Microsoft 365 Copilot collaboration data, and they\u2019re gated to the SharePoint environment where they\u2019re created.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Technical proficiency:<\/em> No-code<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Knowledge sources:<\/em> SharePoint, custom instructions<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Capabilities:<\/em> Not applicable<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Actions and plug-ins:<\/em> Not applicable<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Sharing and publishing:<\/em> Copilot navigation in SharePoint, sharing by link, sharing in Microsoft Teams chat<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Custom engine or bring-your-own model:<\/em> Not applicable<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Reviews: <\/em><strong>No review needed<\/strong><br>IT doesn\u2019t gate knowledge-only agents outside of governance tied to SharePoint sites. Microsoft Digital honors reactive take-down requests like any other self-service construct, but does not provide proactive gating.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-ef8af98e wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<p class=\"wp-block-paragraph\"><strong>Agent Builder in Microsoft 365 Copilot<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>What users can build:<\/em> <strong>Knowledge-only agents<\/strong><br>These agents feature graph connectors from a preapproved catalog to expose additional data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Technical proficiency:<\/em> No-code<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Knowledge sources:<\/em> SharePoint, external websites, custom instructions, additional internal knowledge sources via graph connectors<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Capabilities:<\/em> Code interpreter, image generator<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Actions and plug-ins:<\/em> Not applicable<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Sharing and publishing:<\/em> Individual use, sharing by link<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Custom engine or bring-your-own model:<\/em> Not applicable<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Reviews: <\/em><strong>No review necessary<\/strong><br>These agents only access graph data available in Copilot. Microsoft Digital honors reactive take-down requests like any other self-service construct, but does not provide proactive gating.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-ef8af98e wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<p class=\"wp-block-paragraph\"><strong>Microsoft Copilot Studio<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>What users can build:<\/em> <strong>Task and custom agents<\/strong><br>These agents connect to more systems through connectors and orchestration logic to handle more complex scenarios. We might publish agents at this level of complexity and utility to our agent catalog for wide organizational use.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Technical proficiency:<\/em> Low-code or pro-code<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Knowledge sources:<\/em> SharePoint, external websites, custom instructions, additional internal knowledge sources via advanced graph connectors, Power Platform connectors<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Capabilities:<\/em> Not applicable<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Actions and plug-ins:<\/em><br><strong>Retrieval and task agents:<\/strong> Read-only actions<br><strong>Custom agents:<\/strong> Read or write actions using Power Platform connectors<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Sharing and publishing:<\/em><br><strong>Retrieval or task agents in a personal developer environment:<\/strong> Sharing by link with up to 10 people<br><strong>Custom agents:<\/strong> Publishing to 10 people or the agent catalog in Microsoft 365 Copilot Chat<br><strong>Broad publishing:<\/strong> Requires a review similar to professionally developed apps, including an understanding of the agent\u2019s data implications<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Custom engine or bring-your-own model:<\/em> Custom Azure OpenAI large language models (LLMs)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Reviews:<\/em> <strong>Custom agents<\/strong> <strong>for our catalog <\/strong>require reviews for security, privacy, accessibility, responsible AI, and an environment-specific maker stack review.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-ef8af98e wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<p class=\"wp-block-paragraph\"><strong>Microsoft Foundry<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>What users can build: <\/em><strong>Retrieval, task, and custom agents<\/strong><br>These agents may or may not connect to more systems through connectors and orchestration logic to handle more complex scenarios. We might publish agents produced at this level of complexity and utility as Microsoft Teams apps or to our agent catalog for wide organizational use.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Technical proficiency:<\/em> Pro-code<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Knowledge sources:<\/em> SharePoint, external websites, custom instructions, additional internal knowledge sources via graph connectors<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Capabilities:<\/em> Code interpreter, image generator, Teams chats and channels<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Actions and plug-ins:<\/em> API actions<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Sharing and publishing:<\/em> Publishing as an app in Teams or as an agent in the catalog in Copilot Chat<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Custom engine or bring-your-own model:<\/em> Custom Azure OpenAI large language models (LLMs)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Reviews:<\/em> <strong>Custom agents for publishing as a Teams app or in our catalog<\/strong> require reviews for security, privacy, accessibility, responsible AI, and an environment-specific maker stack review.<\/p>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">In addition to mapping out our policies for governing agents, the matrix illustrates how we see their relative utility across the organization. It demonstrates an escalation from personally useful to organizationally useful agents. Their governance policies and controls escalate accordingly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Regionality is an additional concern. Regulatory compliance might vary, but it\u2019s important to keep in mind that certain kinds of data access and actions might be perfectly permissible in one region, but not in another. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One example is our Employee Self-Service Agent, a central resource employees can turn to for <a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/accelerating-employee-services-at-microsoft-with-the-employee-self-service-agent\/\">help with IT support, HR questions, and facilities requests<\/a>. Because it can access potentially sensitive personal information, this agent required <a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/transforming-into-an-ai-first-frontier-firm-in-partnership-with-our-works-councils\/\">additional review from European works councils to ensure it met all relevant workplace standards<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As you facilitate the experimentation and innovation with agents across your workforce from citizen developers to pro developers, consider adopting a similar matrixed approach to agent governance. It starts with understanding your organization\u2019s needs, your risk tolerance, and the different employee populations you want to equip with agent-building capabilities.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Learning from our matrixed approach to agent governance<\/h3>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background is-layout-grid wp-container-core-group-is-layout-f14c24dc wp-block-group-is-layout-grid\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:0;padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:0\">\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"41\" height=\"40\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-figure-out-building-environment.png\" alt=\"\" class=\"wp-image-23656\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Figure out your building environment strategy<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Decide which scenarios match up with specific environments and make those environments available to the relevant employees.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"40\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-design-governance-structures.png\" alt=\"\" class=\"wp-image-23657\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Design governance structures that scale from low-code to more advanced agentic tools<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">With the proliferation of AI agents, platform-level approvals <a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/empowering-employees-with-the-microsoft-power-platform-at-microsoft\/\">similar to the Power Platform model at Microsoft<\/a> can ensure rapid innovation while requiring review for individual high-impact scenarios.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"40\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-build-trust.png\" alt=\"\" class=\"wp-image-23658\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Build trust through transparency and structure<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">A clear, well-documented approval process helps internal regulatory advisors understand new AI technologies and establishes the trust needed for productive, long-term collaboration.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"44\" height=\"40\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-regional-partners.png\" alt=\"\" class=\"wp-image-23659\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Treat regional partners as strategic allies in the agentic future<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Early feedback on digital agents from regional partners like works councils helps improve product design, accelerate approvals, and reduce fear or misconceptions about AI in the workplace.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"44\" height=\"40\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-Copilot-Studio.png\" alt=\"\" class=\"wp-image-23660\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Don\u2019t forget that Copilot Studio is part of Power Platform<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">You can use what you\u2019ve learned empowering citizen developers in Power Platform to guide your work with agents.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-container-core-group-is-layout-7db9d80f wp-block-group-is-layout-constrained\" style=\"padding-right:0;padding-left:0\">\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-container-core-group-is-layout-639b5052 wp-block-group-is-layout-constrained\" style=\"padding-top:0;padding-right:0;padding-bottom:0;padding-left:0\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"50\" height=\"50\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-Key-takeaways.png\" alt=\"\" class=\"wp-image-23628\" style=\"width:48px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h2 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Key takeaways<\/h2>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Use these tips based on what we learned here at Microsoft to tackle agent governance at your company:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Establish your tolerance for risk.<\/strong> Determine where the most prevalent risks emerge across different populations and kinds of agents. Remember, you control the guardrails in your environment.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Determine what agent-building tools you want to roll out and who can use them.<\/strong> Different populations benefit from different agent-building capabilities. Put thought into what individuals and teams can create and the degree of partnership each level will need from IT.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Define your governance parameters for different kinds of agents.<\/strong> Determine the best ways to hedge against risk at every level. For example, you might choose to trust in tenant governance for simple agents and establish reviews for more complex tools.<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"50\" height=\"50\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-Learn-more.png\" alt=\"\" class=\"wp-image-23629\" style=\"width:48px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h2 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Learn more<\/h2>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>How we did it at Microsoft<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list is-style-list-no-bullets\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/empowering-employees-with-the-microsoft-power-platform-at-microsoft\/\">See how we\u2019re empowering employees with the Power Platform.<\/a> This article explains how our Power Platform governance model influenced our matrixed approach to agent governance.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/the-frontier-firm-how-knowledge-workers-are-forging-their-own-ai-tools-at-microsoft\/\">Learn how our employees are building their own AI tools.<\/a> This article describes how knowledge workers at Microsoft are forging their own agents to help improve efficiency and get more done.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/unlocking-knowledge-through-intelligence-lessons-learned-using-sharepoint-agents-at-microsoft\/\">Check out our lessons learned using SharePoint agents at Microsoft.<\/a> This post shows how we approached governance for low-risk, knowledge-only agents through our deployment of SharePoint agents.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/unlocking-enterprise-ai-extensibility-at-microsoft-with-microsoft-copilot-studio\/\">Read how we\u2019re unlocking enterprise AI extensibility with Copilot Studio.<\/a> This story explores how we govern more advanced agents built with Copilot Studio, including connectors, orchestration, and scaled governance.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Further guidance for you<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list is-style-list-no-bullets\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/cloud-adoption-framework\/ai-agents\/governance-security-across-organization\" target=\"_blank\" rel=\"noreferrer noopener\">Explore governance and security for AI agents across the organization<\/a> with Microsoft Learn content.<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Check out this <a href=\"https:\/\/www.nist.gov\/itl\/ai-risk-management-framework\" target=\"_blank\" rel=\"noreferrer noopener\">industry-standard framework that validates matrixed, risk-based governance approaches for AI systems<\/a>.<\/li>\n<\/ul>\n<\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"chapter-4\">Chapter 4: Tracking, impact, and value<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Managing agents and assessing their business impact for the organization<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s clear that agents bring astonishing capabilities to the enterprise. For many organizations, what remains unclear is exactly how to measure their impact. Without that information, businesses are at a loss for ways to articulate value and drive improvement. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Tracking agents is also a crucial component of preventing sprawl: We need to understand what agents we have, how employees are using them, what critical processes they\u2019re supporting, and if they\u2019re contributing value or need to be retired.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019re at the beginning of our impact-tracking journey, but our work can provide a starting point for your own efforts to measure the value of AI initiatives at your organization.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Managing our agent catalog through comprehensive tracking<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft Digital partners with other internal organizations to ensure we\u2019re prioritizing the right agents and avoiding agent sprawl. Ideally, these engagements take place before teams start building their agents so we can avoid wasted effort or duplicated work.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Still, ongoing management efforts are crucial to keeping our agent ecosystem healthy. Telemetry is the key to assessing usage and ensuring compliance. We\u2019ve developed our own internal tooling to ensure that:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Metadata is complete and available<\/li>\n\n\n\n<li class=\"wp-block-list-item\">The tooling tells us the right information about our agents<\/li>\n\n\n\n<li class=\"wp-block-list-item\">The tools connect properly with other compliance tooling, like Microsoft Purview<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This telemetry also reveals agent behaviors, shows how agents do their work, and tracks events, actions, and policy baselines.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These capabilities help us gain visibility into policy adherence and violations, and then to conduct enforcement actions. We also track the speed of reaction and mitigation. AI-ready data and robust guardrails mean we head off most violations before they occur.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A robust inventory, an agile policy framework, and an automated workflow for enforcement are cornerstones for successfully governing agents at scale.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-agent-365\" target=\"_blank\" rel=\"noreferrer noopener\">release of Microsoft Agent 365, now in early access<\/a>, represents the next step in agent observability and management, two key aspects of agent governance and sprawl mitigation. This control pane for agents incorporates many of our learnings as we\u2019ve bridged governance gaps through IT intervention. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some of the key aspects of the control pane:<\/p>\n\n\n\n<div class=\"wp-block-group is-layout-grid wp-container-core-group-is-layout-acc8bb78 wp-block-group-is-layout-grid\">\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-2065403a wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"55\" height=\"55\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-registry.png\" alt=\"\" class=\"wp-image-23661\" style=\"width:48px\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><strong>The registry<\/strong> <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Provides a complete view of agents, and the enterprise agent store makes it easy to find the right agents for each role and business process within familiar workflows in Microsoft 365 Copilot and Teams.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-2065403a wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"55\" height=\"55\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-visualization.png\" alt=\"\" class=\"wp-image-23662\" style=\"width:48px\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><strong>Visualization<\/strong> <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Delivers the observability layer, including role-specific oversight, compliance and audit features, and performance measurements that can help organizations track their agents\u2019 impact and see where they contribute value.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-2065403a wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"55\" height=\"55\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-interoperability.png\" alt=\"\" class=\"wp-image-23663\" style=\"width:48px\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><strong>Interoperability<\/strong> <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ensures Agent 365 is open to any Microsoft-built or partner ecosystem, while delivering work intelligence through access to data and Microsoft 365 apps.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-2065403a wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"55\" height=\"55\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-security-features.png\" alt=\"\" class=\"wp-image-23664\" style=\"width:48px\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><strong>Security<\/strong> <strong>features<\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Provide crucial confidence through visibility into security posture, detection and response capabilities, and intelligent runtime defense.<\/p>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">As Customer Zero for Agent 365, we\u2019re excited to have a platform for observability and telemetry that encompasses everything from agentic creation through usage.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Tracking governance from agent inception<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Professionally developed agents add a new dimension of tracking and governance, because we need standards in place for ensuring compliant agent-building and to remediate any issues.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We use our Azure DevOps instance to catalog apps on our tenant, and we\u2019ve applied this practice to agents created professionally for lines of business and enterprise agents. This tool contains our service tree with product and app log registration, which is tied to our KPI dashboard and scoring system that validates agent data against our policies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our expectation is that all new apps and agents start from a place of compliance. Any new agent is registered through this platform, and we expect adherence within the first 14 days. In our experience, the introduction of new metrics, policies, or timeframes as our governance policies evolve is where agents tend to drop out of compliance. The priority is restoring compliant status.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ve established a series of metrics to help track and manage these expectations:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Enablement velocity<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Renewal velocity<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Agents in compliance<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Time to remediation of noncompliance<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Through a DevOps process built on our preexisting software development lifecycle practices, we\u2019ve applied governance not only to agents themselves, but to the process of building them professionally.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Measuring progress and unlocking value<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Properly measuring value depends on concrete definitions of success and metrics that support it. Articulating AI\u2019s impact came with several challenges. First, we had to land on a consistent taxonomy for different measurement areas. Then we needed to make the relevant data accessible, ensure its quality, and confirm it made sense.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Microsoft Digital AI Value Framework is our flexible, modular tool for measuring the impact of our AI initiatives. With tools for measurement firmly in place, we can effectively demonstrate value and guide further decision-making.<\/p>\n\n\n\n<div class=\"wp-block-group is-layout-grid wp-container-core-group-is-layout-b757edec wp-block-group-is-layout-grid\">\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-ef8af98e wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<p class=\"wp-block-paragraph\"><strong>Revenue impact<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Direct contributions to revenue generation and business growth<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Example metrics:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Increased sales or customers<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Improved customer targeting<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Higher lead quality<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Deal velocity<\/li>\n<\/ul>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-ef8af98e wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<p class=\"wp-block-paragraph\"><strong>Productivity and efficiency<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Efficiency gains while completing tasks and processes without a reduction in quality<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Example metrics:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Increased throughput<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Process optimization<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Task automation<\/li>\n<\/ul>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-ef8af98e wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<p class=\"wp-block-paragraph\"><strong>Security and risk management<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Improvements in identifying, preventing, and managing security vulnerabilities and risks<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Example metrics:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Vulnerability detection or prevention<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Reduction in data security incidents<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Increased compliance with responsible AI standards<\/li>\n<\/ul>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-ef8af98e wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<p class=\"wp-block-paragraph\"><strong>Employee and customer experience<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The impact of AI initiatives on employee satisfaction, engagement, and productivity<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Example metrics:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Employee or customer engagement satisfaction with products or services<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Improved employee health scores<\/li>\n<\/ul>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-ef8af98e wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<p class=\"wp-block-paragraph\"><strong>Quality improvement<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Enhancements in the quality of deliverables, services, and processes<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Example metrics:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Higher-quality deliverables<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Confidence in code quality<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Accuracy of numbers<\/li>\n<\/ul>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-ef8af98e wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<p class=\"wp-block-paragraph\"><strong>Cost savings<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Reduction in operational costs and resource allocation efficiencies<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Example metrics:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Operational efficiencies<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Improved resource allocation<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Future cost avoidance<\/li>\n<\/ul>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">We plan to use the following capabilities to improve the overall ecosystem:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Filtering our agent inventory on specific criteria like the type of agent or how it was built<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Enhancing governance-specific actions we can take with agents in areas like ownership and quarantining<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Gaining visibility into trends like agent usage<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Ingesting agent blueprints and defining policy templates<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019re still in the midst of our agentic measurement journey at Microsoft, but the blueprint for tracking already exists. Your organization might be in the early stages of agent readiness and deployment. If that\u2019s the case, it could be helpful for you to internalize the lessons we\u2019ve learned as Customer Zero and apply them as early as possible in your own journey toward AI maturity.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Learning from our agent adoption experience<strong><\/strong><\/h3>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background is-layout-grid wp-container-core-group-is-layout-f14c24dc wp-block-group-is-layout-grid\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:0;padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:0\">\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"44\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-think-proactively.png\" alt=\"\" class=\"wp-image-23665\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Think proactively, not retroactively<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">If you put effort into tracking agentic impact early in your AI maturity journey, you\u2019ll be poised to start capturing insights immediately instead of applying your methodology retroactively.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"38\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-involve-stakeholders.png\" alt=\"\" class=\"wp-image-23666\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Involve a wide array of stakeholders<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">This workstream needs oversight from different kinds of stakeholders, including your leadership team, IT, Microsoft 365 administrators, agent developers and builders, and employee champions. That will provide the sponsorship, expertise, and perspective you need for success.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"39\" height=\"40\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-different-measures.png\" alt=\"\" class=\"wp-image-23667\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Different measurements will be appropriate for different phases of your initiatives<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">These measurements include monthly, weekly, or daily active usage; consider which metrics make sense at each phase of an AI initiative.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"40\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-establish-a-continuum-of-value.png\" alt=\"\" class=\"wp-image-23668\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Establish a continuum of value<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Agents need to tie into real business goals, so it\u2019s important to establish metrics that actually speak to those objectives. Cascade business goals to concrete KPIs with well-defined timelines and track those diligently.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group wp-container-content-d8344436 has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9c22b1e3 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"40\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-embrace-the-red.png\" alt=\"\" class=\"wp-image-23669\" style=\"width:36px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Embrace the red<\/h4>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Try to think of underperformance not as failure, but as data. Performance data over time helps you course correct or pivot, making sure you invest where it matters.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-container-core-group-is-layout-7db9d80f wp-block-group-is-layout-constrained\" style=\"padding-right:0;padding-left:0\">\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-container-core-group-is-layout-639b5052 wp-block-group-is-layout-constrained\" style=\"padding-top:0;padding-right:0;padding-bottom:0;padding-left:0\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"50\" height=\"50\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-Key-takeaways.png\" alt=\"\" class=\"wp-image-23628\" style=\"width:48px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h2 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Key takeaways<\/h2>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Here are some important steps to keep in mind as you embark on your own tracking and measurement efforts for agents:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Establish priorities and parameters for tracking agents. <\/strong>Consider measurements that relate to sprawl, usage, and coverage, and build them into your telemetry tooling.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Pull your stakeholders together to establish measurement parameters.<\/strong> Cascade business priorities into measurable value.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Conduct ongoing tracking.<\/strong> Establish a cadence for tracking and reviewing progress with your team.<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"50\" height=\"50\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-Learn-more.png\" alt=\"\" class=\"wp-image-23629\" style=\"width:48px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h2 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Learn more<\/h2>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>How we did it at Microsoft<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list is-style-list-no-bullets\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/measuring-the-impact-of-microsoft-365-copilot-and-ai-at-microsoft\/\">Learn how we\u2019re measuring the impact of Microsoft 365 Copilot and AI at Microsoft.<\/a> Discover our framework for tracking the impact of the investments in AI that we\u2019re making internally.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/deploying-microsoft-agent-365-how-were-extending-our-infrastructure-to-manage-agents-at-microsoft\/\">Find out how we\u2019re deploying Microsoft Agent 365 internally.<\/a> This story shares our intentions for using our unified control pane for agents.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/defining-the-future-how-were-building-an-ai-powered-continuous-improvement-culture-at-microsoft\/\">See how we\u2019re building an AI-powered continuous improvement culture at Microsoft.<\/a> This article outlines our approach to continuous improvement.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/accelerating-transformation-how-were-reshaping-microsoft-with-continuous-improvement-and-ai\/\">Check out how we\u2019re reshaping Microsoft with continuous improvement and AI.<\/a><strong> <\/strong>This post discusses the importance of continuous improvement for accelerating AI at Microsoft, including three initiatives already underway.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Further guidance for you<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list is-style-list-no-bullets\">\n<li class=\"wp-block-list-item\">This Microsoft Learn guidance <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/cloud-adoption-framework\/strategy\/\" target=\"_blank\" rel=\"noreferrer noopener\">helps organizations align AI investments with strategic goals and measurable outcomes over time<\/a>.<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Explore a cloud adoption framework that provides <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/cloud-adoption-framework\/\" target=\"_blank\" rel=\"noreferrer noopener\">practical guidance for defining success metrics, tracking ROI, and tying AI initiatives to business outcomes<\/a>.<\/li>\n<\/ul>\n<\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"conclusion\">Governing the frontier to scale innovation <strong><\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">AI agents are rapidly becoming core contributors to how work gets done. As our experience within Microsoft Digital demonstrates, realizing their full potential demands more than powerful tools or enthusiastic builders. It requires thoughtful governance that evolves alongside your AI maturity, protects what matters, and gives employees the confidence to innovate responsibly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As you consider your own strategy for managing agents, it can be helpful to keep one truth in mind: Governance is a catalyst for progress, not a barrier. By embedding guardrails into tools, grounding agent creation in AI\u2011ready data, applying risk\u2011based and matrixed policies, and reinforcing all of it through adoption and education, we\u2019ve been able to expand agentic capability without sacrificing security, privacy, or trust.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">From our experience, we\u2019ve learned that governance works best when it\u2019s:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Proportional<\/strong>, scaling with risk and agent complexity<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Embedded<\/strong>, not bolted on after the fact<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Human\u2011led<\/strong>, recognizing that accountability and judgment remain essential<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Iterative<\/strong>, adapting as technology, regulations, and business needs evolve<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">When you design governance this way, it allows experimentation, learning, and impact at scale. Employees feel empowered to build agents that solve real problems, while IT and compliance teams gain visibility and control without becoming bottlenecks. Crucially, leaders can measure value, manage risk, and make informed decisions about where to invest next.<\/p>\n\n\n\n<div class=\"wp-block-group has-light-blue-to-light-green-gradient-background has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-10685bb4 wp-block-group-is-layout-constrained\" style=\"padding-right:0;padding-left:var(--wp--preset--spacing--spacing-20)\">\n<div class=\"wp-block-group has-white-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-ff4033b8 wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--spacing-16);padding-right:var(--wp--preset--spacing--spacing-16);padding-bottom:var(--wp--preset--spacing--spacing-16);padding-left:var(--wp--preset--spacing--spacing-16)\">\n<figure class=\"wp-block-image alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Vijaya-Alpathi_blue.png\" alt=\"A photo of Alaparthi.\" class=\"wp-image-23630\" style=\"width:150px\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Vijaya-Alpathi_blue.png 500w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Vijaya-Alpathi_blue-300x300.png 300w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Vijaya-Alpathi_blue-150x150.png 150w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n\n\n\n<p class=\"has-body-xl-font-size wp-block-paragraph\" style=\"margin-top:0;margin-bottom:var(--wp--preset--spacing--spacing-4);font-style:normal;font-weight:600\"><em><em>\u201cAt Microsoft, we believe the future of agentic AI depends on governance that empowers people first. The structures should be invisible when they\u2019re working, intentional when they&#8217;re needed, and trusted by everyone they serve.\u201d<\/em><\/em><\/p>\n\n\n\n<p class=\"has-gray-800-color has-text-color has-link-color has-body-lg-font-size wp-elements-652c702e2ab32ad8f8fa2cfd6c73e040 wp-block-paragraph\" style=\"margin-top:0;margin-bottom:var(--wp--preset--spacing--spacing-4)\"><strong><strong>Vijaya Alaparthi, principal group product manager, Microsoft Digital<\/strong><\/strong><\/p>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">This is the foundation of the Frontier Firm: Organizations where humans lead and agents operate, guided by clear principles and trusted systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As you continue your AI maturity journey, remember that there is no single, correct governance model. Your approach will reflect your risk tolerance, regulatory environment, data maturity, and organizational culture. The practices outlined here provide a proven starting point informed by real-world deployment at enterprise scale.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cAt Microsoft, we believe the future of agentic AI depends on governance that empowers people first,\u201d says Vijaya Alaparthi, principal group product manager in Microsoft Digital. \u201cThe structures should be invisible when they\u2019re working, intentional when they&#8217;re needed, and trusted by everyone they serve.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now is the moment to act. Start with strong foundations. Empower your builders. Measure what matters. And treat governance not as a constraint, but as a strategic advantage that allows your organization to move faster, innovate safely, and lead confidently on the agentic frontier.<\/p>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-container-core-group-is-layout-7db9d80f wp-block-group-is-layout-constrained\" style=\"padding-right:0;padding-left:0\">\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-container-core-group-is-layout-639b5052 wp-block-group-is-layout-constrained\" style=\"padding-top:0;padding-right:0;padding-bottom:0;padding-left:0\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"50\" height=\"50\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-Key-takeaways.png\" alt=\"\" class=\"wp-image-23628\" style=\"width:48px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h2 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Key takeaways<\/h2>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Here are the high-level learnings and insights that you need to consider as you embark on your own agent governance journey, based on what we\u2019ve learned here at Microsoft:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Treat governance as an enabler of innovation, not a brake.<\/strong> Effective agent governance is what makes large\u2011scale innovation possible. When you embed guardrails into platforms, data, and processes, employees can build and experiment confidently without exposing the organization to unnecessary risk or slowing progress.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Match governance rigor to agent risk and maturity.<\/strong> Not all agents need the same level of oversight. A risk\u2011based, matrixed approach lets organizations trust lightweight, personal agents while applying deeper reviews to agents that write data, take actions, or operate across business\u2011critical systems.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Start with AI\u2011ready data and zero\u2011trust foundations.<\/strong> Strong agent governance rests on secure, well\u2011labeled, high\u2011quality data. Clear ownership, intuitive sensitivity labels, default protections, and automation reduce reliance on user judgment and allow agents to operate safely at scale.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Embed governance where agents are built and used.<\/strong> The most effective governance is built into tools and workflows, not enforced through manual reviews alone. Defaults, limits, identity\u2011based access, lifecycle controls, and telemetry should apply automatically so agents are governed by design.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Plan for the full agent lifecycle to prevent sprawl.<\/strong> Agent inventories, ownership models, attestation, and retirement processes are essential. Governance needs to account for how you create, share, evolve, audit, and ultimately decommission agents, whether individuals or enterprise teams are responsible for building them.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Reinforce governance through adoption and education.<\/strong> Guardrails work best when employees understand them. Targeted adoption programs, clear guidance, prerequisites for advanced tools, and visible leadership sponsorship can help employees build responsibly and recognize their role in protecting the organization.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Measure what matters to prove value and drive improvement.<\/strong> Visibility drives trust. Telemetry, observability, and clear metrics that span productivity, quality, risk reduction, and experience allow organizations to track impact, course\u2011correct early, and continuously improve their agent ecosystem.<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"50\" height=\"50\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-Learn-more.png\" alt=\"\" class=\"wp-image-23629\" style=\"width:48px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h2 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Learn more<\/h2>\n<\/div>\n<\/div>\n\n\n\n<ul class=\"wp-block-list is-style-list-no-bullets\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/becoming-a-frontier-firm-our-it-playbook-for-the-ai-era\/\">Discover our IT playbook for becoming an AI-driven Frontier Firm.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/security-for-ai\/agent-365-security\" target=\"_blank\" rel=\"noreferrer noopener\">Learn how to secure your agents at scale with Microsoft Agent 365 guidance.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/cloud-adoption-framework\/ai-agents\/governance-security-across-organization\" target=\"_blank\" rel=\"noreferrer noopener\">Read a guide to governance and security for AI agents at your organization.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/how-were-tackling-microsoft-365-copilot-governance-internally-at-microsoft\/\">Check out this detailed guide to our governance process for the internal rollout of Microsoft 365 Copilot.<\/a> &nbsp;<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/cloud-adoption-framework\/ai-agents\/responsible-ai-across-organization\" target=\"_blank\" rel=\"noreferrer noopener\">Explore ways to establish responsible AI policies for agents across the organization.<\/a> &nbsp;<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/harnessing-ai-how-a-data-council-is-powering-our-unified-data-strategy-at-microsoft\/\">Find out how a data council is powering our unified data strategy at Microsoft.<\/a><\/li>\n<\/ul>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"43\" height=\"50\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-Try-it-out.png\" alt=\"\" class=\"wp-image-23673\" style=\"width:48px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h2 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Try it out<\/h2>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-agent-365\/?OCID=InsideTrack_Product_10814\" target=\"_blank\" rel=\"noreferrer noopener\">Get started building and managing agents at your company with Microsoft Agent 365.<\/a><\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:48px\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"54\" height=\"50\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/Icon-Wed-like-to-hear-from-you.png\" alt=\"\" class=\"wp-image-23674\" style=\"width:48px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<h2 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">We&#8217;d like to hear from you!<\/h2>\n<\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"mailto:msitstaff@microsoft.com\">Want more information? Email us and include a link to this story and we\u2019ll get back to you.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Empowering employees and protecting your organization through agent governance Welcome to the agentic frontier Engage with our experts! Customers or Microsoft account team representatives from Fortune 500 companies are welcome to request a virtual engagement on this topic with experts from our Microsoft Digital team. Agents are expanding the frontier of enterprise AI. By creating [&hellip;]<\/p>\n","protected":false},"author":115,"featured_media":23684,"comment_status":"closed","ping_status":"closed","sticky":true,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":true,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_hide_featured_on_single":false,"_show_featured_caption_on_single":true,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[71,854],"tags":[864,199,868,137,904,850,237,852,827,880,689,848,851],"coauthors":[622],"class_list":["post-23618","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-featured","category-readiness-guide","tag-agent","tag-ai","tag-ai-deployment-and-adoption","tag-change-management","tag-customer-zero","tag-end-user-services-and-support","tag-governance","tag-it-and-business-operations","tag-microsoft-365-copilot","tag-microsoft-copilot-studio","tag-network-security","tag-security-and-risk-management","tag-tenant-management","m-blog-post"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Governing AI agents at scale: Lessons from our journey at Microsoft - Inside Track Blog<\/title>\n<meta name=\"description\" content=\"We share our experience with managing the governance process as we\u2019ve rolled out AI agents across Microsoft.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Governing AI agents at scale: Lessons from our journey at Microsoft - Inside Track Blog\" \/>\n<meta property=\"og:description\" content=\"We share our experience with managing the governance process as we\u2019ve rolled out AI agents across Microsoft.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\/\" \/>\n<meta property=\"og:site_name\" content=\"Inside Track Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-21T16:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-22T18:05:32+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/10814-Hero_image.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2300\" \/>\n\t<meta property=\"og:image:height\" content=\"1293\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Alex Fleck\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alex Fleck\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"46 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\\\/\"},\"author\":{\"name\":\"Alex Fleck\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/b623d895338189d1c487d4a0b93d4764\"},\"headline\":\"Governing AI agents at scale: Lessons from our journey at Microsoft\",\"datePublished\":\"2026-05-21T16:00:00+00:00\",\"dateModified\":\"2026-05-22T18:05:32+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\\\/\"},\"wordCount\":8099,\"image\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2026\\\/05\\\/10814-Hero_image.jpg\",\"keywords\":[\"Agent\",\"AI\",\"AI deployment and adoption\",\"change management\",\"Customer Zero\",\"End user services and support\",\"governance\",\"IT and business operations\",\"Microsoft 365 Copilot\",\"Microsoft Copilot Studio\",\"Network Security\",\"Security and risk management\",\"Tenant management\"],\"articleSection\":[\"Featured\",\"Readiness Guide\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\\\/\",\"url\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\\\/\",\"name\":\"Governing AI agents at scale: Lessons from our journey at Microsoft - Inside Track Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2026\\\/05\\\/10814-Hero_image.jpg\",\"datePublished\":\"2026-05-21T16:00:00+00:00\",\"dateModified\":\"2026-05-22T18:05:32+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/b623d895338189d1c487d4a0b93d4764\"},\"description\":\"We share our experience with managing the governance process as we\u2019ve rolled out AI agents across Microsoft.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2026\\\/05\\\/10814-Hero_image.jpg\",\"contentUrl\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2026\\\/05\\\/10814-Hero_image.jpg\",\"width\":2300,\"height\":1293,\"caption\":\"Approach agent governance with confidence with our guide, which walks you through practical steps that empower employees while maintaining your security and compliance.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Governing AI agents at scale: Lessons from our journey at Microsoft\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/\",\"name\":\"Inside Track Blog\",\"description\":\"How Microsoft does IT\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/b623d895338189d1c487d4a0b93d4764\",\"name\":\"Alex Fleck\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/340114d229a43eb2e869170b958db0ecd4394144a36e326e2b188d4937b1989d?s=96&d=mm&r=g4cfaccedbee32e457bda8cf3019f258b\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/340114d229a43eb2e869170b958db0ecd4394144a36e326e2b188d4937b1989d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/340114d229a43eb2e869170b958db0ecd4394144a36e326e2b188d4937b1989d?s=96&d=mm&r=g\",\"caption\":\"Alex Fleck\"},\"description\":\"I\u2019ve always had a passion for story, whether I find it in a novel, a medieval epic, a movie, or a game. Now, I\u2019m helping tell stories about the people and teams at Microsoft who build the technology that moves our world. When I\u2019m not reading, writing, translating, or gaming, you\u2019ll find me on a backcountry trek in Canada\u2019s woods and mountains.\",\"url\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/author\\\/alexfleck\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Governing AI agents at scale: Lessons from our journey at Microsoft - Inside Track Blog","description":"We share our experience with managing the governance process as we\u2019ve rolled out AI agents across Microsoft.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.microsoft.com\/insidetrack\/blog\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\/","og_locale":"en_US","og_type":"article","og_title":"Governing AI agents at scale: Lessons from our journey at Microsoft - Inside Track Blog","og_description":"We share our experience with managing the governance process as we\u2019ve rolled out AI agents across Microsoft.","og_url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\/","og_site_name":"Inside Track Blog","article_published_time":"2026-05-21T16:00:00+00:00","article_modified_time":"2026-05-22T18:05:32+00:00","og_image":[{"width":2300,"height":1293,"url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/10814-Hero_image.jpg","type":"image\/jpeg"}],"author":"Alex Fleck","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Alex Fleck","Est. reading time":"46 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\/#article","isPartOf":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\/"},"author":{"name":"Alex Fleck","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#\/schema\/person\/b623d895338189d1c487d4a0b93d4764"},"headline":"Governing AI agents at scale: Lessons from our journey at Microsoft","datePublished":"2026-05-21T16:00:00+00:00","dateModified":"2026-05-22T18:05:32+00:00","mainEntityOfPage":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\/"},"wordCount":8099,"image":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/10814-Hero_image.jpg","keywords":["Agent","AI","AI deployment and adoption","change management","Customer Zero","End user services and support","governance","IT and business operations","Microsoft 365 Copilot","Microsoft Copilot Studio","Network Security","Security and risk management","Tenant management"],"articleSection":["Featured","Readiness Guide"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\/","url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\/","name":"Governing AI agents at scale: Lessons from our journey at Microsoft - Inside Track Blog","isPartOf":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\/#primaryimage"},"image":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/10814-Hero_image.jpg","datePublished":"2026-05-21T16:00:00+00:00","dateModified":"2026-05-22T18:05:32+00:00","author":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#\/schema\/person\/b623d895338189d1c487d4a0b93d4764"},"description":"We share our experience with managing the governance process as we\u2019ve rolled out AI agents across Microsoft.","breadcrumb":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.microsoft.com\/insidetrack\/blog\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\/#primaryimage","url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/10814-Hero_image.jpg","contentUrl":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/10814-Hero_image.jpg","width":2300,"height":1293,"caption":"Approach agent governance with confidence with our guide, which walks you through practical steps that empower employees while maintaining your security and compliance."},{"@type":"BreadcrumbList","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.microsoft.com\/insidetrack\/blog\/"},{"@type":"ListItem","position":2,"name":"Governing AI agents at scale: Lessons from our journey at Microsoft"}]},{"@type":"WebSite","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#website","url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/","name":"Inside Track Blog","description":"How Microsoft does IT","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.microsoft.com\/insidetrack\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#\/schema\/person\/b623d895338189d1c487d4a0b93d4764","name":"Alex Fleck","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/340114d229a43eb2e869170b958db0ecd4394144a36e326e2b188d4937b1989d?s=96&d=mm&r=g4cfaccedbee32e457bda8cf3019f258b","url":"https:\/\/secure.gravatar.com\/avatar\/340114d229a43eb2e869170b958db0ecd4394144a36e326e2b188d4937b1989d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/340114d229a43eb2e869170b958db0ecd4394144a36e326e2b188d4937b1989d?s=96&d=mm&r=g","caption":"Alex Fleck"},"description":"I\u2019ve always had a passion for story, whether I find it in a novel, a medieval epic, a movie, or a game. Now, I\u2019m helping tell stories about the people and teams at Microsoft who build the technology that moves our world. When I\u2019m not reading, writing, translating, or gaming, you\u2019ll find me on a backcountry trek in Canada\u2019s woods and mountains.","url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/author\/alexfleck\/"}]}},"jetpack_featured_media_url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/05\/10814-Hero_image.jpg","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9hcZA-68W","_links":{"self":[{"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/23618","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/users\/115"}],"replies":[{"embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/comments?post=23618"}],"version-history":[{"count":40,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/23618\/revisions"}],"predecessor-version":[{"id":23829,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/23618\/revisions\/23829"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/media\/23684"}],"wp:attachment":[{"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/media?parent=23618"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/categories?post=23618"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/tags?post=23618"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/coauthors?post=23618"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}