20+ years with Microsoft 1,100+ organisations under management 131 countries invoiced locally 5 of 6 Solutions Partner designations 4-hour first response
IT Partner.Microsoft Solutions Partner +44 20 8142 5752 Talk to us Get a quote

HomeBlog › Copilot Studio

Copilot · 16 September 2026 · 9 min read

Copilot Studio: building your own agents inside your own tenant

Microsoft 365 Copilot answers from what a person can already see. Copilot Studio is the next step: an agent with a job, fixed sources and, if you allow it, actions — running inside your tenant under your policies. What it costs, how one is built, and which three to build first.

Microsoft 365 Copilot answers questions from what a person can already see. Copilot Studio is the tool for the next step: an agent you design, with a name, a job, a fixed set of sources and, if you allow it, the ability to do things — look up a shipment, open a ticket, file a form. It runs inside your tenant, under your identity, subject to your data policies. This is what it is, what it costs, how an agent is built, and where the three agents most companies build first come from.

What Copilot Studio is, in one paragraph

A low-code builder inside Microsoft 365 for conversational agents. You give an agent instructions in plain English, point it at knowledge — SharePoint sites, documents, a Dataverse table, a website, a line-of-business system through a connector — and optionally give it actions: Power Automate flows or connector operations it may call. You publish it to Teams, to Microsoft 365 Copilot as a plug-in, to a website, or to a channel. It answers from its sources only, cites them, and refuses what it cannot ground. The whole thing is governed by the same Entra ID, Purview and data-loss-prevention policies as the rest of the tenant.

Licensing, honestly

There are two ways to pay, and the difference matters. Included with Microsoft 365 Copilot: a user with a Copilot licence can build and use agents in Copilot Studio within Microsoft 365 Copilot at no extra cost; the capacity is per user, and this covers most personal and team agents. Standalone Copilot Studio: for agents used by people without Copilot licences, or published externally, capacity is bought in message packs: €173.30 per month per pack of 25,000 messages on an annual commitment (€2,079.60 a year), or pay-as-you-go through Azure. A message is one agent response; a typical HR question costs one to three. Most companies under 500 people start on the included capacity and buy the first pack when an agent goes company-wide.

The Copilot Studio user licence itself is zero-priced in the catalogue; it is the message capacity that costs. The catalogue lists both SKUs.

Building an agent: the six steps

1. Decide what it must not do. Before the first click, write the sentence: “This agent answers questions about our leave, expenses and on-call policies from the HR handbook, and does not answer anything else.” Agents that try to be general assistants are the ones that embarrass their owners.

2. Create it in Copilot Studio (copilotstudio.microsoft.com, or from the Copilot app in Teams). Name, description, and the instructions from step one, in plain language, with the tone you want: “Answer briefly, cite the policy section, and if the question is outside the handbook say so and give the HR mailbox.”

3. Add knowledge. A SharePoint site or a document library is the usual first source; the agent indexes it and respects its permissions, so a user only gets answers from files they could open anyway. Add a public website for product documentation; add a Dataverse table or a SQL connector for structured data. Test the questions from step one immediately; most fixes at this stage are fixes to the documents, not to the agent.

4. Add actions, if any. Actions are where an agent stops answering and starts doing: a Power Automate flow that creates a ticket in your helpdesk, a connector call that looks up an order number in the ERP, an approval that goes to a manager. Each action is a defined operation with defined inputs; the agent does not get a free hand.

5. Set the guardrails. Authentication: who may talk to it — usually “anyone in the organisation”, sometimes a security group. Data-loss prevention: the Power Platform DLP policy that decides which connectors an agent may use, so nobody wires a customer table to a public service. Content moderation level. Environment: build in a development environment, publish in production, like any application.

6. Publish and watch. To Teams, so people find it where they work; as a Microsoft 365 Copilot agent, so it appears inside Copilot itself; or on a web page. The analytics show the questions it could not answer — that list is the roadmap for the next month.

The three agents most companies build first

The HR policy agent. Sources: the handbook, the benefits guide, the on-call rota policy. Action: none, or “open a case with HR”. It answers the forty questions HR answers by email every week, with the section cited, at midnight and on a Sunday. Build time: an afternoon, if the handbook is in SharePoint and current. Its value is decided by whether the handbook is current.

The IT helpdesk triage agent. Sources: the internal IT knowledge base, the software catalogue, the security policies. Actions: reset a password through a flow with MFA, open a ticket with the category pre-filled, look up a device in Intune. It resolves the “how do I” questions itself and hands over the rest with the diagnosis done. This one is usually the first to justify a message pack.

The supplier or customer onboarding agent. Sources: the onboarding checklist, the standard terms, the required documents. Actions: create the SharePoint folder, send the document-request email, add a row to the tracking list. It walks a new supplier through what is needed and does the clerical steps; a person does the approval.

Where it goes wrong

Three ways, in order of frequency. The sources are stale: the agent answers correctly from a policy that was superseded last year. Fix the library before the agent. Permissions are too wide: the agent surfaces a document a user should not have seen; that is a SharePoint permissions problem the agent has made visible. The scope creeps: someone adds “and answer general questions” and the agent starts guessing. Keep the sentence from step one on the wall.

What we do, and what you do

The permissions review and the DLP policy are the part where an outside pair of hands is worth the money: it is the same job every time, and it is the one nobody inside the company wants. The agent itself, most companies build themselves after the first one is built with them; that is the point of a low-code tool. Our custom development covers the first agent end to end, including the connector work to an ERP or a helpdesk; the Business Premium or Microsoft 365 E3 pages show what the base licence must include.

Related: One company, two agents: IT helpdesk and HR onboarding · Which Copilot? The six compared · Copilot at work: five companies, five departments · Copilot, ChatGPT or Claude for a Microsoft 365 company.

One email a month, at most

New write-ups, when there is one worth sending

Postmortems, timelines, licensing changes that cost people money. No newsletter cadence, no digest of other people’s news. If a month has nothing worth your time, you hear nothing.

Please enter a work email address.

Related

Worth reading next

Scoping costs nothing

Put the questions in this article to us

We will answer them about our own work, in writing, with the numbers. If the answers do not convince you, they should at least make the next partner’s answers easier to judge.