← All insights

News analysisLens: United States4 min read

When a Copilot agent keeps working after you leave, who owns what it does?

Microsoft's Autopilot, heading into private preview, turns delegation into a standing mandate. The governance questions that creates for enterprises running on Microsoft 365.

Listen to this article · 6 min

AI-generated narration of the full article.

Office tower at night with lit windows, in La Madre duotone, beside the words Standing mandate
Photo: Vladimir Kudinov (StockSnap, CC0)

Every enterprise AI governance model written so far rests on a quiet assumption: a person is present when the AI acts. The user asks, the assistant answers, the user decides. Approval happens in the moment, by someone who is looking.

Microsoft’s new Copilot breaks that assumption on purpose.

What Microsoft announced

On September 25, Microsoft introduced three capabilities in the Copilot app:

  • Home, which brings Chat and Cowork together, with Word, Excel and PowerPoint built into the experience.
  • Code, which lets people describe an app, dashboard or automation in natural language and have Copilot build it, on the same underlying technology as GitHub Copilot.
  • Autopilot, previously called Scout, which Microsoft describes as “a persistent, proactive and personal agent that keeps working even when you’re not.”

Status matters here. Home and Code roll out through Microsoft’s Frontier program. Autopilot expands to private preview at the end of the month. None of these is generally available yet.

Microsoft’s description of Autopilot is specific. You give it a name, a role and a goal. It watches channels, follows up on threads, runs recurring work and picks projects back up days later “without waiting for a prompt”. It lives in the tenant “with its own identity, memory, computer and workspace”, shows up in Teams and Outlook where it can be @mentioned like a colleague, and has, in Microsoft’s words, “permissions, audit and governance behind it”. Cowork, Code and Autopilot run on usage-based billing.

From assistant to mandate

A chat assistant executes requests. Autopilot executes a mandate: a standing instruction to pursue a goal over days, taking actions when the person who set it is asleep, in a meeting or on vacation.

That is a different kind of delegation, and it maps onto questions enterprises already know from human delegation: powers of attorney, spending authority, who can sign on behalf of the company. The difference is that these questions now apply to software that can send messages, schedule meetings and chase stakeholders on its own.

Microsoft’s example is telling: Autopilot can run a full supplier review process, “right down to reaching out to stakeholders for updates”. That means an agent writing to suppliers. Whose voice is that?

The lifecycle of a persistent agent mandate01Mandate: goal,scope, expiry02Agent acts inTeams andOutlook03Escalationwhen unsure04Audit review05Owner changeor expiryThe agentYour operating model
  1. Mandate: goal, scope, expiry
  2. Agent acts in Teams and Outlook
  3. Escalation when unsure
  4. Audit review
  5. Owner change or expiry

The agentYour operating model

A persistent agent turns delegation into a lifecycle. Only one of these steps belongs to the agent.

Six questions that need an owner

1. On whose authority does it act? Autopilot has its own identity, which is good for audit. It also means the agent is not simply “you”. Decide which commitments it may make on behalf of a person, a team or the company, and which it may never make.

2. What is in scope, and until when? A goal without an end date becomes a permanent process nobody designed. Mandates should have a scope, a review date and an expiry.

3. What happens when it is unsure? Define escalation: who is notified, through which channel, and what the agent does while waiting. “Keep going” and “stop” are both valid answers; “undefined” is not.

4. Who reads the audit trail? Microsoft says audit and governance are built in. A log only protects you if someone reviews it. For higher-risk mandates, decide on sampling or periodic review of what the agent actually did.

5. What happens when the owner leaves? People change roles and leave the company. An agent with an active mandate needs a transfer or shutdown process, the same way access rights do.

6. What is it allowed to spend? Usage-based billing means a long-running agent has a running cost. Microsoft announced FinOps capabilities in Agent 365, including spending policies and model availability per group. Someone has to set those limits per mandate, not only per tenant.

Operating at scale

For a large US enterprise, the practical answer is to treat persistent agents as a managed population, not as individual productivity tools:

  • A registry of active agents, with owner, purpose, scope and review date.
  • Risk tiers: an agent that summarizes channels is not an agent that writes to suppliers. Tier by the actions it can take, not by the tool it runs in.
  • A clear RACI between the business owner of the mandate, IT, security and compliance.
  • An offboarding step in HR and access-management processes that covers agents.

None of this is exotic. It is what enterprises already do for service accounts and scheduled jobs. The shift is that business users, not engineers, will be creating these agents.

During the private preview

If your organization joins the preview, use it to answer the questions above before scale arrives: pick two or three mandates with real value and moderate risk, write down their scope and escalation rules, and review the audit trail weekly. The goal of the preview is not to prove that the agent works. It is to prove that your operating model does.

For the broader picture of which layers platforms now provide and which remain yours, see our 2026 stack guide.

Have an AI use case stuck between prototype and production?

Tell us what you’re trying to ship. We’ll reply with honest next steps.

Discuss a use case