Microsoft's own IT says to pick the simplest agent platform that works. Review effort should follow risk
A Customer Zero guide shows how Microsoft routes builders between Agent Builder, Copilot Studio and Foundry, automates reviews by risk color and treats maker friction as a security metric.
Listen to this article · 5 min
AI-generated narration of the full article.

The most useful line in Microsoft’s new internal guide to building agents is a warning against its own most capable product. Teams should not choose Foundry, it says, “simply because it is the most powerful option”.
The guide, published on October 8 by Microsoft Digital, the company’s IT organization, describes how Microsoft enables its own employees to build agents across three products: Agent Builder in Microsoft 365 Copilot, Copilot Studio and Microsoft Foundry. It is an internal practice, not a product release, and some of it depends on controls Microsoft already runs. But the decision logic transfers to any company with more than one way to build an agent.
Four questions before any tool
Microsoft asks builders four questions before pointing them at a platform: what business outcome is intended; what data is needed, and whether it is personal, team-based or enterprise-wide; whether the agent retrieves information, takes actions or operates autonomously; and how broadly it will be shared.
Two of those four questions are about blast radius, not capability. Data scope and sharing breadth decide how much damage a mistake can do. The guide’s tiers follow from the answers.
| Tier | Who builds | What it does | Who owns the risk | Move up when |
|---|---|---|---|---|
| Agent Builder | Anyone | Retrieval from approved Microsoft 365 and web sources | The platform | Data outside Microsoft 365, actions or workflows are needed |
| Copilot Studio | Citizen and low-code developers | Tasks, workflows and connector actions | The administrator | Custom orchestration, model tuning or proprietary APIs are needed |
| Foundry | Professional developers | Automation across many services and channels | The organization | Top tier: governance is designed per solution |
The guide is candid that the boundaries overlap. Copilot Studio can handle autonomous behaviors that also fall within Foundry’s scope, so the tiers are a default, not a rule. It also gives a cost reason for staying low: the advanced tools often assume more capable, and more expensive, models.
Review that scales with risk
The part most companies should study is how Microsoft keeps review from becoming the bottleneck. Self-service agents in Copilot Studio are assessed mostly by automation against preconfigured settings. Agents shared across a line of business or the whole enterprise get full reviews by security, privacy and other specialists.
The triage has names. A Risk-O-Meter classifies submissions as green, yellow or red, then approves, declines or routes them to a reviewer. An Action-O-Meter applies the same logic to new connectors and MCP servers. A Friction Meter tracks how much the process slows builders down, and Microsoft treats it as a primary metric.
The numbers Microsoft reports for itself: active makers grew from about 2,000 to 20,000 a month, about 150,000 personal development environments are under governance, and maker friction, by Microsoft’s own measure, fell from roughly 50% to 5%.
Three design choices in that machinery are worth copying.
Sharing is a risk event. A personal agent becomes an enterprise agent the day it is shared with five thousand people, without a line of it changing. Microsoft limits sharing by purpose and scope and handles expansion through bounded requests that the CISO’s office can approve against measurable controls.
Tools are reviewed as their own objects. The Action-O-Meter reviews connectors and MCP servers, not only agents. For actions, the tool is often the right unit of risk, because many agents will reuse it.
Friction is measured next to compliance. The guide says it plainly: over-restriction pushes activity toward shadow AI and erodes visibility. A security dashboard that only counts blocks will optimize for blocking. Active makers and time to production belong on it too.
What depends on Microsoft’s setup
The bottom tier works because Agent Builder agents stay inside Microsoft 365 boundaries, with identity controls, permissions, data loss prevention, sensitivity labels and compliance protections already in place. Microsoft’s IT has spent years on those. A company with years of oversharing in SharePoint inherits that too: in the guide’s words, data readiness drives agent quality, and the same is true of agent risk. The lifecycle rule, a 60-day inactivity threshold that triggers alerts and automated cleanup, is easy to copy; the labeling underneath is not.
Microsoft’s guide also sits alongside this month’s Copilot Studio update, which brought apps, workflows and agents into one environment. As the middle tier gains capability, its review rules matter more.
What travels without Microsoft’s infrastructure is the order of operations: ask the four questions at intake, route review by risk color rather than by tool, treat sharing as a trigger for re-review, review connectors once for every agent that uses them, and measure friction alongside control.