All insights

Copilot Agents · 6 min read

Copilot Studio hooks: how to make your AI agent follow the rules every time

By James Wilkinson 30 September 2026

Hooks let a Copilot Studio agent run a check, a log or a lookup every time something happens, whether the agent thinks it matters or not. What they do and the catch to know first.

TL;DR
  • A hook attaches a workflow to a moment in your agent's life, such as a message arriving or a tool about to run. The workflow runs every time that moment happens, whether the agent thinks it matters or not.
  • A tool is a suggestion the agent can take or leave. A hook is a rule. Use hooks for audit logs, policy checks before a sensitive action and giving the agent the right background from the start.
  • The catch: if the workflow behind a hook fails, the agent carries on as if the hook returned nothing. Keep the agent's permissions tight and monitor the workflow, so a broken hook cannot quietly let everything through.

Most AI agents follow your rules when they decide to. Copilot Studio hooks change that: they let you run a check, a log or a lookup every single time something happens, whether the agent thinks it matters or not.

That difference sounds small. For an accountancy practice, a law firm or anyone handling client data, it is the gap between an agent you can trial and one you can trust with real work.

Hooks are a new preview feature in Copilot Studio. Here is what they are, what they are good for and the one catch every firm needs to understand before relying on them.

What a hook is

A hook is a rule attached to a moment in your agent’s life. When that moment arrives, the hook runs a workflow automatically.

It has two parts:

  • The moment (the event). For example, a conversation starting, a user sending a message, the agent about to use a tool, a tool finishing or something going wrong.
  • What happens (the action). A workflow you have built, such as a check, a lookup or a log entry.

The workflow receives details about what just happened, including who the user is and which channel they are on. Its response then feeds back into the conversation and can change what the agent does next.

Why this is different from giving the agent a tool

Copilot Studio agents already use tools, and a tool can run exactly the same workflow as a hook. The difference is who decides when it runs.

ToolHook
What triggers itThe agent chooses to use itThe event happens
How often it runsOnly when the agent judges it relevantEvery time
What its answer doesGives the agent information it may useChanges what the agent does next

A tool is a suggestion the agent can take or leave. A hook is a rule. If you need something to happen consistently, such as logging every action or checking every request against a policy, you want a hook.

Four ways a firm could use hooks

1. Keep an audit trail of everything the agent does

A hook that runs after every tool call can write a record to a SharePoint list: which user, which agent, what it did and what came back. For a regulated firm this is the difference between “we think the agent behaves” and “here is the log”. It can also strip sensitive values out of a result before the agent sees them.

2. Stop the agent doing something it shouldn’t

A hook that runs just before a tool is used can look at what the agent is about to do and block it. For example, you could stop an agent emailing anyone outside the firm’s domain, or refuse to update a client record unless the user belongs to the right team. This is the only type of hook that can actually say no.

3. Give the agent the right background from the start

A hook that runs when a conversation begins can look up the user’s team, office or current clients and hand that to the agent before the first message. The agent starts every conversation already knowing who it is talking to, rather than having to ask.

4. Handle failures calmly

When something breaks, a hook can tell the agent whether to retry, skip or stop, and control the message the user sees. That means a plain “the practice system is unavailable, try again shortly” instead of a confusing error.

You can apply a hook to every tool or just to one sensitive one. A sensible setup is one hook logging everything, plus a stricter check on the single tool that touches client data.

The catch: if a hook fails, the agent carries on

This is the part most write-ups will skip, and it matters more than anything else here.

If the workflow behind a hook fails, times out or sends back something the agent can’t read, the agent does not stop. It carries on as if the hook had returned nothing. Microsoft says so plainly in its own documentation and advises against relying on a hook as your only safeguard for a business-critical rule.

In practice that means a blocking hook protects you when it works, but a broken one quietly lets everything through. So:

  • Don’t treat a hook as the only thing standing between the agent and a serious mistake.
  • Keep the agent’s own permissions tight, so the worst it can do is limited even if a hook fails.
  • Monitor your hook workflows, so you find out when one stops running rather than discovering it months later.

Other things to know before you rely on them

  • It’s a preview. Features and behaviour may change before general release, so avoid building anything critical around the exact details yet.
  • It only works on certain agents. Hooks apply to agents running on the newer GitHub Copilot harness in Copilot Studio, not every agent you may already have. What the harness changes and what it costs and which harness your agent should be built on cover the choice.
  • There is a cost. Using, building and testing these agents can use Copilot Credits, so a hook that runs on every tool call adds to your usage. Worth modelling before you switch one on across the board. Copilot Credits explained shows what each workload costs.
  • Changes need saving and publishing. A hook isn’t live for your users until the agent is saved and published, and the workflow behind it must be published too.
  • One workflow, many hooks. A hook points to a workflow rather than copying it, so editing that workflow changes every hook that uses it. Handy for consistency, risky if someone edits it without realising.
  • Treat what comes in as untrusted. User messages, tool results and error text can contain anything. Your workflow should check them before acting on them.

Where hooks fit in keeping an agent under control

Hooks are a strong new layer, not a replacement for the basics. For any firm putting its first agent live, we still recommend a simple foundation underneath:

  1. One named owner. A person, not a committee, who is responsible for the agent. Why every agent needs an owner explains the role.
  2. A one-page scope. What the agent does and, just as importantly, what it doesn’t.
  3. Least-privilege access. The agent can only reach the data it genuinely needs.
  4. Transcripts on, reviewed weekly. Ten minutes a week reading what it actually said.
  5. A kill switch and a test set. A way to turn it off quickly, and a set of known questions to test before any change goes live.

Hooks then sit on top of that: the audit log proves what happened, the blocking check catches the obvious mistakes and the start-of-conversation context makes the agent more useful. Together, that is an agent a partner can sign off with confidence. Three questions to ask of any agent and using Copilot with client data cover the wider governance picture.

The short version

Hooks let you make a Copilot Studio agent follow your rules every time, not just when it feels like it. They are ideal for audit trails, policy checks and giving the agent the right context from the start. Just remember they fail open, so pair them with tight permissions and proper oversight. Pairing hooks with skills and tests on your own live agents is the kind of work the Advanced Copilot Studio day is for.

Sources checked

Last checked: 30 September 2026.

  • Microsoft Learn, “Hooks (preview) in Copilot Studio”, prerelease documentation, accessed 30 September 2026.

If you’re thinking about agents for your firm and want to know how to keep them under control, book a free 30-minute call. No pitch, just a straight conversation about what would work for you.

Related reading

More on Copilot Agents

Copilot Agents How do you know your agent still works? Agents fail quietly. Copilot Studio's evaluation tools let you test an agent against a saved question set before and after every change. Most firms have never opened the tab. Copilot Agents Microsoft's Agent Governance Toolkit: three questions to ask of any agent Microsoft's open-source Agent Governance Toolkit enforces agent rules in code, not prompts. Why that matters for firms that will never install it. Copilot Agents Copilot skills explained: Agent Builder, Copilot Studio and Cowork compared A skill teaches a Copilot agent one job, done your firm's way. What skills are in Agent Builder, Copilot Studio and Cowork, how to package one and when they save Copilot Credits. Copilot Agents What happens after the agent is built? Why every agent needs an owner An agent is a running service, not a finished project. What changes after go-live, the five-point minimum a firm with no IT team can run and who owns it. Automation Copilot Studio's new engine: what the GitHub Copilot harness changes and what it costs Copilot Studio's default is now the GitHub Copilot harness, the engine behind Copilot Cowork. What changes, what the credits cover and the checks before you build. Automation Which Copilot Studio harness should your agent be built on? An agent harness explained in plain English, why the GitHub Copilot harness costs more and how to decide which harness each agent build belongs on. Copilot Licensing Copilot Credits explained: what each Microsoft workload costs in October 2026 Copilot Credits in one page, from Microsoft's October 2026 guide. How to buy them, what Cowork, Code, SharePoint, Copilot Studio, Teams Phone Agent, apps, Work IQ and Dynamics draw and what the licence covers. Copilot Governance Can you use Microsoft Copilot with client data? A practical governance guide Can you use Microsoft Copilot with client data? Yes, but only inside clear governance, approved tools and a review process built around risk levels. Service area Enable Copilot Studio workshops for the people who'll build. Next step Book a free 30-minute call A free 30-minute call about the work an agent could take off your team, and whether Discover is the right next step.

Common questions

Questions about Copilot Studio hooks

What is a hook in Copilot Studio?
A rule attached to a moment in your agent's life, such as a conversation starting, a message arriving, a tool about to run, a tool finishing or an error. When that moment arrives, the hook runs a workflow you have built and its response can change what the agent does next.
What is the difference between a hook and a tool?
Who decides when it runs. The agent chooses whether to use a tool, so it runs only when the agent judges it relevant. A hook runs every time its event happens, and its answer changes what the agent does next.
Can a hook stop an agent doing something?
Yes, but only the type that runs just before a tool is used. It can look at what the agent is about to do and block it, for example emailing anyone outside the firm's domain.
What happens if a hook fails?
The agent carries on as if the hook had returned nothing. Microsoft says so in its documentation and advises against relying on a hook as the only safeguard for a business-critical rule.
Are hooks available now?
They are a preview feature, so behaviour may change before general release. They apply to agents running on the newer GitHub Copilot harness in Copilot Studio, not every existing agent.