All insights

Copilot Agents · 5 min read

Copilot Studio workflows explained: what does what, and where the partner signs off

By James Wilkinson 4 October 2026

In the new Copilot Studio, the agent does the thinking and a workflow makes sure the right person signs off. Get that split right and most of the confusion about the new building blocks goes away.

TL;DR
  • The agent makes the judgement calls, a skill holds your firm's way of doing a task, a tool does one action in one system and a workflow runs the steps that must happen the same way every time.
  • Partner sign-off belongs in a workflow, not in the agent's instructions. A workflow step is a gate; an instruction is guidance the agent interprets.
  • A workflow's route is fixed but any AI step inside it can still word things differently each run, so put AI steps before the human check, never after it.
  • Every workflow action draws on capacity or Copilot Credits, so a workflow should earn its length.

Microsoft has added a new way to build agents in Copilot Studio, running on what it calls the GitHub Copilot harness. It comes with four building blocks you will hear about from anyone building agents: agents, skills, tools and workflows. This guide explains each one in plain English, using a job every firm knows: getting an engagement letter from request to partner sign-off.

Checked against Microsoft’s documentation on 4 October 2026. This area changes often, so check the date before relying on the detail.

Four building blocks, one engagement letter

Each building block does one kind of work. Picture a manager asking for an engagement letter for a new limited company client, and follow it through.

The agent makes the judgement calls. It reads the request, works out which services are involved and spots what is missing, such as the year end or whether payroll is in scope. Then it asks the manager rather than guessing. Microsoft describes an agent as something that reasons through a request and decides the best next step.

A skill holds your firm’s way of doing it. How you scope a letter, which schedules go with which services, the wording your risk partner insists on. A skill is written once as a set of instructions, with templates or reference documents attached if needed. Any agent that drafts letters can reuse it, and the agent picks it up when a request matches.

Tools do single actions in your systems. Look up the client record, open last year’s letter in SharePoint, save the new draft. Each tool is one capability, usually a connector to a system you already use.

A workflow runs the steps that must happen the same way every time. Send the draft to the responsible partner, wait for approve or reject, file the approved letter and tell the manager. A workflow can be started by an agent, on a schedule, by an event or by hand.

One point that trips people up: a workflow is added to an agent as a tool. That is why the two terms blur. The difference is size. A tool is one action; a workflow is a chain of them, with rules about the order.

The agent prepares the letter, the workflow makes sure the partner signs off A manager asks for a letter and the agent drafts it, using a skill for the firm's way of working and tools for the client record and files. The draft then enters a workflow: it is sent to the partner, who approves or rejects. If the partner rejects it, the letter goes back to the agent with the partner's comment. If the partner approves it, the letter is filed and the manager is told. Workflow: the same steps every time Manager asks for a letter Agent drafts the letter Send draft to the partner Partner approves? File the letter and tell the manager Skill your firm's way Tools client record, files no yes back to the agent with the partner's comment uses
Engagement letter from request to partner sign-off

The partner’s decision is the gate: nothing is filed until they approve, and a rejection goes back to the agent with their comment.

Why sign-off belongs in a workflow, not the agent’s instructions

You can write “always get partner approval before sending” into an agent’s instructions, and the agent will usually follow it. Usually isn’t good enough for an engagement letter.

Instructions are guidance the agent interprets each time it runs. A workflow step is a gate. The letter can’t move on until the partner has responded, and their answer decides what happens next.

Workflows include human-in-the-loop steps that pause the process, send the reviewer a request (by email in Outlook, for example) and carry on once they respond. Ask for a comment as well as a yes or no. Then add a step that saves the decision and the comment to the client file, so you can show who approved what and when.

A good rule of thumb: the agent drafts, a person approves.

”Deterministic” needs a footnote

The route through a workflow is fixed, but the words an AI step writes inside it are not.

Microsoft describes workflows as deterministic, meaning the same input produces the same output. That holds for the route: the steps run in the order you set and none get skipped. But workflows can also contain AI steps, such as running a prompt or calling an agent, and those can word things differently from one run to the next.

The practical rule: put AI steps before the human check, never after it. Anything an AI step writes should pass a person before it reaches a client.

What about agent flows and Power Automate?

Neither is going away, and anything that already works doesn’t need rebuilding.

Agent flows are still what Microsoft calls the established flow format in Copilot Studio, and they can include human review steps too. They run on the standard harness, which Microsoft positions for rule-based agents and predictable, repeatable work. Workflows are the automation side of the newer GitHub Copilot harness, built for longer processes that need reasoning across several tools and files.

So the choice is less “old or new” and more “what does this job need”. A well-defined, rule-based process suits the standard harness. A process that needs judgement along the way suits the GitHub Copilot harness. Power Automate is still there for automation that doesn’t involve an agent at all. Our guide to which harness your agent should be built on goes through that choice in more detail.

And no, your data isn’t going to GitHub. Despite the name, Microsoft states the GitHub Copilot harness is not the GitHub Copilot service. Customer data isn’t sent to or processed by that service, and Copilot Studio’s existing privacy, security, compliance and data residency commitments still apply.

What it costs to run

Every step costs something, so a workflow should earn its length.

Workflows draw on your Copilot Studio capacity for each action they run. A ten-step workflow costs more per run than a single tool call, so don’t build a workflow where one action would do.

If your environment’s prepaid capacity runs out, new workflow runs are blocked until more is available. Runs already under way finish, but nothing new starts. Pay-as-you-go billing avoids that stoppage, at a price.

Agents and workflows on the GitHub Copilot harness use Copilot Credits, and Microsoft notes that building and testing can consume credits too, not just live use.

Before approving a project, ask whoever is building it for an estimate of runs per month and what each run uses.

A quick way to decide

Ask one question of each part of the process, and the answer tells you which building block it needs.

AskUseIn the engagement letter
Does this need a judgement call?AgentWorking out which services apply and what’s missing
Is this how our firm does a particular task?SkillYour scoping rules, schedules and standard wording
Is it one action in one system?ToolOpening last year’s letter in SharePoint
Is it several steps that must happen in order, or a sign-off?WorkflowPartner approval, then filing and notifying the manager

Where to start

Most firms don’t need all four building blocks on day one. Pick one process where the sign-off matters, map who decides what, then build the smallest thing that does the job.

If you’d like a hand working out where the agent stops and the partner starts in your own processes, book a free 30-minute call. No pitch, no obligation.

Sources checked

Last checked: 4 October 2026.

Related reading

More on Copilot Agents

Copilot Agents How do you know your agent still works? Agents fail quietly. Copilot Studio's evaluation tools let you test an agent against a saved question set before and after every change. Most firms have never opened the tab. Copilot Agents Copilot skills explained: Agent Builder, Copilot Studio and Cowork compared A skill teaches a Copilot agent one job, done your firm's way. What skills are in Agent Builder, Copilot Studio and Cowork, how to package one and when they save Copilot Credits. Copilot Agents Copilot Studio hooks: how to make your AI agent follow the rules every time Hooks let a Copilot Studio agent run a check, a log or a lookup every time something happens, whether the agent thinks it matters or not. What they do and the catch to know first. Agents Microsoft Copilot agents Plain-English guidance on where Microsoft Copilot agents fit, how to govern them and when to build. Automation Which Copilot Studio harness should your agent be built on? An agent harness explained in plain English, why the GitHub Copilot harness costs more and how to decide which harness each agent build belongs on. Automation Copilot Studio's new engine: what the GitHub Copilot harness changes and what it costs Copilot Studio's default is now the GitHub Copilot harness, the engine behind Copilot Cowork. What changes, what the credits cover and the checks before you build. Next step Book a free 30-minute call A free 30-minute call about the work an agent could take off your team, and whether Discover is the right next step.

Common questions

Questions about Copilot Studio workflows

What is a workflow in Copilot Studio?
A chain of steps that run in a set order, such as sending a draft to a partner, waiting for approve or reject, filing the approved letter and telling the manager. It can be started by an agent, on a schedule, by an event or by hand, and it is added to an agent as a tool.
What is the difference between a tool and a workflow?
Size. A tool is one action, usually a connector to a system you already use. A workflow is a chain of actions with rules about the order they run in.
Should partner approval go in the agent's instructions?
No. An agent will usually follow an instruction to get approval, but usually is not good enough for something like an engagement letter. A workflow's human-in-the-loop step pauses the process until the reviewer responds, and their answer decides what happens next.
Are workflows really deterministic?
The route is. The steps run in the order you set and none get skipped. But a workflow can contain AI steps, such as running a prompt or calling an agent, and the words those produce can differ from one run to the next. Put AI steps before the human check so a person sees anything an AI step writes before it reaches a client.
Do agent flows and Power Automate still matter?
Yes, and anything that already works does not need rebuilding. Agent flows run on the standard harness, which suits rule-based and repeatable work. Workflows belong to the newer GitHub Copilot harness, built for longer processes that need reasoning across several tools and files. Power Automate is still there for automation that does not involve an agent at all.
Does my data go to GitHub if I use the GitHub Copilot harness?
No. Microsoft states that the GitHub Copilot harness is not the GitHub Copilot service. Customer data is not sent to or processed by that service, and Copilot Studio's existing privacy, security, compliance and data residency commitments still apply.