All insights

Copilot Agents · 10 min read

How to launch your first AI agent

By James Wilkinson 6 October 2026

You don't need an IT department to launch your first AI agent safely. You need one well-chosen job, tidy sources, a one-page scope, a few simple checks and your Microsoft 365 admin, in that order.

TL;DR
  • Pick one routine job that always lands on the same person, from the "answer" list rather than the "needs a person's judgement" list.
  • Tidy the sources first. An agent answers from your documents with complete confidence, including the out-of-date ones.
  • Write a one-page scope. It becomes the agent's instructions, gives your DPIA a head start and is what the owner checks the agent against every week.
  • Start with an agent you talk to, built in Agent Builder, and test it on 20 real questions before anyone else uses it.
  • Go live small, with one named owner, ten minutes a week and a known way to switch it off.

You don’t need a big IT department or a compliance team to launch your first AI agent safely. You need one well-chosen job, tidy sources, a short written scope, a few simple checks and your Microsoft 365 admin for a handful of settings, done in that order.

This guide walks through each step as I’d run it with a firm building its first agent in Microsoft Copilot.

1. Pick one job

Start with the work, not the technology. Ask the partners to sort the firm’s routine jobs into three lists:

  • Answer: questions with a known answer in the firm’s own documents, such as “Which engagement letter do I use?” or “What’s our process for a new self assessment client?”
  • Draft: work where an agent can produce a first version for a person to check and send, such as a routine client reply built from approved wording.
  • Needs a person’s judgement: anything involving a client relationship, professional sign-off or a judgement call.

Your first agent comes from the first list. Pick one job that comes round every week and always lands on the same person, usually the practice manager or a senior. An agent that answers those questions takes the repeat questions off their desk, so they can spend that time on the work that needs them. It’s also easy to test, easy to explain to the team and easy to judge.

Resist building an agent that does everything. One job is the difference between an agent people trust and one they try once.

2. Tidy the sources first

An agent is only as good as the documents it answers from. If your procedures are out of date, duplicated or scattered across personal folders, the agent will give out-of-date, conflicting answers with complete confidence.

Before you build anything:

  • Put the documents the agent will use in one SharePoint folder or site, owned by one person.
  • Remove old versions, drafts and duplicates. If two documents disagree, the agent can’t tell which one is right.
  • Keep each document short and to the point. Microsoft’s own guidance is to keep the files you give Copilot concise.
  • If you’re using a spreadsheet, keep the data on one sheet. Microsoft notes that agents answer best from Excel data held in a single sheet.

Know the limits too. Agent Builder reads up to 100 SharePoint files per agent, and if your admin has turned on Restricted SharePoint Search, it can’t use SharePoint at all. For the wider clean-up, see preparing your files, permissions and knowledge base.

Then decide what the agent should say when the answer isn’t there. A good first agent says “I can’t find that in our procedures, please ask the practice manager” rather than guessing. Agent Builder has a setting called Only use specified sources that makes the agent prioritise your documents and fall back to a message saying it can’t find the information. It prioritises your sources rather than fully blocking general knowledge, so write the same rule into the agent’s instructions as well. If you need stricter control, that’s a reason to build in Copilot Studio instead.

3. Write a one-page scope

Before anyone opens Copilot, write down what the agent is for. One page is enough, and if it won’t fit on one page, the agent is trying to do too much. Cover:

  • The job: one sentence on what it does.
  • What it doesn’t do: the questions it should send back to a person.
  • Who uses it: a team, a service line or the whole firm.
  • Its sources: the folder or site it answers from, and who keeps those documents up to date.
  • When it’s unsure: the exact wording it should use and who it should point people to.
  • The owner: one named person, usually a partner or the practice manager.
  • How you’ll judge it: what “working” looks like after a month.

This page does three jobs. It becomes the agent’s instructions, it gives your DPIA a head start and it’s what the owner checks the agent against every week.

4. Choose the kind of agent

There are two kinds of agent, and the difference matters more than any feature list.

  • An agent you talk to answers when someone asks it a question. It waits in Copilot or Teams until someone needs it.
  • An agent that runs starts on its own when something happens, such as an email arriving or a document being saved. It does its work in the background, usually with a person approving the result.

For most firms, the first agent should be one you talk to. It’s simpler to build and test, and nothing happens unless someone asks.

In Microsoft Copilot, there are two places to build:

Agent BuilderCopilot Studio
Where it isInside Microsoft 365 CopilotA separate web portal
Best forQuestion-and-answer agents for a person or small teamAgents for a whole department or firm, multi-step workflows and agents that start on their own
Control over sourcesPrioritises your sourcesStricter control over what it answers from
MonitoringMonitor tab: usage, sources used, ratings and commentsDetailed analytics, plus conversation transcripts with some limits

Adapted from Microsoft’s comparison of Agent Builder and Copilot Studio and related Microsoft Learn pages. For the full picture, see Agent Builder vs Copilot Studio.

Agent Builder is a good place to prove the idea. If the agent proves itself and needs to reach the whole firm, Microsoft lets you copy it into Copilot Studio rather than starting again. Linked SharePoint sources and instructions come across, but uploaded files have to be added again.

What each person can use depends on your licences. Agents that answer from your SharePoint files or uploaded documents need either a Microsoft 365 Copilot licence or usage billing set up by your admin for the people using them, so check this before you promise the agent to the whole team.

5. Give it only the data it needs

An agent that answers questions about engagement letters doesn’t need to see payroll, client files or partner drawings. Point it at the one folder or site in its scope and nothing else.

The good news is that agents you talk to answer from your documents using the permissions of the person asking. Microsoft describes this as “no new privileges”: if someone can’t open a document in SharePoint, the agent won’t show them what’s in it. Copilot Studio works the same way for SharePoint knowledge.

That cuts both ways. If your SharePoint permissions are looser than you think, the agent will surface whatever people can already reach. So before launch, check who can see the folder the agent uses.

Three traps catch firms out:

  • Files uploaded straight into the agent. In Agent Builder you can upload files from your computer rather than link to SharePoint. Microsoft warns that anyone who can use the agent can get answers from those files, whatever their normal access. Keep anything sensitive in SharePoint and link to it.
  • Agents that run on their own. These don’t have a person asking, so in Copilot Studio they run on the connections the builder signed in with. Microsoft notes this can let users reach data through the agent that they couldn’t reach themselves. If you get to this stage, build them under an account that can only reach what the agent needs, not a partner’s or an admin’s login.
  • Sharing that widens file access. When you share an Agent Builder agent, it can share its SharePoint files with the same people. Removing them from the agent later doesn’t take that file access away, so check the folder permissions after sharing, not just before.

More on this in are Copilot agents secure, and where does your data go.

6. Test it on questions you already know the answers to

Before anyone else uses the agent, ask the person who currently answers these questions to write down 20 real ones, with the correct answer for each. Use questions people actually ask, worded the way they actually ask them. Then add three more types:

  • Questions outside its scope. It should decline and point to a person, not have a go.
  • Questions with no answer in the documents. It should say it can’t find the answer, not invent one.
  • The same questions from a junior’s account. This checks it doesn’t show anyone something they shouldn’t see.

In Agent Builder, run the list on the Try it tab before you share the agent. Then share it with one junior colleague and have them ask the same questions, because Try it runs as you. Agents built on Copilot Studio’s standard experience have an evaluation feature where you save test questions with expected answers, choose which user to test as and rerun them. The newer experience has an evaluation tab too, but it’s in preview and doesn’t yet check against your expected answers. There’s more in how do you know your agent still works.

Keep the list. Every time someone changes the agent’s instructions or sources, run it again before the change goes live. Rerunning the same twenty questions is quick, and it catches problems before your team does.

7. Go live small, with an owner and a weekly check

Share the agent with a small group first, ideally the people who ask these questions most. Give them a month before you roll it out to everyone.

One named owner. One person, not a working group. They own the sources, the instructions and the test questions, and everyone knows to tell them when an answer looks wrong. Every agent needs an owner for exactly this reason.

Ten minutes a week. The owner looks at what the agent has been asked and how people rated the answers. What they can see depends on where it was built:

  • In Agent Builder, the Monitor tab shows how many people use the agent and which sources it draws on. It also shows the thumbs up or down and comments people leave, once your admin turns on agent feedback sharing. It doesn’t show the conversations themselves, so ask the pilot group to rate answers and send the owner anything odd.
  • In Copilot Studio, owners of a custom agent can view and download transcripts from the last 28 days, if your admin allows it and gives them the transcript viewer role. There’s a catch: when the agent answers from SharePoint, the transcript shows the question and the documents it used but hides the answer itself. So ask for ratings here too.

A way to switch it off. Know before launch how you’d stop it. In Agent Builder, an owner can remove people from the Share screen and the change is immediate. If org-wide sharing is on, turn that off too. Your Microsoft 365 admin can also disable, block or remove agents from the admin centre. For a Copilot Studio agent, the controls sit in the Power Platform admin centre. Write down who does it and how, and keep it with the one-page scope.

The paperwork you still need

None of the steps above replace your data protection duties. Three things still need doing.

A DPIA. The ICO’s view is that in the vast majority of cases, using AI will need a data protection impact assessment, and that if you decide yours doesn’t, you should record how you reached that decision. An agent that only answers questions from internal procedures handles far less personal data than one reading client files, and if it genuinely touches no personal data the legal duty may not apply. Doing the assessment anyway is still good practice. Your one-page scope gives you a head start, because a DPIA starts by describing what the processing is for and what data it uses. The ICO notes this guidance is under review following the Data (Use and Access) Act, so check the latest version when you write yours.

An AI policy. A short document setting out which AI tools staff can use, what they must never put into them and who approves a new agent. It doesn’t need to be long, but it does need to exist before the second agent appears.

Training for the team. People need to know what the agent is for, what it won’t do and who to tell when it gets something wrong. Ten minutes at a team meeting is often enough for a first agent.

This is practical guidance, not legal advice. If your agent will handle client personal data, take advice from your data protection lead before you go live.

Where to start

If you’d like to build your first agent with your own team, around one of your own processes, the Building Your First Copilot Agent session takes you from the three lists to a tested agent in one sitting.

Or book a free 30-minute call, and I’ll work out which job your first agent should take on.

Related reading

More on Copilot Agents

Copilot Agents Copilot skills explained: Agent Builder, Copilot Studio and Cowork compared A skill teaches a Copilot agent one job, done your firm's way. What skills are in Agent Builder, Copilot Studio and Cowork, how to package one and when they save Copilot Credits. Copilot Agents What happens after the agent is built? Why every agent needs an owner An agent is a running service, not a finished project. What changes after go-live, the five-point minimum a firm with no IT team can run and who owns it. Copilot Agents Are Copilot agents secure? Where your data goes The long answer on Copilot agent security: where answers come from, what stays inside the Microsoft 365 service boundary and what your admins control. Copilot Agents Copilot Agent Builder vs Copilot Studio: which do you need? The plain-English difference between the agent builder in Copilot Chat and Copilot Studio, and the one question that decides between them. Copilot Agents What is a Copilot agent? A plain-English definition A plain-English definition of Microsoft Copilot agents: what they are made of, the jobs they do well, where they run and how firms go from one agent to a team. Copilot Readiness SharePoint Copilot readiness: preparing your files, permissions and knowledge base SharePoint Copilot readiness is the foundation of safer AI. Fix permissions, content ownership and duplicates in the areas where Copilot will matter most. Copilot Agents How do you know your agent still works? Agents fail quietly. Copilot Studio's evaluation tools let you test an agent against a saved question set before and after every change. Most firms have never opened the tab. Course Copilot agents course A short course for anyone in your firm with a Copilot licence: each person builds their own agent for one of their jobs, and in the three-hour version adds a skill to it. Next step Book a free 30-minute call A free 30-minute call about the work an agent could take off your team, and whether Discover is the right next step.

Common questions

Questions about launching your first AI agent

What should my first AI agent do?
One routine job that comes round every week and always lands on the same person, usually the practice manager or a senior. An agent that answers questions from your firm's own documents is the easiest to test, explain and judge. Anything involving a client relationship, professional sign-off or a judgement call should stay with a person.
Should I build my first agent in Agent Builder or Copilot Studio?
For most firms, Agent Builder. It sits inside Microsoft 365 Copilot and suits question-and-answer agents for a person or small team. Copilot Studio is for agents that serve a whole department or firm, multi-step workflows, agents that start on their own and stricter control over sources. If an Agent Builder agent proves itself, you can copy it into Copilot Studio rather than starting again.
Can an agent show people files they couldn't open themselves?
Not when you talk to it. Agents you talk to answer from your documents using the permissions of the person asking. The exceptions are files uploaded straight into Agent Builder, agents that run on their own using the builder's connections, and sharing that widens file access. Check the folder permissions before and after you share.
How do I test an AI agent before sharing it?
Ask the person who currently answers the questions to write down 20 real ones with the correct answers. Add questions outside its scope, questions with no answer in the documents and the same questions from a junior's account. Run the list on the Try it tab, then have a junior colleague ask the same questions, because Try it runs as you.
Do I need a DPIA for an AI agent?
The ICO's view is that in the vast majority of cases using AI will need a data protection impact assessment, and that if you decide yours doesn't, you should record how you reached that decision. An agent that answers only from internal procedures handles far less personal data than one reading client files, but doing the assessment is still good practice.