Practical insights

Agents can act. Within a clear boundary.

Once an agent sends messages or changes records, a correct answer is only part of quality. Equally important is whether it reliably refrains from an unauthorised action.

WERKVERSTAND / CONNECTING INTELLIGENCE

The essential answer

Constrain data sources, connections and actions in the environment. Binding decisions need a defined approval before the write step. A polite request in a prompt or a model-triggered clarification is not an equivalent technical control.

Data policies establish the technical boundary

Power Platform data policies classify connections into groups including business, non-business and blocked. Copilot Studio can restrict sources, tools, channels and further capabilities. Turn this into a traceable selection for each agent: which connection is required for which task? Broad approval for convenience makes later review harder and expands the potential scope of impact.

Place approval before the action

Microsoft documents human input as part of workflows. For model-driven computer use, it also warns that review requests are triggered probabilistically and are not a guaranteed fail-safe. For binding dispatch, we therefore recommend a deterministic sequence: present the finished draft, verify approval of that exact content, and only then permit the send step.

Example: prepare a contract change request

The agent records a request and drafts a proposal with the customer, requested change and affected documents. The responsible person sees that information together with the intended recipient. Rejection ends the dispatch path. Subsequent changes to the draft require another review. Missing approval or a timeout leaves the item open and visibly hands it to a person.

A refused action is part of acceptance

Test rejected approvals, revoked permissions, failed connections and repeated events using controlled data. Inspect the destination system to confirm that no unauthorised message or duplicate change occurred. An agent error is insufficient when an earlier step already had an effect. Partial failures need a defined recovery path that recognises completed steps.

Working template: an allowed-action register

Describe each action with a verb, destination system, permitted data scope, execution identity and required approval. “Use the CRM” is too broad. “Add a draft to an existing case without changing customer status” is verifiable. Also record how partial success is recognised and repetition prevented. Expand the operational action boundary only after a successful test.

  • Approval object: content, recipient and effect must be visible together.
  • Rejection: the workflow must not select an alternative dispatch route.

Document ownership, changes and shutdown

For every operational agent, record the business owner, technical operator, permitted actions and latest accepted version. Changes to connections or data policies trigger another review. A clear shutdown route and manual fallback keep the process workable. The System Check first prioritises a workflow whose value can be demonstrated with bounded autonomy.

Keep it verifiable

Primary sources

The next sensible step

Assess your agent controls

Eight steps from a general interest in AI to a clearer decision for your business.

Start AI System Check
FreeProvider-neutralNo credentials