One business task instead of an all-knowing bot
A suitable first knowledge agent might answer questions about a defined product portfolio. It has approved service descriptions and a route for unanswered questions. Also specify what it does not answer: individual legal assessments, unapproved discounts or sensitive personnel matters. That boundary belongs in test cases and source organisation, not just in the greeting.
Review source connection and authentication together
The documented SharePoint knowledge integration respects the requesting user’s permissions. Authentication and the chosen connection type are therefore part of the architecture. Protected or encrypted documents can have additional limits. Check the actual SharePoint option used by the agent and test under an ordinary user account. A successful test as the maker is not a substitute.
Example: internal answers about service scope
An employee asks whether a support issue belongs to the standard package. The agent searches the current service description, states the relevant boundary and links its source. Without the specific contract, it must not infer a customer-specific commitment. Instead, it identifies the document the responsible person still needs to review. This keeps the answer useful without inventing decisions.
Reading and acting require different permissions
For tools, Copilot Studio distinguishes maker authentication from user authentication. If the agent later creates a ticket or updates a record, that choice must be reviewed again. We recommend a read-only scope for the initial knowledge pilot. Each added write action needs its own test, clear ownership and, where appropriate, technically enforced approval.
Working template: six questions for the first test
Start with six deliberately different cases: a clear standard question, a question requiring two sources, outdated information, unknown information, access to a restricted area and a request outside the agent’s responsibility. The business team defines the expected boundary beforehand. A good standard answer cannot compensate for a failure involving protected information. Add new cases from actual questions observed later.
- Source: the answer must use the authoritative version.
- Escalation: an unresolved item identifies the appropriate manual route.
Evaluate more than the easy questions
Microsoft provides repeatable agent evaluations, but they do not replace security review. Include correct answers, missing sources, conflicting versions and unauthorised access in your test set. Assess every decisive statement against a business-approved expectation. Repeat the same tests after source changes. The System Check assesses whether a knowledge agent is the right starting point or whether better filing would already suffice.
Keep it verifiable
Primary sources
- Microsoft: SharePoint knowledge in Copilot StudioSource checked:
- Microsoft: User authentication for agent toolsSource checked:
- Microsoft: About agent evaluationSource checked:



