Skip to content

Control 4.14: Copilot Studio Agent Lifecycle Governance

Control ID: 4.14 Pillar: Operations & Monitoring Regulatory Reference: FFIEC IT Handbook (Operations Booklet), FINRA Rule 3110 (supervisory systems and WSPs), OCC Bulletin 2023-17 (Third-Party Relationships: Risk Management), Sarbanes-Oxley §§302/404 (where applicable to ICFR), 12 CFR part 30, appendix D (OCC Heightened Standards) Last Verified: 2026-06-12 Governance Levels: Baseline / Recommended / Regulated


Scope boundary: FSI-CopilotGov vs FSI-AgentGov

This control governs the Microsoft 365 Copilot surface only — tenant-level configuration, data-source posture, audit/eDiscovery, and admin-managed extensibility. Governance of the agents themselves (Copilot Studio agents, declarative agents, Agent Builder, custom pro-code agents) — including agent registration, risk tiering, environment zoning, model-card review, and lifecycle promotion — lives in the companion FSI-AgentGov framework. See Relationship to FSI-AgentGov for the full boundary map.

Consume-and-cross-link control

The end-to-end Copilot Studio agent lifecycle — authoring, testing, publishing, versioning, deprecation, Power Platform solution ALM, environment variables, connection references, pipelines, and DLP — is built and governed in the Power Platform admin center and Copilot Studio, and is authoritative in FSI-AgentGov, not here. This control is intentionally thin: it covers only the Microsoft 365 Copilot consumption side — the firm's decision to permit or block published Copilot Studio agents that surface in the Copilot experience, and the operational visibility needed to make that decision. For the authoritative lifecycle controls, use:

Objective

Govern, from the Microsoft 365 Copilot side, the published Copilot Studio agents that surface in the Copilot experience: which externally or internally published agents are made available to Copilot users, who approved their availability, and whether they are inventoried for supervision and examination readiness. This control helps support FFIEC Operations Booklet change-management expectations, FINRA Rule 3110 supervisory systems and WSPs, OCC Bulletin 2023-17 third-party lifecycle expectations, Sarbanes-Oxley §§302/404 (where applicable to ICFR), and 12 CFR part 30, appendix D (OCC Heightened Standards).

The build/test/publish/ALM lifecycle of Copilot Studio agents — which occurs in the Power Platform admin center and Copilot Studio — is authoritative in FSI-AgentGov (see the callout above). This control adds the Copilot-surface availability decision and cross-references those controls rather than re-specifying them. It wraps adjacent Copilot-side controls:

  • Control 1.10 establishes the initial authoring approval gate before an agent is built.
  • Control 1.16 governs Copilot tuning (model fine-tuning), referenced — not duplicated — here.
  • Control 4.13 governs operational extensibility (connectors, plugins, Graph data sources) and the Copilot-side agent operational signals.

Why This Matters for FSI

Published Copilot Studio agents that surface in Copilot execute on behalf of users and can persist for months or years. From the Copilot side, the firm should know which published agents its users can reach, who approved that availability, and where the authoritative lifecycle evidence lives. This control helps cover:

  • FFIEC IT Handbook (Operations Booklet) — change and configuration management visibility for operational technology surfaced to users.
  • FINRA Rule 3110 (supervisory systems and WSPs) — supervisory oversight of tools that touch member-firm business activities.
  • OCC Bulletin 2023-17 — lifecycle expectations for third-party and internally configured tools that depend on third-party platforms.
  • Sarbanes-Oxley §§302/404 (where applicable to ICFR) — evidence where agents support financial reporting or related internal controls.
  • 12 CFR part 30, appendix D (OCC Heightened Standards) — governance-maturity expectations for material AI tooling.

No single control satisfies these obligations. Apply this control together with the authoritative FSI-AgentGov lifecycle controls.

Disclaimer

This control is provided for informational purposes only and does not constitute legal, regulatory, or compliance advice. See full disclaimer.

Control Description

Authoritative governance is in FSI-AgentGov. Authoring, testing, publishing, versioning, deprecation, Power Platform solution ALM, environment variables, connection references, deployment pipelines, and connector DLP are specified in FSI-AgentGov (Controls 2.1, 2.3, 2.5, 2.25). This control does not restate them. It governs the Copilot-surface availability decision and the cross-references that keep the two frameworks aligned.

Admin-Plane Attribution

Activity Owning admin plane Governed by
Authoring, testing, publishing, versioning, deprecation of Copilot Studio agents Copilot Studio FSI-AgentGov 2.3, 2.5
Solution transport, environment variables, connection references, pipelines, environment/connector DLP Power Platform admin center FSI-AgentGov 2.1, 2.3
Agent registry, ownership, and tenant-wide visibility M365 admin center (Agent registry) + Agent 365 FSI-AgentGov 2.25; surfacing decision here
Making a published agent available to / blocking it from Copilot users M365 admin center > Integrated apps / Agents This control (4.14)

Copilot-Side Scope (what this control governs)

  • Maintain Copilot-side visibility of which published Copilot Studio agents can surface for the firm's Copilot users, sourced from the M365 admin center Agent registry and Integrated apps.
  • Decide and record whether each published agent is made available to Copilot users; block by default and admit only approved, inventoried agents.
  • Cross-reference each available agent to its authoritative FSI-AgentGov lifecycle record (owner, version, test evidence, approval) rather than maintaining a parallel lifecycle inventory.

Researcher and Analyst Note

Researcher and Analyst are part of the core Copilot chat experience and are not managed as installable registry agents; usage oversight for them is addressed in Control 4.13 and FSI-AgentGov.

Copilot Surface Coverage

Surface Copilot-Side Governance Priority Notes
Microsoft 365 Copilot Chat Critical Common runtime surface for published Copilot Studio agents
Teams High Frequent embedding surface for published agents
Microsoft 365 Admin Center (Agent registry) High Source of Copilot-side availability and ownership visibility
Microsoft Purview Audit Medium Evidence for agent invocation surfaced in Copilot (Control 3.1)
Copilot Studio (authoring) Reference only Authoritative lifecycle surface — governed in FSI-AgentGov
Power Platform admin center Reference only Authoritative ALM/DLP surface — governed in FSI-AgentGov
Microsoft Scout (Frontier preview) — subagents Reference only Scout composes work through skills and delegated subagents on the endpoint, plus MCP servers. Subagent lifecycle for Scout is governed under Control 4.16 alongside Scout's extensibility posture in Control 4.13; it is distinct from Copilot Studio agent authoring/publishing/versioning covered here.

Governance Levels

Baseline

  • Maintain Copilot-side visibility of published Copilot Studio agents available to the firm's Copilot users, from the M365 admin center Agent registry and Integrated apps.
  • Block published agents from Copilot availability by default; admit only agents recorded in the firm's approved list.
  • Defer authoring, testing, publishing, versioning, and deprecation governance to FSI-AgentGov (Controls 2.1, 2.3, 2.5).
  • Require documented admin approval before a published agent is made available to Copilot users; block end-user self-installation.
  • Cross-reference each available agent to its FSI-AgentGov lifecycle record (owner, current version, test evidence, publish approver).
  • Integrate the Copilot-side availability decision into the firm's change-management process under Control 4.12.
  • Treat AI model selection for agents as a change event recorded in the FSI-AgentGov lifecycle record; before enabling a cross-geo model (including currently generally available Anthropic Claude and GPT-5 family models) in a production agent, complete a data-residency review under Control 2.7.

Regulated

  • Reconcile the Copilot-side approved list with FSI-AgentGov lifecycle and publishing-approval records quarterly; suspend Copilot availability of any agent whose lifecycle evidence has lapsed.
  • Confirm independent reviewer sign-off (recorded in FSI-AgentGov) exists for production publishes of agents made available to Copilot users.
  • Include the Copilot-side approved list and its cross-references to FSI-AgentGov evidence in examination packages aligned with SOX §§302/404 (where applicable to ICFR) and 12 CFR part 30, appendix D (OCC Heightened Standards).
  • Monitor for ownerless or unauthorized published agents surfacing in Copilot through the M365 Admin Center Agent registry; investigate exceptions weekly.

Setup & Configuration

Step 1: Identify Published Agents Reaching Copilot

Portal: Microsoft 365 admin center > Agents (Agent registry) and Microsoft 365 admin center > Integrated apps.

Export the published agents that can surface for Copilot users and record each in the Copilot-side approved list with owner, availability decision, and a reference to its FSI-AgentGov lifecycle record. Do not duplicate authoring/testing/version detail — reference the authoritative FSI-AgentGov record.

Step 2: Apply the Availability Decision

Block published agents from Copilot availability by default. Admit only agents in the approved list that have a current FSI-AgentGov lifecycle record. Require admin approval before availability; block end-user self-installation.

Step 3: Configure the Lifecycle in FSI-AgentGov

Use FSI-AgentGov Control 2.3 for solution-based ALM, versioning, and deprecation; FSI-AgentGov Control 2.5 for pre-publish testing; and FSI-AgentGov Control 2.1 for Power Platform environment and connector-DLP governance. Record the cross-reference so examiners can trace the Copilot-side availability decision to the authoritative lifecycle evidence.

Step 4: Audit and Supervision Coverage

Confirm agent invocation surfaced in Copilot is captured by the unified audit log (Control 3.1) and supervision tooling (Control 3.6), and forwarded to the SIEM (Control 4.11) where required.

Financial Sector Considerations

Broker-dealers: Treat published agents surfaced to registered representatives as a supervised technology surface under FINRA Rule 3110; point supervisors to the FSI-AgentGov lifecycle and publishing-approval evidence.

Banking institutions: Reflect Copilot-side availability decisions in enterprise technology change records consistent with FFIEC expectations; the underlying ALM evidence is retained in FSI-AgentGov.

SOX-reporting entities: Where an available agent supports finance, reporting, or control workflows, retain the Copilot-side availability decision and its cross-reference to FSI-AgentGov lifecycle evidence under Sarbanes-Oxley §§302/404 where applicable to ICFR.

Covered institutions under OCC Heightened Standards: Reflect material agent availability decisions in the firm's risk governance framework.

Verification Criteria

# Verification Step Expected Result Tier
1 Review the Copilot-side approved list of published agents Every published agent available to Copilot users is listed with owner and availability decision Baseline
2 Confirm default-block posture for Copilot availability Published agents are blocked by default; only approved-list agents are admitted Baseline
3 Confirm cross-reference to FSI-AgentGov Each available agent references a current FSI-AgentGov lifecycle record (Controls 2.1 / 2.3 / 2.5) Recommended
4 Confirm admin-approval gate Published agents require admin approval before Copilot availability; end-user self-install is blocked Recommended
5 Confirm change-management integration Availability decisions are recorded in the firm's change-management process (Control 4.12) Recommended
6 Confirm quarterly reconciliation (Regulated) The approved list is reconciled with FSI-AgentGov lifecycle/publishing records each quarter; lapsed evidence triggers Copilot suspension Regulated
7 Confirm independent reviewer linkage (Regulated) Production publishes of agents available to Copilot users have independent reviewer sign-off recorded in FSI-AgentGov Regulated
8 Review ownerless or unauthorized published agents Exceptions surfacing in the Agent registry are investigated per the defined cadence Regulated

Additional Resources


FSI Copilot Governance Framework v1.8.0 - July 2026