Control 4.15: Copilot Cowork Governance
Control ID: 4.15 Pillar: Operations & Monitoring Regulatory Reference: FFIEC IT Examination Handbook, GLBA §501(b), Sarbanes-Oxley §§302/404, OCC Heightened Standards (12 CFR part 30, appendix D), FINRA Rule 3110 Last Verified: 2026-07-10 Governance Levels: Baseline / Recommended / Regulated
Scope boundary: FSI-CopilotGov vs FSI-AgentGov
This control governs the Microsoft 365 Copilot surface only — tenant-level configuration, data-source posture, audit/eDiscovery, and admin-managed extensibility. Governance of the agents themselves (Copilot Studio agents, declarative agents, Agent Builder, custom pro-code agents) — including agent registration, risk tiering, environment zoning, model-card review, and lifecycle promotion — lives in the companion FSI-AgentGov framework. See Relationship to FSI-AgentGov for the full boundary map.
Objective
Establish governance over Microsoft 365 Copilot Cowork — an agentic Copilot experience that performs multi-step work on a user's behalf — as it moves from preview into general availability. This control helps organizations govern access (via usage-based billing and discovery), model selection, local browser use, plugin and skill extensibility, consumption limits, supervision, and evidence collection so adoption proceeds under documented governance rather than default tenant exposure.
Why This Matters for FSI
Microsoft 365 Copilot Cowork reached general availability in June 2026 for Microsoft 365 Copilot tenants (worldwide, in tier-1 languages). Cowork is not enabled for users automatically at GA: access is gated by usage-based billing (Copilot Credits), and a separate discovery setting controls whether users see Cowork listed in Microsoft 365 Copilot. If Cowork is made discoverable but usage-based billing is not configured for a user, that user can submit an access request that an administrator reviews and approves. Some Cowork capabilities — notably the local browser use experience — remain preview features even after Cowork itself reached GA.
For a regulated financial institution, an agentic capability that can perform multi-step retrieval, generation, browsing, and image creation across a user's accessible content introduces supervision, operational-risk, cost-management, and books-and-records considerations that should be assessed before broad adoption. The FFIEC IT Examination Handbook emphasizes change control, vendor and third-party risk management, and ongoing monitoring for enterprise technology; those expectations apply to introducing a new AI experience with consumption-based cost exposure and third-party model providers. FINRA Rule 3110 expects firms to maintain supervisory systems and written supervisory procedures reasonably designed to achieve compliance; agentic outputs that influence client-facing work or recordkeeping may fall within that supervisory scope. Sarbanes-Oxley §§302/404 expectations apply where Cowork is used in finance, reporting, or control-support workflows, and the OCC Heightened Standards (12 CFR part 30, appendix D) reinforce board-level risk governance for covered institutions. GLBA §501(b) safeguarding expectations remain relevant because Cowork operates over content the user can already access, so existing oversharing and least-privilege weaknesses can be amplified by automated, multi-step retrieval and browser actions.
No single control satisfies these obligations on its own. This control is intended to be applied alongside readiness, data-protection, extensibility, and supervision controls rather than as a standalone assurance. Organizations should verify that their own legal, compliance, and risk functions have reviewed Cowork — including its third-party model providers and any models that require provider data retention — before enabling it for regulated populations.
Disclaimer
This control is provided for informational purposes only and does not constitute legal, regulatory, or compliance advice. See full disclaimer.
GA feature with preview components
Microsoft 365 Copilot Cowork is generally available as of June 2026. Certain sub-features remain in preview at the time of last verification, including local browser use and the Claude Fable 5 (Preview) model. FSI organizations should treat these sub-features as preview software, keep them disabled until reviewed, and re-verify configuration guidance against current Microsoft documentation before relying on it in production governance.
Control Description
Cowork governance at GA centers on access gating (billing + discovery), model policy, browser-use policy, extensibility (plugins and custom skills via the Customize page), consumption oversight, and Purview integration. The primary governance surfaces are:
| Governance Surface | Primary Path | Governance Use |
|---|---|---|
| Access gate — usage-based billing | M365 Admin Center > Copilot > Cost management | Enables Cowork access for specified users/groups and configures spending policies; Cowork access is gated on this setup |
| Discovery setting | M365 Admin Center > Copilot > Settings > AI experiences enabled by usage-based billing | Controls whether users can discover Cowork (and other usage-based experiences); can be enabled independently of billing to allow access requests |
| Access request review | M365 Admin Center (admin notification workflow) | If discovery is on but billing is not set up for a user, the user can request access; admins should review requests against policy, cost, and compliance |
| Model policy — Anthropic family | M365 Admin Center > Copilot settings | Allows admins to turn off the Anthropic model family (Claude Opus, Sonnet, Fable) at the tenant level |
| Model policy — Fable 5 (Preview) | M365 Admin Center > Copilot settings | Fable 5 (Preview) is off by default; admins opt in explicitly, acknowledging that the model provider retains prompts and responses |
| Browser-use tenant toggle | M365 Admin Center > Copilot > Settings > View All > Cowork settings > Allow browser access | The Cowork Browsing capability is disabled by default; admins enable "Allow Cowork to use the Microsoft Edge browser to perform tasks on behalf of users" only after review |
| Consumption visibility and limits | M365 Admin Center > Copilot > Cost management | Shows Cowork consumption (model responses, tools/skills, image generation, browser tasks) and supports per-user or per-group consumption limits |
| Plugin governance | M365 Admin Center > Integrated apps / plugin availability controls | Controls which Microsoft 365 App Store plugins (Microsoft and partner) extend Cowork, deployment scope, and connector authentication |
| Custom skill governance | Cowork > Customize > Skills | Governs user-authored and uploaded custom skills, including guided-builder, .md/.zip/.skill uploads, and skill sharing |
| Uploaded plugin packages | Cowork > Customize > Plugins | Governs uploaded plugin packages (for example, converted Claude packages) and their sharing scope |
| Purview integration | Microsoft Purview portal | Provides sensitivity-label handling, DLP for Copilot, audit, and eDiscovery coverage for Cowork interactions per the dedicated Purview for Cowork guidance |
| Data residency | Follows the Microsoft 365 Copilot data residency model | No separate Cowork residency configuration; residency is governed by the tenant's Copilot residency posture |
Access Model at GA
At GA, Cowork exposure is a combination of two independent settings:
| Setting | Effect |
|---|---|
| Usage-based billing enabled for a user/group | The specified users can use Cowork; consumption counts against the tenant's Copilot Credits |
| Discovery enabled (billing not yet configured) | Users see Cowork listed in Microsoft 365 Copilot and can submit an access request; they cannot use Cowork until an admin approves and enables billing for them |
| Discovery off, billing not enabled | Cowork is not visible to users and cannot be requested |
| Discovery off, billing enabled for specified users | Only the explicitly billed users can access Cowork; billing overrides discovery for those users |
For FSI, the recommended posture during initial adoption is to enable usage-based billing only for an approved pilot group and to keep tenant-wide discovery off so Cowork is not surfaced to the wider workforce before governance is complete.
Agentic, Model, Browser, and Data-Access Considerations
Cowork performs multi-step work and retrieves content the user is already permitted to access. It does not grant new permissions, but it can surface and act on existing content more efficiently, which makes the quality of underlying access governance more consequential. Cowork ships with third-party models from Anthropic (Claude Opus 4.8, Sonnet 5, and Fable 5 (Preview)) alongside a Sonnet+Opus Advisor pairing, GPT 5.5, and Imagen 2 for image generation; Fable 5 (Preview) is off by default and, when enabled, causes the model provider to retain prompts and responses (Cowork displays a banner while it is selected). Admins may turn off the entire Anthropic model family through Copilot settings if organizational policy requires it.
Local browser use runs in the user's local Microsoft Edge browser using their existing sign-ins and inherits organizational Conditional Access, Microsoft Purview DLP, browser management policy, and any site allow/block/view-only rules already in force. Cowork records each browser task it starts on a user's behalf in the unified audit log alongside other Cowork activity. Because sessions, cookies, and credentials stay on the user's device, the agent's reach is bounded by what the user could reach manually — no more and no less.
Cowork follows the Microsoft 365 Copilot data residency model; there is no separate Cowork residency configuration. Microsoft Purview supports securing and governing Cowork per the Purview for Cowork guidance. Organizations should confirm current data-handling, residency, and compliance behavior against Microsoft documentation on an ongoing basis as GA capabilities evolve.
Copilot Surface Coverage
| Surface | Coverage | Notes |
|---|---|---|
| Microsoft 365 Copilot on the web | Full | Cowork is used at https://m365.cloud.microsoft; the Customize page (skills + plugins) and browser use are hosted here |
| Microsoft 365 Copilot desktop app | Partial | Cowork is available; local browser tasks are not run from the desktop app and are routed to the web experience |
| Microsoft 365 Copilot mobile app (iOS/Android) | Partial | Cowork is available on mobile; browser use is not supported on mobile |
| Local Microsoft Edge browser (preview) | Preview | Cowork Browsing runs in the user's local Edge, inheriting Conditional Access, DLP, browser policy, and site allow/block/view-only rules |
| Microsoft 365 App Store plugins | Full | Microsoft plugins (for example, Dynamics 365 Customer Service, Sales, ERP, Fabric IQ) and partner connectors (for example, Jira, Salesforce, ServiceNow, SAP ERP, Workday HCM, Zendesk) extend Cowork and are governed through admin plugin controls |
| Uploaded and shared skills/plugin packages | Full | Custom skills and uploaded plugin packages are governed through Cowork's Customize page and the tenant's extensibility posture |
Governance Levels
Baseline
- Document the tenant's Cowork access posture: which users/groups have usage-based billing enabled, whether the discovery setting is on, and the approval basis for both decisions
- Restrict initial Cowork access (usage-based billing) to an approved pilot security group rather than the whole tenant
- Keep tenant-wide discovery off during the pilot so Cowork is not surfaced to users who are not yet in scope
- Keep the Cowork Browsing local-browser toggle off until browser use is reviewed under this control and Control 4.1
- Keep the Claude Fable 5 (Preview) model off unless provider data retention has been reviewed and approved
- Maintain an inventory of which Cowork plugins (Microsoft and partner) are available and who approved them
- Document the initial per-user or per-group consumption limit and the approval basis
Recommended
- Manage usage-based billing scope, discovery, model toggles, browser-use toggle, and consumption limits through a documented change register
- Separate approval and implementation so the same person does not both authorize and enable Cowork changes
- Review Cowork plugin availability, uploaded plugin packages, custom skills, and their sharing scope periodically against the approved inventory
- Route access requests received in the admin center through a documented approval workflow (policy, cost, and compliance review)
- Confirm that Cowork activity (including browser tasks and Purview-recorded interactions) is captured by existing audit and supervision tooling, and document any coverage gaps
- Coordinate Cowork rollout decisions with Copilot readiness and data-protection controls to limit oversharing exposure
Regulated
- Require dual approval (technology + compliance) before enabling usage-based billing, discovery, browser use, or the Anthropic/Fable model toggles for any regulated or client-facing population
- Treat Cowork outputs that influence client communications or recordkeeping as in-scope for supervisory review under FINRA Rule 3110, where applicable
- Verify that Cowork-generated outputs subject to retention obligations are captured by existing books-and-records and retention controls
- Restrict Cowork administration using time-bound privileged access (PIM or equivalent) and least-privilege AI Administrator / M365 Global Admin roles
- Prohibit or explicitly document any use of models that require provider data retention (for example, Claude Fable 5 (Preview)) for regulated data
- Preserve billing scope, discovery setting, model-toggle, browser-toggle, plugin/skill inventory, and consumption-limit evidence for examination-ready retention periods
- Maintain a documented exception register for any deviation from the approved Cowork governance baseline
Setup & Configuration
Step 1: Confirm the access posture (billing + discovery)
Navigate to M365 Admin Center > Copilot > Cost management and record which users or groups have usage-based billing enabled for Cowork. Then navigate to M365 Admin Center > Copilot > Settings > AI experiences enabled by usage-based billing and record whether discovery is on. Document the approver, the pilot scope, and the initial spending policy.
Step 2: Govern model toggles
In M365 Admin Center > Copilot settings, confirm the state of the Anthropic model family toggle and the Claude Fable 5 (Preview) toggle. Fable 5 (Preview) should remain off unless the provider data retention terms have been reviewed and approved for the intended use. Record the model-toggle decisions and their approval basis.
Step 3: Govern the Cowork Browsing tenant toggle
Navigate to M365 Admin Center > Copilot > Settings > View All > Cowork settings > Allow browser access. Leave "Allow Cowork to use the Microsoft Edge browser to perform tasks on behalf of users" unchecked until browser use has been reviewed against Control 4.1, existing Conditional Access, Microsoft Purview DLP, browser management policy, and any tenant-wide site allow/block/view-only rules that should apply. Local browser use remains a preview feature and should be treated accordingly.
Step 4: Govern plugins and custom skills
Review the plugins available to Cowork through the admin plugin controls. Maintain an approved-plugin inventory covering Microsoft plugins and partner connectors, confirm connector authentication for any Dynamics 365 / Agent 365 integrations, and restrict plugin availability to approved populations. Coordinate with Control 4.13 (Extensibility Governance) on the Customize page (Cowork > Customize): user-created and uploaded custom skills (.md, .zip, .skill), uploaded plugin packages, and skill/plugin sharing scope.
Step 5: Set consumption limits and monitor spend
In Copilot > Cost management, set per-user or per-group consumption limits appropriate to the pilot's approved budget. Establish a review cadence for consumption reporting so growth against the approved budget is visible before month-end. Include model responses, tools/skills, image generation, and browser tasks in that view.
Step 6: Confirm Purview, audit, and supervision coverage
Confirm Cowork is included in the tenant's Purview posture per the Purview for Cowork guidance (sensitivity labels, DLP for Copilot, audit, communication compliance, eDiscovery). Confirm browser task audit records are visible in the unified audit log. Document any gaps, and define a review cadence for access posture, model toggles, browser toggle, plugin/skill inventory, and consumption reporting.
Financial Sector Considerations
Broker-dealers: Before enabling usage-based billing for registered representatives, evaluate whether agentic outputs — including browser-driven form submissions and image generation — that contribute to client communications or correspondence fall within supervisory review and books-and-records obligations under FINRA Rule 3110 and SEC Rule 17a-4 (for required broker-dealer records), and restrict billing scope until those procedures are confirmed.
Banking institutions: Treat Cowork enablement and each subsequent expansion (billing scope, discovery, browser use, Fable 5 (Preview), consumption-limit change) as change-control and operational-risk events consistent with FFIEC expectations, and reflect the decisions in enterprise technology governance records.
SOX-reporting entities: Where Cowork is used in finance, reporting, or control-support workflows, retain access-posture, model-toggle, and approval evidence in a form that supports internal and external audit review under Sarbanes-Oxley §§302/404 where applicable to ICFR.
Covered institutions under OCC Heightened Standards: Reflect Cowork adoption — and any use of third-party model providers, including any model that requires provider data retention — within the firm's risk governance framework so that introduction of a new agentic capability is subject to appropriate board and risk-management oversight.
Preview sub-features: Local browser use and Claude Fable 5 (Preview) remain preview capabilities at the time of last verification. Organizations should avoid embedding preview sub-features in critical or unsupervised workflows and re-assess them each time Microsoft updates the preview status.
Verification Criteria
| # | Verification Step | Expected Result |
|---|---|---|
| 1 | Review Cowork access posture | Usage-based billing scope and the discovery-setting state are documented with an approver, and both match the approved pilot decision |
| 2 | Review access-request handling | Any user access requests are routed through a documented approval workflow with a policy, cost, and compliance review |
| 3 | Review model toggles | The Anthropic-family and Claude Fable 5 (Preview) toggles match the documented decisions; Fable 5 (Preview) is off unless provider data retention has been reviewed and approved |
| 4 | Review the Cowork Browsing toggle | The Cowork Browsing tenant toggle is off, or is on only after a documented review of Conditional Access, DLP, browser policy, and site allow/block/view-only rules |
| 5 | Review Cowork plugin, uploaded package, and custom skill inventory | Available plugins, uploaded plugin packages, and custom skills (with their sharing scope) match an approved inventory |
| 6 | Review consumption limits and reporting | Per-user or per-group consumption limits match the approved budget; consumption reporting is reviewed on a documented cadence |
| 7 | Confirm Purview and audit coverage | Cowork is included in the tenant's Purview posture per the Purview for Cowork guidance; browser task events appear in the unified audit log, or gaps are documented with a remediation owner |
| 8 | Confirm review cadence | A documented frequency exists for reviewing access posture, model toggles, browser toggle, plugins/skills, and consumption reporting |
Additional Resources
- Manage Copilot Cowork for your organization
- What's new in Copilot Cowork
- Choose a model for Cowork
- Manage plugins for Cowork
- Customize Cowork (skills and plugins)
- Use the local browser with Cowork (preview)
- Discovery setting for AI experiences enabled by usage-based billing
- Managing AI experiences enabled by usage-based billing (Copilot Credits)
- Use Microsoft Purview to manage data security & compliance for Copilot Cowork
- Data residency for Microsoft 365 Copilot
- Implementation Playbooks: Portal Walkthrough · PowerShell Setup · Verification · Troubleshooting
- Related Controls: 4.1 Admin Settings and Feature Management, 4.13 Extensibility Governance, 4.14 Copilot Studio Agent Lifecycle Governance