Governing-The-Autonomous-Workforce

Copilot Agent Governance: Guardrails for Custom AI Agents

Governing-The-Autonomous-Workforce
Microsoft Copilot Consulting

Governing the Autonomous Workforce: Establishing Guardrails for Custom Copilot Agents

A partner at a mid-size firm once described her ideal assistant: someone who reads every matter file, drafts the first version of every routine document, and never sleeps.

Not long ago, that assistant would have needed a job offer and a background check. Today, she can build one herself, in an afternoon, with no IT ticket required.

The same assistant, two routes
Two routes to the same assistant. The upper one passes a job offer and a background check. The lower one passes the same two points, drawn empty, and arrives with identical reach. Nothing about the assistant changed. Only the approval did.

That is the quiet shift happening inside Copilot Studio. And it is exactly why CIOs and general counsel are starting to ask questions about something that sounds, on paper, like a pure productivity win.

The Shift Nobody Approved

For the past two years, AI in legal work was mostly conversational.

A lawyer asked a question. AI gave an answer. A human reviewed it before anything important happened.

That model had a built-in safety net. If the answer was wrong, it generally stayed there until someone decided to use it.

Custom agents change that.

Answering, then acting
The same gate in both lanes. In the upper one somebody is standing in it, which is the safety net the paragraph above describes. In the lower one it is drawn empty, and the flow does not stop there: it runs straight to the four actions named in the next paragraph.

An agent can do more than answer a question. It can update a matter record, draft client correspondence, pull information from a CRM, or trigger a workflow.

And because these agents can be built with low-code tools, the person creating one may have nothing to do with IT.

It could be a paralegal automating client intake. A knowledge manager is building a research assistant. Or an associate trying to save an hour before a filing deadline.

None of that is reckless. In fact, that is exactly what these tools are designed to enable.

The problem starts when the agent becomes more capable than the guardrails around it.

When Nobody's Watching: How a Small Shortcut Becomes a Legal Risk

Consider a simple example.

An associate is working on a litigation matter and builds a "matter research assistant" to speed up drafting. To get it working quickly, the agent is connected to the SharePoint libraries the associate can access.

The setup works.

But there is a problem: the associate has access to more information than this matter requires.

A few weeks later, a partner reviews a draft brief and notices a sentence that looks strangely familiar. After checking the source, the team discovers that the wording came from a memo belonging to an unrelated matter involving the same opposing counsel.

That information was sitting behind an ethical wall.

What the agent was given, against what the matter required
The difference between the two boxes is the whole incident. What the matter required stops well short of the wall. What the agent was given does not, so a document on the far side sat inside its reach without anyone choosing that it should.

The associate did not deliberately access it. Nobody was trying to bypass control. The agent simply had more access than the task required, and nobody had checked its scope before it went live.

Now a productivity tool has potentially created a much bigger problem: a conflicts issue, a possible client disclosure obligation, and an uncomfortable explanation if the matter reaches a judge during discovery.

And that is one agent.

Now imagine dozens of similar agents being created across practice groups over the course of a year.

One agent, then dozens
Forty-nine agents across nine practice groups. The dashed line is what the firm can actually see, and it is flat, because review capacity does not grow just because the number of agents does. Every square above it is an agent that works exactly as built and that nobody has checked.

The risk does not just grow. It compounds.

The Four Risks That Grow Together

Once agents start multiplying across a firm, four problems tend to appear together.

Four problems that appear together
  • Data exposure. An agent can inherit the permissions of the systems it connects to. Those permissions may be much broader than what the agent actually needs.
  • Compliance drifts. An agent created outside the firm's review process may not align with existing retention, security, or data loss prevention controls.
  • Cost sprawl. Different practice groups may build similar agents without realizing that another team has already created one, adding unnecessary licenses and compute costs.
  • Identity ambiguity. When something goes wrong, the firm needs to know who created the agent, what information it accessed, what actions it took, and who approved it.

The common thread is simple:

The common thread

If nobody has visibility into the agents being created, nobody has reliable control over them either.

What Good Governance Actually Looks Like

Firms that are approaching this well are treating agents much like they would treat a new employee who needs access to client information: give them the access they need, define what they can do, and make sure someone is accountable for their actions.

That means:

The Agent Governance Framework
  • Approval before deployment.An agent should go through central administrative review before it goes live, rather than waiting for something to go wrong.
  • Defined access.Agents should be limited to specific Microsoft 365 users or groups instead of being left open-ended.
  • Governed data.Agents should work from the firm's approved document and matter data rather than pulling information indiscriminately from the open web.
  • Complete traceability.Firms should be able to see what an agent accessed and changed, creating a record that can be explained to a client, regulator, or judge if necessary.
  • A named owner.Every agent should have one accountable owner in the tenant. When something goes wrong, there should be no question about who is responsible for it.
The same five, read as a lifecycle
Four of the five are points an agent passes through. The fifth is not: an accountable owner has to hold at every point on the track, which is why it is drawn as the band under all of it rather than as a final step somebody signs off and leaves behind.

Every agent has a defined scope. Every action can be traced. And when something goes wrong, the firm can explain what happened instead of trying to reconstruct it under pressure.

The autonomous workforce is already inside the firm.

The question for legal leadership

The question for legal leadership is no longer whether employees will build AI agents. It is whether those agents will have a supervisor.