Microsoft has introduced a pivotal security enhancement to Copilot Studio, empowering developers to establish manual approval workflows for AI agents and specific tools. In scenarios where an AI agent undertakes sensitive tasks, such as sending emails, the system will automatically pause and initiate an approval request. Subsequently, users have the option to approve the action, permit the current session to proceed, or deny the request. These approval requests have been seamlessly integrated into work channels, including Teams and Microsoft 365 Copilot.
Presently, this feature is fully operational as a standard function within the web-based version of Copilot Studio and has been rolled out worldwide via Microsoft's robust multi-tenant cloud infrastructure. This strategic move establishes clear security boundaries for enterprise-level AI agents, mitigates risks associated with compliance and asset loss, and sets a precedent for the compliant deployment of AI agents in sensitive business environments.
