You Already Have More Agents Than You Think
Someone enables one agent for one team. Six weeks later there are fourteen of them, and nobody can say what data each one is allowed to read. Agents arrive in a SharePoint tenant three ways. None of them needs sign-off from anyone in IT.
Agent come with the site. Every SharePoint site ships with a ready-made agent, scoped to that site's content. Nobody switches it on. Before anyone builds a thing, your agent count equals your site count.
Anyone with edit rights makes one. A custom agent is a file, a .agent file, sitting in the site like any document. Microsoft's own documentation says these "don't automatically appear in any list or published location." People open them like Word files and pass them around by copying a link.
Your developers ship them without meaning to. Every SharePoint Copilot App is built on a declarative agent of its own. If you have a component roadmap, you have an agent roadmap.
Add those up and here is what you are actually being asked to govern: an invisible file that answers questions, created without approval, findable only by whoever has the link. You cannot even label it. Sensitivity labels do not yet apply to .agent files, so Purview DLP has to target the file extension instead.
Gartner's Five Steps
Gartner's guidance recommend five steps:
- Adaptive governance. Tier your controls by the risk and complexity of each agent rather than applying one policy to everything.
- Redefine the site-owner role. Site owners become frontline AI stewards, accountable for what their site's agents expose.
- Content hygiene. Metadata, sensitivity labels, and lifecycle management on the content underneath.
- Third-party tooling. Buy something to bridge the gaps that native Microsoft tools leave open.
- Formal training and certification. Train the stewards, certify them, make it a programme.
Nothing on that list is wrong. It just assumes a company that can staff it. Of the five, content hygiene is the only one I would defend when the budget conversation starts, and I will come back to why.
SharePoint Agent Governance Process We Run for SMBs
Gartner's governance tiers are mostly aspirational for organisations below 500 seats. The organisations we work with have no headcount for a site-owner-as-AI-steward programme with training and certification. So we collapse it into four things one person can actually finish.
Audit before you enable Copilot for anyone. Take the top five to ten sites by sensitivity: finance, HR, partner and owner material, anything client-confidential. Run a permissions review on those specifically, not on the tenant. This is a fortnight of work, not a quarter.
Label the worst offenders. Sensitivity labels on what the audit found. This is Gartner's content hygiene step, scoped down. It is the only step on their list that fixes the problem instead of hiding it, which is why it survives when the budget gets cut.
Flag those sites with Restricted Content Discovery. Flag a site and its content stops surfacing in Copilot and org-wide search, and the AI entry points vanish from the site itself: no Copilot button, no agent creation, no ready-made agent answering questions.
That one switch is what prevents the "Copilot just surfaced a 2022 partner comp spreadsheet" story, and it is the only switch that also stops someone building a new agent on that content. It protects the sites you flagged and nothing else, which is why the audit comes first.
Pilot with five users. A few weeks. Watch what they genuinely ask Copilot, not what you assumed they would ask. That pilot is what replaces the certification programme, and it costs nothing.
Then give every agent a named human. Microsoft has automation for this, a sponsor role in Entra ID Governance and reassignment rules in the admin center, but read the licensing before you plan around it (might need Microsoft 365 E7, or an Agent 365 licence on top of Entra ID P1).
If your base subscription is E3 or E5, assigning a single Microsoft 365 Copilot licence to one user gives your SharePoint admins the SharePoint Advanced Management features that support Copilot deployment, tenant-wide. The oversharing reports and Restricted Content Discovery both run on it. One licence, not one per admin.
The SharePoint Admin Agent Is the Inventory You Wanted
I went looking for a tenant-wide list of every agent running in a customer tenant. This is the nearest thing Microsoft ships, and it is worth knowing exactly where it stops.
The SharePoint Admin Agent (GA) lets an admin ask in plain language instead of running reports. "Show me a list of the top 10 agents that are accessing my SharePoint and OneDrive content." "Identify sites with low activity by department." "Which sites are overshared and what are the risk levels for these sites?"
Material: Move from insight to action with the SharePoint Admin Agent
It reads SharePoint Advanced Management data, so it sees what SAM sees, and nothing SAM does not. It also ships with core skills, including a Storage skill and a Recovery skill (integrated with Microsoft 365 Backup to find restore points), and can be integrated with Agent 365.
Conclusion
The right governance shape changes enormously between 50 seats and 5,000, and most of what gets published is written for the top of that range. At around 500 seats the question is not whether to allow Copilot agents in SharePoint.
It is which sites you would be uncomfortable seeing one answer questions about, and whether anyone in the building can name the owner of a single agent in your tenant today.
Work with Precio FishbonePrecio Fishbone works with organisations to move from AI and Microsoft strategy to structured, practical implementation. To discuss what this means for your environment, contact our team.
Frequently Asked Questions
Do we need to enable agents in SharePoint?
No. Agents require no activation and every site ships with a ready-made agent scoped to its content. Access is governed by Copilot licence assignment, or by a pay-as-you-go billing policy.
Can we see every agent in our tenant?
Partly. The Copilot Control System lists agents used in Copilot Chat, but its block button does not yet apply to SharePoint, OneDrive or Teams. The SharePoint Admin Agent gets you closer.
What is the SharePoint Admin Agent?
A governance agent that answers questions about your tenant in plain language, built on SharePoint Advanced Management data. It requires SAM and the SharePoint Advanced Management Administrator role in Entra ID. It is the closest thing to a working tenant-wide agent inventory Microsoft currently offers.
Do agents respect our existing permissions?
Yes. An agent never shows a user content they could not already open. It makes existing oversharing easy to find, which is the real risk.