Microsoft Copilot Studio: Enabling makers to require human approval for tool calls
🚨 The Signal: Copilot Studio now allows human approval for agent tool calls, enabling a 'human-in-the-loop' for high-risk actions like sending emails or processing payments. This provides a critical guardrail for autonomous agent operations.
The Impact
Security teams and Copilot Studio makers are affected, gaining a critical control to mitigate risks from autonomous agent actions.
- Security Teams: Reduces risk of unauthorised automated actions.
- Copilot Studio Makers: Enables safer deployment of agents with sensitive capabilities.
- Compliance Officers: Provides auditable human oversight for automated processes.
- End Users: Introduces an approval step for agent-initiated high-stakes actions.
The Action
- Review existing Copilot Studio agents for tools performing high-stakes actions.
- Identify tools within agents that require human approval for execution.
- Enable 'Require human approval' toggle for identified tools in Copilot Studio.
- Communicate new approval workflows to agent users and stakeholders.
- Establish an approval policy for agent tool calls, defining approvers and scenarios.
Domain: Agentic-AI · Impact: high · Workload: Other · Essential Eight: Restrict Administrative Privileges · ISM: ISM-0445, ISM-1175, ISM-1380, ISM-1507, ISM-1508, ISM-1509, ISM-1647, ISM-1648, ISM-1650, ISM-1686, ISM-1688, ISM-1689, ISM-1883, ISM-1897, ISM-1898