What Microsoft means by an agent
In Microsoft 365, an agent is a version of Copilot set up for one job. It has instructions, a defined set of knowledge such as a SharePoint library or a few documents, and sometimes actions it is allowed to take2. People open it from Copilot Chat or from Teams, and ask it questions or give it tasks the same way they would ask Copilot itself. Microsoft now calls the paid product Microsoft Copilot and the free chat Microsoft Copilot Chat, dropping the Microsoft 365 prefix, so menus and admin pages may use either name17.
There are four kinds worth separating. Microsoft builds some agents itself, such as Researcher and Analyst, and Researcher is part of the default experience for people with the paid Copilot licence16. Anyone permitted by an admin can create a simple agent in Copilot Chat with Agent Builder, by describing what it should do and pointing it at content3. Copilot Studio is the fuller tool, where a maker can add connectors to other systems, actions, approval steps and triggers1. Finally, Copilot features inside Word, Excel and PowerPoint can now carry out multi-step edits on a document when asked, and Microsoft keeps renaming these features, so check the current name in your apps. Each kind has a very different effort and risk profile.
Three levels of ambition
A useful way to plan is to sort ideas into three levels, and to finish the first level before starting the second.
- Level 1, answer from our documents: an agent that answers staff questions from a curated set of files, such as the employee handbook, the health and safety manual or product specifications. Built with Agent Builder in an afternoon. Realistic for almost any business that already keeps its documents in SharePoint3.
- Level 2, help with a defined process: an agent that gathers information and drafts something, then hands it to a person, such as triaging a job enquiry and drafting a quote cover note, or preparing a supplier summary from a form. Usually needs Copilot Studio, Power Automate or both, and someone who can test it properly1.
- Level 3, act on its own: an agent that runs on a trigger, such as a new email or a new row in a list, and takes actions in other systems without a person approving each step. Copilot Studio supports this, but it needs careful permissions, monitoring and a budget for usage1,4. Most firms under fifty staff should treat this level as a later project.
Use cases that work for small NZ businesses
The agents that earn their keep in small firms are almost always narrow. They answer one kind of question well from material someone keeps up to date. Here are patterns that suit businesses of five to two hundred people.
A Palmerston North trades business with a scattered crew can build a Level 1 agent over its safe work method statements and site induction notes, so a supervisor can ask a question from a phone in Teams and get the relevant procedure with a link. The Health and Safety at Work Act 2015 still places the duties on the business and on officers, and it requires the business to engage with workers on matters that affect their health and safety9. The agent helps people find the right procedure faster. It does not decide what is safe, and it should always link to the controlled document rather than paraphrase it.
A Napier wholesale business can use a Level 2 flow in which a Microsoft Forms enquiry triggers Power Automate, Copilot drafts a summary and a suggested reply, and the result lands in a Teams channel for a person to check and send. The person stays in the loop for every customer response, and the agent never quotes a price on its own.
An office manager in a Whangārei professional practice can create a Level 1 agent over the staff handbook, leave policy and IT how-to pages. It handles routine questions such as how to book leave or connect to the printer, and passes anything about a specific person's employment to the manager.
- Good first agents: policy and procedure lookup, product or service knowledge for new staff, a template finder, a meeting-prep agent that summarises a client's recent emails and files.
- Poor first agents: anything customer-facing without review, anything that changes financial records, and anything that makes or recommends a decision about an individual employee or customer.
What it really takes to build and run one
The build is rarely the hard part. Agent Builder lets a non-technical person create a working Level 1 agent quickly3. The ongoing work is in the knowledge behind it. An agent answers from whatever files it is given, so out-of-date policies produce confident, out-of-date answers. Somebody has to own the content, review it on a schedule, and remove superseded versions.
Testing is the second hidden cost. Before an agent is shared, write twenty or so real questions staff actually ask, including awkward ones, and check every answer against the source. Repeat the test whenever the knowledge changes. For Level 2 and 3 agents, test what happens when the input is wrong, missing or malicious, not only when it is tidy.
Cost depends on the kind of agent and who uses it. Copilot Studio usage is measured in Copilot Credits, with some usage covered for people who hold a paid Microsoft 365 Copilot licence and other usage billed through capacity packs or pay-as-you-go4. Power Automate flows that use premium connectors may need their own licences. Get a written estimate from your Microsoft provider for the specific agent before you build anything at Level 2 or 3.
The risks that are specific to agents
An agent multiplies whatever is wrong with its setup. Microsoft's Copilot Studio security guidance covers authentication, who can use an agent, and which connectors and data it can reach7. Power Platform data loss prevention policies let an admin block connectors that would move business data to places it should not go5. Neither control helps if nobody switches it on.
Prompt injection is the risk most small businesses have not heard of. If an agent reads emails, web pages or uploaded documents, someone can hide instructions in that content to make the agent ignore its own rules or leak information. The NCSC's joint guidance on engaging with AI lists this kind of manipulation among the threats organisations should plan for11. The practical defence is to keep agents that read outside content away from sensitive actions, and to require a person to approve anything that sends, pays, deletes or changes records.
Privacy duties also apply at scale. An agent that summarises customer files is using personal information, so the Privacy Act 2020 principles on purpose, accuracy and security apply to it as much as to a person doing the same task13. The Privacy Commissioner expects human review of AI output before an agency acts on it12. The GCDO's public-service guidance makes the same point about keeping accountable people involved in AI-assisted decisions14.
- Give each agent the narrowest knowledge and permissions it needs.
- Require human approval for any action that leaves the business or changes a record.
- Name an owner for every shared agent, and record what it can reach6.
- Turn on data loss prevention policies in the Power Platform admin center before makers start using connectors5.
Automation and your people
Automation changes jobs, and New Zealand employment law has a view on how that is handled. Under the Employment Relations Act 2000, the duty of good faith means an employer proposing a decision that will, or is likely to, have an adverse effect on the continuation of employees' jobs must give them access to relevant information and a chance to comment before the decision is made8. If an automation project could reduce hours or remove roles, plan consultation from the start rather than presenting it as finished.
Most small-business agents do not remove jobs. They remove the repetitive parts of jobs. Say so plainly, involve the people who do the work in choosing what to automate, and let them test the agent. They know where the exceptions are. MBIE's responsible AI guidance for businesses encourages exactly this kind of proportionate, transparent approach, with clear accountability for each AI use10.
Governance a small business can actually run
You do not need an AI committee. You need a few decisions written down. In the Microsoft 365 admin center, admins can control which agents are available to whom and who may create and share them6. Start with sharing limited to a pilot group, and open it up once you have seen what people build.
- Decide who may create agents, and who may share them beyond themselves.
- Keep a simple register: agent name, owner, purpose, knowledge sources, connectors, review date.
- Review each shared agent every quarter, and retire ones nobody uses.
- Set a usage budget and alert for any pay-as-you-go or credit-based billing4.
A realistic first ninety days
For the first 30 days, focus on Copilot itself, not agents. Get people using Copilot Chat or paid Copilot well, and clean up SharePoint permissions and old content, because every agent will inherit those problems. Our guide on checking permissions before a Copilot rollout covers that step.
In the second month, build one Level 1 agent over a single, well-maintained set of documents, such as the staff handbook. Test it with real questions, share it with a pilot group, and record what it gets wrong. In the third month, decide whether a Level 2 process is worth building, and if so, scope it with the people who do that work today, including where a person must approve the result. Leave Level 3 until you have run Level 2 safely for a while.