Are you sure about that title? Cause agents are made with IT products, right? But you need an idea, and a use case to start making one.
Whenever I ask organisations about citizen development for agents, the answer is almost always the same: "Oh, we don’t have any of that here." But if you look under the hood, employees are more than willing to build their own agents. And before you think, "well, sure, but that's only at super techy companies," trust me! I see this happening everywhere, even in places not exactly known for being on the cutting edge.
When I run AI workshops (whether it's Copilot chat, Cowork, or general AI discovery) I always ask people about their experience with AI, both personal and professional. Lately, almost everyone has a story. Someone used AI to design a garden shed they’ve wanted to build for years but had no idea how to start. Someone else used it to plan a complex family vacation or draft a custom weekly meal plan.
That kind of hands-on experimentation triggers a spark. Once people discover what AI can do in their personal lives, they start looking at their jobs differently. They spot repetitive tasks, look at the endless searching for documents, and realise, "Hey, this doesn't have to be so draining."
Those curious employees are the exact people who will help your organisation develop agents that are actually useful. Innovation starts right there on the shop floor, with an employee trying to make their workday a little bit easier.
Having an Idea is One Thing. Managing It is Another.
Finding a cool use case is a great first step, but agents, just like every other asset in your IT stack, need proper governance and a proper home.
As an agent grows in complexity, where it lives needs to change:
- A quick personal agent works fine using Agent Builder inside Microsoft 365.
- An agent meant for an entire team is probably a better fit for Copilot Studio.
- A specialised agent designed for complex, cross-system business processes might need Microsoft Foundry and professional engineering.
Each of these environments (whether tied to SharePoint, OneDrive, Power Platform, or Azure) requires its own set of guardrails. Some of those guardrails are technical, while others are financial. After all, most advanced agents rely on tokens, external APIs, or background reasoning, and those consumption costs can add up quickly if nobody is watching the meter!
The Spectrum of Autonomy: From Observing to Acting
To understand why this gets tricky, it helps to think about what an agent actually does. We can break agent behavior into four basic levels:
- Observe: The agent simply retrieves and summarises information, like a SharePoint search helper.
- Advise: It recommends actions or drafts content for a human to review.
- Act with approval: It writes data or triggers a workflow, but only after a person clicks "yes".
- Act autonomously: It runs in the background, handling tasks, updating systems, or processing tickets completely on its own.
As you move up that list from Observe to Act autonomously, the business value jumps, but so does the potential for chaos! An agent that just reads a document is low risk. An autonomous agent that edits files, sends emails to clients, updates records, or places orders is basically operating as a digital coworker.
Platform Governance vs. Agent Governance
Besides setting up the platform guardrails, you also have to govern the individual agents. If an agent has the power to act, you need to stay in control of what it's allowed to do, what data it touches, and who is responsible for it.
That's where Agent 365 comes looking around the corner.
Microsoft created Agent 365 specifically because we are heading toward a world with hundreds, or even thousands, of agents running across an enterprise. IT needs a control plane. Agent 365 gives your IT admins a complete overview of all the agents operating in your organisation. It lets them see which data sources are connected, what the system prompt looks like, which connectors are active, and who has access.
In a best-practice scenario, you want to assign an agent owner from the business side for every production agent. Microsoft has tried out a few different names for this role, including "Agent Boss." I’m still not entirely sure how I feel about that title, but it definitely gets the point across!
Agents are digital employees, and someone in the business needs to be responsible for what they’re up to. Nobody knows the business process or the required information better than the person actually working with that agent every day.
Just like a human colleague, an agent can even be assigned its own Entra ID identity through Agent 365. That way, you can track its activity in audit logs, apply Conditional Access rules, and enforce Data Loss Prevention policies.
So... about licensing...
As this entire ecosystem matures, Microsoft is adjusting its licensing to match how organisations actually adopt AI. You start with basic Copilot Chat, move to Microsoft 365 Copilot for regular daily users, add Copilot Studio for team processes, and eventually need Agent 365 to keep the whole digital workforce safe.
When an organisation reaches the point where their employees need full enterprise security, heavy Copilot usage, advanced identity protection, and central agent governance, buying all those pieces separately becomes a logistical and financial headache. That's precisely why Microsoft 365 E7 has been introduced. It comes with E5 capabilities, Microsoft 365 Copilot, Agent 365 and Entra ID Suite.
Does every single company or employee need an E7 licence tomorrow? Absolutely not! An SMB running one read-only knowledge agent certainly doesn't need it. But for mature enterprises rolling out broad Copilot capabilities alongside governed, autonomous agents, having an integrated licence suite makes the overall stack far easier to manage.
Governed Abundance
i Dundun, Loa of Abundance - World of Warcraft

I don't believe the future consists of just a handful of centrally managed enterprise agents built by IT. The future is going to be hundreds of agents, big and small, popping up across every department.
The question isn't whether agent sprawl will happen. It will! The real question is whether your organisation has the governance, ownership, and platform foundations ready to support it.
The companies that succeed won't be the ones trying to block people from experimenting. They will be the ones that embrace that initial spark of employee creativity, give those agents a safe place to land, and use tools like Agent 365 to turn personal productivity hacks into managed, business-critical capabilities.