-
Notifications
You must be signed in to change notification settings - Fork 0
2026 04 26 ms copilot cowork
What is Microsoft 365 (M365) Copilot Cowork, how does it technically differ from custom Microsoft Copilot Skills, and what are the governance, legal, and shadow Information Technology (IT) risks it introduces for enterprise organisations?
In scope:
- What Cowork is: product capabilities, workflows, and positioning from official Microsoft documentation and public material
- Technical differentiation from custom Copilot Skills: architecture, extensibility model, data access, and trust boundaries
- Legal and regulatory implications: data residency, privacy, intellectual property (IP) ownership, and enterprise liability exposure
- Whether Cowork is a strategic "claw" for enterprise lock-in: dependency creation, switching cost, and vendor leverage
- Shadow Information Technology (IT) risks: how Cowork enables workflows and automated processes to be built outside normal IT governance, and what controls (if any) exist
Out of scope:
- Full legal advice or formal compliance assessment for any specific organisation
- Detailed implementation guide for deploying Cowork
- Comparison with non-Microsoft Artificial Intelligence (AI) assistant platforms (e.g. Google Workspace, Slack AI)
Constraints:
- Published documentation and credible third-party analysis only: no speculation presented as fact
- Legal analysis limited to publicly available regulatory guidance; not a substitute for legal counsel
[fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/get-started] Microsoft positions Microsoft 365 (M365) Copilot Cowork as a preview, action-taking workspace inside Microsoft 365 Copilot that can send emails, schedule meetings, create files, post in Teams, search enterprise content, and run recurring prompts across a user's existing Microsoft 365 environment. [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq; https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-24-business-led-low-code-agent-governance.md; https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-22-enterprise-ai-use-case-routing-frameworks.md] The enterprise decision is therefore not whether Cowork can automate useful work, but whether the tenant already has the permissions hygiene, rollout controls, and low-code governance needed to stop user-authored automations from becoming shadow Information Technology (IT).
- Read the official Microsoft Cowork documentation at https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/ and extract what Cowork is, what it does, and how it is licensed.
- Identify how Cowork differs architecturally from custom Copilot Skills and Microsoft 365 (M365) Copilot plugins, specifically the trust model, data access scope, and workflow creation mechanism.
- Investigate legal and regulatory implications: data sovereignty, retention, access logging, and how Cowork-created workflows interact with existing enterprise data governance policies.
- Assess the "enterprise lock-in" dimension: what dependencies does Cowork create, and how reversible are workflows created within it?
- Analyse shadow Information Technology (IT) risk: what governance gaps arise when business users create Cowork workflows without IT involvement, and what Microsoft-provided or third-party controls address this.
- Synthesise a clear risk register for enterprise adoption decisions.
- Microsoft 365 Copilot Cowork overview — - primary product documentation for capabilities, built-in skills, approvals, and preview status.
- Use Cowork — - primary workflow documentation for approvals, scheduling, file handling, and custom skill creation.
- Get started with Cowork — - prerequisites, channel availability, and Anthropic dependency.
- Cowork frequently asked questions — - primary documentation for admin disablement, limitations, security statements, and regional restrictions.
- Manage Cowork for your organization — - replacement for the seeded admin-guide URL, which returned 404 in this environment.
- Microsoft 365 Copilot extensibility documentation — - top-level entry for Microsoft's formal extensibility model.
- Agents for Microsoft 365 Copilot — - official distinction between declarative agents and custom engine agents.
- Declarative agents overview — - official packaging, distribution, and compliance model for declarative agents.
- Custom engine agents overview — - official architecture, hosting, and compliance responsibilities for custom engine agents.
- Microsoft 365 Copilot connectors overview — - official external data access models for synced and federated connectors.
- Microsoft 365 Copilot APIs overview — - official API-based extensibility and governance model.
- Microsoft 365 Copilot extensibility planning guide — - official guidance on choosing connectors, agents, and APIs.
- Microsoft 365 Copilot extensibility frequently asked questions — - official clarification of agents, actions, plugins, and connector differences.
- Data, privacy, and security for Microsoft 365 Copilot — - primary privacy, training-use, data residency, and agent-governance documentation.
- Anthropic as a subprocessor for Microsoft Online Services — - primary source for Anthropic enablement, exclusions, and regional defaults.
- Data residency commitments for Microsoft 365 Copilot and Copilot Chat — - primary source for at-rest geography commitments, Advanced Data Residency (ADR), and Multi-Geo.
- Privacy, security, and compliance in Microsoft OneDrive — - primary source for tenant-boundary and data residency claims relevant to Cowork file handling.
- Learn about the Microsoft 365 Copilot and Copilot Chat location for Data Loss Prevention (DLP) — - primary source for DLP controls and control gaps.
- Overview of audit logs for Microsoft Copilot and AI applications — - primary source for auditability and accessed-resource logging.
- Microsoft Trust Center data management — - primary source for retention and deletion commitments.
- Microsoft Frontier program — - official source for preview enrollment framing.
- Creating custom skills for Copilot Cowork — - secondary practitioner confirmation of per-user skill creation and preview behavior.
- How to create custom skills in Cowork — - secondary practitioner confirmation of preview behavior, skill discovery, and lack of visible per-skill approval.
- How to get your Microsoft 365 tenant ready for Copilot Cowork — - secondary governance-focused analysis used only where marked as inference.
- Business-led low-code agent governance: conditions for durable value versus fragmentation in regulated environments — - prior completed repository work on governed citizen development.
- Enterprise AI use-case routing frameworks — - prior completed repository work on routing low-code versus pro-code work.
- Enterprise AI platform operating models: organisational structure and ownership — - prior completed repository work on shared control planes and federated delivery.
- Business-led low-code agent governance: conditions for durable value versus fragmentation in regulated environments
- Enterprise AI use-case routing frameworks
- Enterprise AI platform operating models: organisational structure and ownership
(Full output from running the research skill - retained verbatim in the completed item. Sections 0-5 are the investigation, and section 6 seeds the Findings section below.)
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/agents-overview] Research question restated: what Cowork is, how it technically differs from Microsoft's formal Copilot extensibility surface, and which governance, legal, and shadow IT risks it creates for enterprise tenants.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/planning-guide; https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy] Scope confirmed: in scope are Cowork capabilities, skill architecture, admin controls, data handling, legal and residency implications, lock-in effects, and low-code governance risk; out of scope are tenant-specific legal advice, deployment tutorials, and comparison with non-Microsoft platforms.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance] Constraint confirmed: the primary evidence base is prerelease Microsoft documentation that explicitly says the feature is preview and subject to change, so documentation inconsistencies must be surfaced as uncertainty rather than normalized away.
- [fact; source: https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-24-business-led-low-code-agent-governance.md; https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-22-enterprise-ai-use-case-routing-frameworks.md; https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-22-enterprise-ai-platform-operating-models.md] Prior completed repository work already established three adjacent claims that matter here: business-led automation only scales safely with guardrails, intake should route work by risk and control surface, and shared control planes are usually preferable to fragmented local governance.
- Output format: knowledge.
- Root question: What is Cowork, how is it architecturally different from Microsoft's formal Copilot extensibility model, and what enterprise risks follow?
-
A. Product and rollout
- A1. What actions can Cowork take, and under what user interaction model?
- A2. What licensing, preview, provider, and regional prerequisites govern access?
-
B. Technical differentiation
- B1. How do Cowork custom skills work?
- B2. How do Cowork custom skills differ from declarative agents, custom engine agents, connectors, and Copilot Application Programming Interfaces (APIs)?
- B3. Which trust boundaries and deployment controls are present in each model?
-
C. Governance, legal, and regulatory controls
- C1. What admin availability, deployment, audit, and data-protection controls exist for Cowork?
- C2. What data residency, retention, and Artificial Intelligence (AI) subprocessor constraints apply?
- C3. Which documented control gaps remain?
-
D. Strategic dependency
- D1. What elements of a Cowork workflow are portable, and what elements are tenant-specific?
- D2. Does Cowork create meaningful switching costs or vendor leverage?
-
E. Shadow IT risk
- E1. How easily can business users create new Cowork automations without central review?
- E2. Which controls are necessary before broad rollout is defensible?
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq] Microsoft's preview Cowork pages disagree on at least one operational detail, the custom-skill limit is stated as 20 on the overview page and 50 on the use and frequently asked questions pages, so the exact limit must be treated as preview-unstable.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/get-started; https://adoption.microsoft.com/en-us/copilot/frontier-program/] Microsoft's preview pages also create rollout ambiguity, because some pages require Frontier enrollment for access while the admin-governance page says Cowork is available to all Microsoft 365 Copilot tenants and all licensed users by default.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq] Cowork is a preview Microsoft 365 Copilot agent that can send emails, schedule meetings, create Word, Excel, PowerPoint, and Portable Document Format (PDF) files, post in Teams, search organizational content, conduct deep research, and run scheduled prompts.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/get-started] Cowork breaks work into visible steps, allows interruption or pause, queues follow-up instructions, and requires user approval before sensitive actions such as sending emails, posting messages, or scheduling meetings.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq] Cowork works with cloud content in OneDrive, SharePoint, Teams, and attached files, stores created files in OneDrive and SharePoint, and does not access local files on the user's device.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/get-started; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq; https://adoption.microsoft.com/en-us/copilot/frontier-program/] The current preview requires a Microsoft 365 Copilot license, Frontier enrollment or availability, and Anthropic availability in the tenant and region, while mobile support is not yet available.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq] Cowork has 13 built-in skills and can load user-created custom skills that are stored as
SKILL.mdfiles under a OneDriveDocuments/Cowork/skills/folder and discovered automatically at the start of a conversation. - [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq] The custom skill format is a Markdown file with a frontmatter block containing at least a name and description plus free-form instructions, and Microsoft's documentation says users can also ask Cowork to help create such skills in natural language.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/agents-overview; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-declarative-agent; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-custom-engine-agent] Microsoft's formal Copilot extensibility model is built around declarative agents, custom engine agents, connectors, and Copilot APIs, each of which has explicit packaging, deployment, data-source, or hosting concepts that go beyond user-authored instruction files.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-declarative-agent; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/faq] Declarative agents are app-packaged experiences that use Copilot's orchestrator, knowledge, and actions, can include manifests and optional plugin manifests, and are visible to enterprise administrators through admin-center distribution controls.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-custom-engine-agent; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/copilot-apis-overview] Custom engine agents support custom orchestration, custom models, external hosting or managed hosting through Copilot Studio, and programmatic access to Microsoft 365 Copilot capabilities through APIs.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-copilot-connector; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/planning-guide] Connectors and plugins extend Copilot with external knowledge or actions through synced content, federated real-time retrieval, or REST API calls, which is a different mechanism from a OneDrive-hosted instruction file.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-declarative-agent; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-custom-engine-agent; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-copilot-connector] Cowork custom skills are therefore best understood as prompt-layer extensions of a prebuilt Microsoft agent, not as tenant-governed application components in their own right.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-declarative-agent] The trust boundary is materially different: declarative and custom engine agents expose explicit manifests, admin distribution, and development tooling, while Cowork custom skills ride inside an already approved agent and shift governance to the combination of agent availability, user permissions, and user-authored instructions.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq] Administrators can block Cowork, scope it to specific users or groups, deploy it on behalf of users, and pin it in the Microsoft 365 Copilot rail, using the same agent-governance controls as other Microsoft 365 Copilot agents.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance] The admin-governance page says Cowork is available to all licensed users by default and can be self-installed from the Agent Store unless administrators restrict access.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork] Microsoft states that Cowork uses the caller's existing Microsoft 365 permissions, asks for approval before sensitive actions, and lets users skip repeated approvals for similar actions within the current conversation.
- [fact; source: https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy; https://learn.microsoft.com/en-us/sharepoint/onedrive-privacy-security-overview] Microsoft states that prompts, responses, and data accessed through Microsoft Graph are not used to train foundation models, and that Microsoft 365 Copilot only surfaces organizational data a user can already access.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/enterprise/m365-dr-service-copilot; https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance] Microsoft states that Copilot interaction content is stored at rest in the relevant local region geography, that Cowork supports ADR and Multi-Geo commitments, and that Microsoft 365 Copilot traffic can still use nearby processing capacity unless European Union (EU) boundary safeguards apply.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/connect-to-ai-subprocessor; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/get-started] Cowork depends on Anthropic as a Microsoft subprocessor, Anthropic is disabled by default in the EU, the European Free Trade Association (EFTA), and the United Kingdom (UK), and Anthropic-backed features are unavailable in government and sovereign clouds.
- [fact; source: https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy; https://learn.microsoft.com/en-us/microsoft-365/copilot/connect-to-ai-subprocessor] Microsoft's privacy documentation says Microsoft 365 Copilot is within existing privacy and compliance commitments, but also says Anthropic models are outside the EU Data Boundary and in-country Large Language Model (LLM) processing commitments when used.
- [fact; source: https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance] Microsoft Purview DLP policies apply to Copilot and prebuilt agents including Cowork, can block prompts containing sensitive information, and can exclude sensitivity-labeled files and emails from processing.
- [fact; source: https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about] Microsoft also says DLP does not scan the contents of files uploaded directly into prompts, which leaves a documented control gap for prompt-attached files.
- [fact; source: https://learn.microsoft.com/en-us/purview/audit-copilot; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance] Audit logs capture Copilot interactions and include accessed resources, sensitivity labels, read or create or modify actions, and agent identifiers, which means Cowork activity is auditable at the platform layer.
- [fact; source: https://www.microsoft.com/en-us/trust-center/privacy/data-management] Microsoft's trust-center documentation says customer data is retained for 90 days in a limited-function account after subscription end and then deleted within a further 90 days for in-scope services.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq] Cowork workflows depend on Microsoft 365 identity, Outlook, Teams, OneDrive, SharePoint, agent-side scheduling, and Cowork's built-in action surface, even when the custom layer is only a Markdown instruction file.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-declarative-agent; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-custom-engine-agent] Microsoft's formal extensibility model offers more portable enterprise artifacts, such as manifests, connectors, external APIs, custom-hosted orchestrators, and multi-channel agents, than Cowork's OneDrive skill file model does.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-custom-engine-agent; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/copilot-apis-overview] The instructions inside a Cowork
SKILL.mdfile are portable as text, but the operational value of a Cowork workflow is not, because execution depends on Microsoft-specific permissions, applications, and orchestration surfaces. - [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/planning-guide] Cowork therefore creates medium-to-high switching costs through embedded workflow habits, file locations, approval flows, and tenant-specific context rather than through an inherently proprietary skill syntax alone.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork] Within the current preview documentation, licensed users can install Cowork for themselves when it is available, create custom skills in their own OneDrive, and schedule recurring prompts, while Microsoft explicitly says user-created custom skills are not validated by Microsoft.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/purview/audit-copilot] The central shadow IT risk is not hidden access escalation, because Cowork stays within user permissions, but hidden procedure creation, because business users can turn their existing access into repeatable, weakly governed automations faster than central teams can review them.
- [inference; source: https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-24-business-led-low-code-agent-governance.md; https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-22-enterprise-ai-use-case-routing-frameworks.md; https://www.floor16.com/blog/how-to-get-your-microsoft-365-tenant-ready-for-copilot-cowork-a-governance-first-guide-for-it-leaders; https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about] This risk profile matches the broader low-code pattern from prior repository research: the platform becomes durable only when rollout is group-scoped, sensitive data is policy-protected, audit is turned on, and overshared content is remediated before business-led creation scales.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance] The stable factual core is that Cowork is a preview Microsoft 365 Copilot agent with action-taking capabilities, approval checkpoints, OneDrive-hosted custom skills, admin availability controls, and platform-level DLP and audit integration.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-declarative-agent; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-custom-engine-agent; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-copilot-connector; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/copilot-apis-overview] The stable factual contrast is that formal Microsoft Copilot extensibility uses packaged agents, connectors, plugins, and APIs with explicit development and deployment surfaces, which Cowork custom skills do not expose.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq; https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about] The strongest governance inference is that Cowork shifts risk from data acquisition to workflow execution, because it combines existing permissions with user-authored instructions, action surfaces, schedules, and only partial preventative controls.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/connect-to-ai-subprocessor; https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy; https://learn.microsoft.com/en-us/microsoft-365/enterprise/m365-dr-service-copilot] The strongest legal and regulatory inference is that mainstream Microsoft 365 controls still apply, but region-sensitive organizations must separately evaluate Anthropic enablement and data-boundary commitments before rollout.
- [assumption; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork] The investigation assumes that the absence of a documented per-skill registration or approval workflow in current official documentation means enterprises should govern Cowork custom skills as user-managed artifacts unless Microsoft publishes a stronger control surface. Justification: the accessible admin pages enumerate agent-level access, deployment, and pinning controls, but do not document skill-level approval, versioning, or inventory features.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq] Internal contradiction found: Microsoft's preview documentation conflicts on the custom-skill limit, with one page stating 20 and other pages stating 50.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/get-started; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://adoption.microsoft.com/en-us/copilot/frontier-program/] Internal contradiction found: Microsoft's preview documentation conflicts on rollout wording, with some pages requiring Frontier enrollment while the admin-governance page describes default tenant availability.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance] These contradictions do not change the main conclusion, because both conflicting versions still imply that Cowork is preview software whose precise operational boundaries can change quickly and must be tested in-tenant before broad rollout.
- [fact; source: https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about; https://learn.microsoft.com/en-us/purview/audit-copilot; https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy] No contradiction was found on the core control claims about DLP, audit, permission trimming, retention, or the Anthropic subprocessor, so those points carry the highest evidential stability in the item.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-declarative-agent] Technical lens: Cowork's custom layer is a low-friction instruction file, not an application package, so the technical governance problem is discovery and review of user-authored behavior, not application deployment mechanics.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/connect-to-ai-subprocessor; https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy; https://learn.microsoft.com/en-us/microsoft-365/enterprise/m365-dr-service-copilot] Regulatory lens: Cowork inherits mainstream Microsoft 365 privacy and residency commitments, but Anthropic-specific exclusions create an extra approval gate for European, United Kingdom, and public-sector environments.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/planning-guide] Economic lens: Cowork lowers the setup cost of task automation so sharply that governance overhead, permissions hygiene, and review discipline become the dominant scarce resources, not technical build capacity.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq; https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-24-business-led-low-code-agent-governance.md] Behavioral lens: because users can create skills in natural language, self-install the agent, and normalize approvals inside a conversation, Cowork is likely to spread first through convenience and local success rather than through centrally designed process change.
(This section seeds the Findings below.)
Executive summary:
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/agents-overview; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-declarative-agent] Microsoft 365 Copilot Cowork is best treated as a preview, low-friction automation layer over a prebuilt Microsoft agent, not as the same class of governed extensibility artifact as declarative agents, custom engine agents, connectors, or Copilot APIs.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about; https://learn.microsoft.com/en-us/purview/audit-copilot] The enterprise governance risk is therefore dominated by shadow procedure creation and permissions hygiene, not by undocumented new data access, because Cowork can already act across email, meetings, files, and Teams while user-created skills remain lightly governed.
- [inference; source: https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy; https://learn.microsoft.com/en-us/microsoft-365/copilot/connect-to-ai-subprocessor; https://learn.microsoft.com/en-us/microsoft-365/enterprise/m365-dr-service-copilot] Legal and regulatory exposure is manageable only if tenants explicitly account for Anthropic subprocessor settings, regional exclusions, data-residency commitments, and the documented DLP gap for uploaded files.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-24-business-led-low-code-agent-governance.md] The right enterprise posture is controlled enablement: restrict Cowork to pilot groups, remediate oversharing first, require audit and DLP coverage, and treat user-created skills as low-code artifacts subject to registration and review before scaling.
Key findings:
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq] Cowork is a preview Microsoft 365 Copilot agent that can execute multi-step work across Outlook, Teams, documents, calendar, and enterprise search, and it requires user approval before sensitive actions.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-declarative-agent; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-custom-engine-agent] Cowork custom skills are technically different from formal Microsoft Copilot extensibility because they are per-user instruction files loaded into a prebuilt agent rather than packaged agents, connectors, or custom orchestration components.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq] The main governance issue is not privilege escalation, because Cowork runs in the user's security context, but the rapid conversion of existing user permissions into repeatable automations and scheduled work.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork] Microsoft explicitly says user-created custom skills are not validated by Microsoft, which means tenant-level governance must treat skill content and outputs as user-managed artifacts rather than vendor-assured components.
- [fact; source: https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy; https://learn.microsoft.com/en-us/microsoft-365/enterprise/m365-dr-service-copilot; https://learn.microsoft.com/en-us/sharepoint/onedrive-privacy-security-overview] Microsoft's baseline privacy and residency commitments still apply, including no training on prompts or responses, permission trimming, and local-geography at-rest storage commitments for interaction content.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/connect-to-ai-subprocessor; https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/get-started] Anthropic subprocessor dependence creates a material regional governance decision because Anthropic-backed features are outside the EU Data Boundary, disabled by default in the EU, EFTA, and UK, and unavailable in government and sovereign clouds.
- [fact; source: https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about; https://learn.microsoft.com/en-us/purview/audit-copilot; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance] Microsoft supplies meaningful enterprise controls through DLP, audit logs, and group-scoped availability management, but the documented DLP inability to inspect the contents of uploaded prompt attachments leaves a concrete preventive-control gap.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/planning-guide; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-custom-engine-agent] Cowork creates moderate operational lock-in because even though a skill file is portable as Markdown text, the useful workflow depends on Microsoft-specific permissions, data locations, scheduling, approval patterns, and integrated action surfaces.
- [inference; source: https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-24-business-led-low-code-agent-governance.md; https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-22-enterprise-ai-use-case-routing-frameworks.md; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance] The defensible adoption pattern is a governed low-code rollout in which Cowork is limited to approved groups and bounded use cases until permissions cleanup, DLP coverage, audit review, and a skill registration process are demonstrably in place.
Evidence map:
| Claim | Source | Confidence | Notes |
|---|---|---|---|
| [fact] Cowork is a preview, action-taking Microsoft 365 agent with approvals for sensitive actions. | Overview, Use Cowork, FAQ | high | Direct product documentation. |
| [inference] Cowork custom skills are prompt-layer extensions, not packaged enterprise extensibility artifacts. | Use Cowork, Declarative agents, Custom engine agents | high | Strong primary-source contrast. |
| [fact] Cowork's core governance issue is fast automation of existing permissions, not new privileges. | Admin governance, FAQ | high | Official docs confirm user-context authorization. |
| [fact] Microsoft does not validate user-created custom skills. | FAQ, Use Cowork | high | Explicit limitation. |
| [fact] Baseline Microsoft 365 privacy and residency commitments still apply to Cowork interaction content. | Privacy, Data residency, OneDrive privacy | high | Multiple primary Microsoft sources agree. |
| [fact] Anthropic dependency creates region-specific legal and rollout constraints. | Anthropic subprocessor, Privacy, Get started | high | Direct official statements on exclusions and defaults. |
| [fact] DLP, audit, and group-scoped access exist, but uploaded file contents in prompts are a documented DLP gap. | DLP, Audit, Admin governance | high | Control surface and gap both documented. |
| [inference] Cowork creates moderate operational lock-in despite text-portable skill files. | Use Cowork, Planning guide, Custom engine agents | medium | Mostly structural inference from architecture. |
| [inference] Cowork should be governed as a business-led low-code automation surface. | Business-led low-code governance, Use-case routing frameworks, Admin governance | medium | Prior repository synthesis plus official control surface. |
Assumptions:
- [assumption; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork] Enterprises should assume user-created skills are unmanaged unless they build their own registry or review process. Justification: current official docs expose agent-level controls but no accessible skill-level approval or inventory mechanism.
- [assumption; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/get-started; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://adoption.microsoft.com/en-us/copilot/frontier-program/] The conflicting rollout statements are interpreted conservatively as preview instability rather than as evidence that every licensed tenant can already use Cowork without further enablement. Justification: multiple official pages disagree, so the safer enterprise reading is to verify in-tenant before planning rollout.
Analysis:
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-declarative-agent; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-custom-engine-agent] The evidence was weighted toward official Microsoft pages for architecture, controls, and legal commitments, and those pages support a clean distinction between Cowork's instruction-file model and the formal packaged extensibility surface used for enterprise agents.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about; https://learn.microsoft.com/en-us/purview/audit-copilot] Competing interpretations of Cowork as either "just another chat surface" or "a new privileged platform" were resolved by the user-context facts: it does not appear to grant new permissions, but it does materially increase the speed and repeatability with which existing permissions can be exercised.
- [inference; source: https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy; https://learn.microsoft.com/en-us/microsoft-365/copilot/connect-to-ai-subprocessor; https://learn.microsoft.com/en-us/microsoft-365/enterprise/m365-dr-service-copilot] The legal trade-off is similarly bounded: Microsoft's existing enterprise commitments remain meaningful, but Anthropic regional exclusions and data-boundary carve-outs mean regulated tenants still need explicit provider-level review rather than relying on the generic Microsoft 365 control story alone.
- [inference; source: https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-24-business-led-low-code-agent-governance.md; https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-22-enterprise-ai-use-case-routing-frameworks.md] Prior repository research was used to interpret the governance pattern, not to replace primary evidence: Cowork's shape matches a governed low-code lane more closely than a centrally engineered pro-code lane.
Risks, gaps, uncertainties:
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq] Preview instability remains a live uncertainty because Microsoft documents contradict each other on both skill limits and rollout conditions.
- [fact; source: https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about] A concrete control gap remains for files uploaded directly into prompts, because DLP does not inspect their contents before submission.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork] The accessible documentation does not show a first-party skill inventory, versioning, or approval surface, so enterprises may need compensating controls outside the product.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/connect-to-ai-subprocessor; https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy] Region-sensitive organizations still need tenant-specific validation of Anthropic toggles, data-boundary behavior, and feature availability before legal review can be considered complete.
Open questions:
- Is Microsoft planning a tenant-level inventory, approval, or versioning surface for Cowork custom skills, or are enterprises expected to govern them entirely outside the product?
- How much of Cowork's approval, schedule, and skill metadata is exportable in a form that supports formal operational review or migration?
- Will Microsoft converge the contradictory preview pages on rollout conditions and skill limits before general availability?
- Can enterprises apply more granular preventive controls to uploaded prompt attachments than the current DLP model documents?
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/agents-overview; https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy; https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about] Final review outcome: every factual or inferential claim in the Research Skill Output is labeled and source-bound, the main uncertainties are explicit, and the analysis distinguishes stable control facts from preview-specific ambiguity.
- [inference; source: https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-24-business-led-low-code-agent-governance.md; https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-22-enterprise-ai-use-case-routing-frameworks.md; https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-22-enterprise-ai-platform-operating-models.md] The synthesis is consistent with prior repository work: Cowork belongs in the governed business-led automation lane, not in an unbounded self-service lane.
(Populated from section 6 Synthesis above.)
[inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/agents-overview] Microsoft 365 Copilot Cowork is a preview, action-taking Microsoft agent whose main enterprise risk is the low-friction conversion of existing user permissions into user-authored automations, not the introduction of a wholly new extensibility stack. [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-declarative-agent; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-custom-engine-agent] It technically differs from formal Microsoft Copilot extensibility because Cowork custom skills are OneDrive-hosted instruction files loaded into a prebuilt agent, whereas declarative agents, custom engine agents, connectors, and Copilot APIs are explicit enterprise extensibility artifacts with manifests, deployment paths, or hosting models. [inference; source: https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy; https://learn.microsoft.com/en-us/microsoft-365/copilot/connect-to-ai-subprocessor; https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about] The legal and regulatory posture is manageable but conditional, because core Microsoft 365 privacy and residency commitments remain in force while Anthropic subprocessor settings, regional exclusions, and a documented DLP gap for uploaded prompt attachments require separate governance decisions. [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-24-business-led-low-code-agent-governance.md] Enterprises should therefore govern Cowork as a business-led low-code automation surface, using pilot groups, permissions cleanup, DLP, audit, and explicit registration or review of user-created skills before wider enablement.
- High confidence. [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq] Cowork is a preview Microsoft 365 Copilot agent that can execute multi-step work across Outlook, Teams, documents, calendars, and enterprise search, and it is explicitly designed to request user approval before sensitive actions.
- High confidence. [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-declarative-agent; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-custom-engine-agent] Cowork custom skills are not the same technical category as Microsoft's formal extensibility options, because they are per-user instruction files loaded into a prebuilt agent rather than packaged agents, connectors, or custom orchestration components.
- High confidence. [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq] Cowork operates in the caller's existing Microsoft 365 security context, which means the dominant risk is not hidden privilege escalation but the faster operationalization of already overshared content and already overbroad user access.
- High confidence. [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork] Microsoft explicitly states that custom skills created by users are not validated by Microsoft, so enterprises cannot treat those skills or their outputs as vendor-assured controls or reviewed business procedures.
- High confidence. [fact; source: https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy; https://learn.microsoft.com/en-us/microsoft-365/enterprise/m365-dr-service-copilot; https://learn.microsoft.com/en-us/sharepoint/onedrive-privacy-security-overview] Microsoft's baseline privacy, retention, and residency commitments still apply to Cowork interaction content, including no training on prompts or responses, permission trimming, and local-geography storage commitments for interaction data at rest.
- High confidence. [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/connect-to-ai-subprocessor; https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/get-started] Anthropic subprocessor dependence creates a material regional governance decision because Anthropic-backed features are outside the EU Data Boundary, disabled by default in the EU, EFTA, and UK, and unavailable in government and sovereign clouds.
- High confidence. [fact; source: https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about; https://learn.microsoft.com/en-us/purview/audit-copilot; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance] Microsoft supplies meaningful enterprise controls through DLP, audit logs, and group-scoped availability management, but the documented DLP inability to inspect the contents of uploaded prompt attachments leaves a concrete preventive-control gap.
- Medium confidence. [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/planning-guide; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-custom-engine-agent] Cowork creates moderate operational lock-in because even though a skill file is portable as Markdown text, the useful workflow depends on Microsoft-specific permissions, data locations, scheduling, approval patterns, and integrated action surfaces.
- Medium confidence. [inference; source: https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-24-business-led-low-code-agent-governance.md; https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-22-enterprise-ai-use-case-routing-frameworks.md; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance] The defensible adoption pattern is a governed low-code rollout in which Cowork is limited to approved groups and bounded use cases until permissions cleanup, DLP coverage, audit review, and a skill registration process are demonstrably in place.
| Claim | Source | Confidence | Notes |
|---|---|---|---|
| [fact] Cowork is a preview, action-taking Microsoft 365 agent with approvals for sensitive actions. | Overview; Use Cowork; FAQ | high | Direct product documentation. |
| [inference] Cowork custom skills are prompt-layer extensions, not packaged enterprise extensibility artifacts. | Use Cowork; Declarative agents; Custom engine agents | high | Strong primary-source contrast. |
| [fact] Cowork's core governance issue is fast automation of existing permissions, not new privileges. | Admin governance; FAQ | high | Official docs confirm user-context authorization. |
| [fact] Microsoft does not validate user-created custom skills. | FAQ; Use Cowork | high | Explicit limitation. |
| [fact] Baseline Microsoft 365 privacy and residency commitments still apply to Cowork interaction content. | Privacy; Data residency; OneDrive privacy | high | Multiple primary Microsoft sources agree. |
| [fact] Anthropic dependency creates region-specific legal and rollout constraints. | Anthropic subprocessor; Privacy; Get started | high | Direct official statements on exclusions and defaults. |
| [fact] DLP, audit, and group-scoped access exist, but uploaded file contents in prompts are a documented DLP gap. | DLP; Audit; Admin governance | high | Control surface and gap both documented. |
| [inference] Cowork creates moderate operational lock-in despite text-portable skill files. | Use Cowork; Planning guide; Custom engine agents | medium | Mostly structural inference from architecture. |
| [inference] Cowork should be governed as a business-led low-code automation surface. | Business-led low-code governance; Use-case routing frameworks; Admin governance | medium | Prior repository synthesis plus official control surface. |
Explicit assumptions made during the investigation and the justification for each.
- Assumption: [assumption; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork] Enterprises should assume user-created skills are unmanaged unless they build an internal registry or review workflow. Justification: accessible Microsoft documentation describes agent-level controls but no first-party skill approval or inventory mechanism.
- Assumption: [assumption; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/get-started; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://adoption.microsoft.com/en-us/copilot/frontier-program/] The conflicting availability pages are safer to read as preview inconsistency than as proof of universal tenant readiness. Justification: primary sources disagree, so conservative rollout planning requires tenant validation.
[inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-declarative-agent; https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-custom-engine-agent] The evidence was weighted toward official Microsoft pages for architecture, controls, and legal commitments, and those pages support a clean distinction between Cowork's instruction-file model and the formal packaged extensibility surface used for enterprise agents. [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about; https://learn.microsoft.com/en-us/purview/audit-copilot] Competing interpretations of Cowork as either "just another chat surface" or "a new privileged platform" were resolved by the user-context facts: it does not appear to grant new permissions, but it does materially increase the speed and repeatability with which existing permissions can be exercised. [inference; source: https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy; https://learn.microsoft.com/en-us/microsoft-365/copilot/connect-to-ai-subprocessor; https://learn.microsoft.com/en-us/microsoft-365/enterprise/m365-dr-service-copilot] The legal trade-off is similarly bounded: Microsoft's existing enterprise commitments remain meaningful, but Anthropic regional exclusions and data-boundary carve-outs mean regulated tenants still need explicit provider-level review rather than relying on the generic Microsoft 365 control story alone. [inference; source: https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-24-business-led-low-code-agent-governance.md; https://github.com/davidamitchell/Research/blob/main/Research/completed/2026-04-22-enterprise-ai-use-case-routing-frameworks.md] Prior repository research was used to interpret the governance pattern, not to replace primary evidence: Cowork's shape matches a governed low-code lane more closely than a centrally engineered pro-code lane.
- [fact; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-faq] Preview instability remains a live uncertainty because Microsoft documents contradict each other on both skill limits and rollout conditions.
- [fact; source: https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about] A concrete control gap remains for files uploaded directly into prompts, because DLP does not inspect their contents before submission.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-admin-governance; https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/use-cowork] The accessible documentation does not show a first-party skill inventory, versioning, or approval surface, so enterprises may need compensating controls outside the product.
- [inference; source: https://learn.microsoft.com/en-us/microsoft-365/copilot/connect-to-ai-subprocessor; https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy] Region-sensitive organizations still need tenant-specific validation of Anthropic toggles, data-boundary behavior, and feature availability before legal review can be considered complete.
- Should the repo add a dedicated backlog item on how enterprises should inventory, review, and retire Cowork custom skills when Microsoft does not yet expose clear first-party skill governance?
- What export and migration path exists for scheduled prompts, custom skills, and conversation metadata if an enterprise later moves away from Cowork?
- How should enterprises classify Cowork tasks that bridge multiple sensitivity zones, such as combining internal documents with customer-facing messaging, within a formal intake process?
(Produced from this research.)
- Type: knowledge
- Description: Research note defining Cowork's architecture, differentiating it from Microsoft's formal Copilot extensibility model, and synthesizing the enterprise governance, legal, lock-in, and shadow IT implications.
- Links:
Navigation
By Tag
bureaucracy
change-management
coase
constraint-analysis
control-model
decision-rights
delegation
- Q4: Decision rights that should move closer to execution
- Q5: Control model for the best throughput-risk trade-off
delivery-risk
- Operating model synthesis for split-authority delivery systems
- Q6: Leading indicators of instability in split-authority flow systems
demand-segmentation
enterprise
exception-handling
execution
flow
flow-design
flow-metrics
governance
- Operating model synthesis for split-authority delivery systems
- Q1: Dominant flow constraint in split-authority delivery systems
- Q2: Demand segmentation for fast-path vs controlled-path flow
- Q4: Decision rights that should move closer to execution
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
governance-patterns
incentives
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
instability
institutional-economics
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
leading-indicators
operating-model
organisation
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
organisational-design
queue-design
queueing
regulated-enterprise
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
routing
throughput
throughput-risk
transaction-costs
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
triage
- Q2: Demand segmentation for fast-path vs controlled-path flow
- Q3: Routing design that isolates exceptions from routine flow
williamson