The Question
Chapters 1-3
- 01The Examiner Walks In
- 02The Accountability Assumption in Microsoft Environments
- 03Why Microsoft Defaults Don't Answer Who Owns the Agent

The Book | First Edition 2026
Enterprise AI Accountability on the Microsoft Stack
Your tenant can prove what the agent did. Proving it was allowed to is a different record, and almost nobody has written it.
The question the book is about
She is not asking for logs. She has those. She is asking for the name of the person who decided this agent could read that mailbox, the date they decided it, and the scope they approved.
Enterprise AI agents now read email, move money, file tickets, and call other agents. Most were authorized once, by someone who has since changed roles, for a scope that no longer describes what the agent does. The record of the action survives. The record of the authorization was never created.
This book maps what Microsoft 365 Copilot, Copilot Studio, Power Platform, Microsoft Foundry, Agent 365, Microsoft Entra Agent ID, and Microsoft Purview can actually prove about agent authorization, where the gaps sit, and what has to be built on top of them.
The question is not whether your agents are governed. It is whether anyone could prove it on demand.
Contents
Every chapter opens on a documented failure and closes on the question that failure leaves behind. Chapters can be read out of order without losing the argument.
Chapters 1-3
Chapters 4-9
Chapters 10-13
Chapters 14-17
Chapters 18-20
What it builds
Each framework arrives as the answer to a documented failure. Each is published openly and separately in The Authorization Layer library, so a team can cite it without buying the book.
The three organizational layers that have to exist before any agent goes live.
One approval, granted once, still covering a multi-agent chain nobody has revisited.
The belief that accountability sits with the platform, and what it costs when tested.
What your tenant contains, measured against what your organization approved.
Keeping approvals current while the agents underneath them change.
Converting detection signals into recorded governance decisions.
Also inside: the Organizational Agent Controls, the Deployment Accountability Map, the Agent Substrate Readiness Model, and the Governance Readiness Matrix. Open the framework library
Appendix A
One page. Ten entries. One record per deployed agent, retained as evidence.
No diagrams, no YAML, no hexadecimal beyond a single identifier string. It is the least technical artifact in the book and the one that has been missing from every chapter of it.
Who it is for
Answering for agent behavior in environments they did not approve agent by agent.
Designing the layer beneath the Microsoft agent estate.
Examination readiness when the evidence request is about authorization, not activity.
Deploying agents faster than the governance record is being written.
Written for banks, insurers, healthcare systems, and government contractors. No vendor marketing. No futurism.

Sourcing standard
Every Microsoft capability claim in the book was verified against published Microsoft documentation and carries the date it was checked. Every incident comes from a named primary source. Nothing is drawn from confidential or nonpublic information.
Platform detail moves faster than a print schedule can track. Console paths, license boundaries, preview status, and corrections to this edition are maintained in the companion annex, updated one detail at a time as the primary sources change. Open the companion annex
The author
Technology manager and enterprise AI governance researcher, with 26 years inside enterprise systems and 13 years on federal engagements at agencies including the SEC, CFTC, and NIH as a contractor.
He publishes The Governance Gap, a weekly newsletter on enterprise AI accountability, and maintains The Authorization Layer, an open framework library on authorization architecture. Views expressed are his own and do not represent any employer, client, or agency.
Portions of this book adapt and extend previously published work: the white paper Who Owns the Agent? The Intent Architecture Stack (May 2026, DOI 10.5281/zenodo.20481551) and The Authorization Layer framework library (July 2026, DOI 10.5281/zenodo.21245690).
It is the same document either way.