Skip to main content

Companion annex

Who Owns the Agent?

Enterprise AI Accountability on the Microsoft Stack

This companion page keeps the print book connected to the platform details that move faster than a book can. It preserves the parts readers need to verify, fill in, copy, and revisit as Microsoft documentation changes.

Standing framing note

This page maintains, against current Microsoft documentation, the details that move faster than a print schedule can track: console procedures and admin center paths, license tier names and plan boundaries, preview statuses, capability details the book deliberately kept out of print, and corrections to the first edition.

Primary documents move on their publishers' schedules, not the author's. The modules below are built to be updated one detail at a time as those primary sources change.

Each platform module carries a verification date so readers can tell whether they are looking at a recently checked value or an older standing reference. The intended re-verification cadence is monthly, with urgent updates made when Microsoft publishes a retirement, GA, preview, licensing, or admin-center change.

Fast-moving platform detail

Microsoft platform details to verify before use

Each module captures the exact product name, documented release status, current admin center or portal path, and the canonical source page checked for the book companion annex.

Release status is the weakest column here. When the cited primary source does not state preview or general availability, the module says so rather than filling the gap from secondary coverage.

Maintained registry

These eight platform modules draw from the maintained Microsoft Product Registry. Use the registry for the current product name and verification record behind the annex modules.

Open the Microsoft Product Registry

Chapter 4

Exact product name

Microsoft 365 Copilot

Documentation distinguishes this from Microsoft 365 Copilot Chat, which requires no add-on license.

Verified August 15, 2026.
Release status as documented
Microsoft 365 Copilot is documented as an add-on plan with licensing prerequisites. The service description was last updated August 5, 2026 and lists commercial availability for Microsoft 365 Copilot features, with cloud-specific differences.
Admin center or portal path
Microsoft 365 admin center setup guidance is linked from the licensing page. The cited service description does not publish a single governance screen path.

Governance gap: this surface proves a user can use Copilot features under existing Microsoft 365 permissions and licensing; it does not prove that an agent, prompt, or delegated action was authorized by a named business owner before use.

Chapter 5

Exact product name

Microsoft Copilot Studio

Page title reads Copilot Studio overview; the legal notice uses the Microsoft-prefixed form.

Verified August 15, 2026.
Release status as documented
The Workflows flows format is stated as in public preview; no status label appears for the product overall. Documentation notes that after the end of June 2026 the Copilot Studio for Teams app can no longer create classic chatbots.
Admin center or portal path
Standalone web app at copilotstudio.microsoft.com.

Governance gap: Copilot Studio can build and administer agents, but the product record is not the same as an authorization decision naming who accepted the business scope, prohibitions, and review triggers.

Chapter 6

Exact product name

Power Platform and Power Automate

Power Platform admin center is the governance console for Power Apps, Power Automate, Power Pages, Microsoft Copilot Studio, and some Dynamics 365 apps.

Verified August 15, 2026.
Release status as documented
Not documented on the cited page.
Admin center or portal path
admin.powerplatform.microsoft.com. The CoE Starter Kit transition page maps governance work to Inventory, Usage, Monitor, and Actions in Power Platform admin center.

Change recorded: Microsoft says the Power Platform CoE Starter Kit is no longer actively maintained, and that core capabilities are moving into Power Platform admin center. Governance gap: inventory and actions can reveal what exists; they do not by themselves prove a pre-operation authorization record exists.

Chapter 7

Exact product name

Microsoft Foundry

Verified August 15, 2026.
Release status as documented
Not labeled preview or GA on the cited page. Documentation records a brand evolution: Azure AI Studio and Azure AI Foundry are now Microsoft Foundry, Azure AI Services is now Foundry Tools, and hub-based projects live in a separate Foundry (classic) portal.
Admin center or portal path
Foundry portal at ai.azure.com.

Governance gap: Foundry governs the AI development surface. It does not prove that a business authority approved the operational purpose, permitted actions, explicit prohibitions, or renewal conditions for the deployed agent.

Chapter 8

Exact product name

Agent 365

Documented as the control plane for IT and security leaders to observe, secure, and govern agents.

Verified August 15, 2026.
Release status as documented
Not documented as preview or GA on the cited documentation page. Licensing is documented: available as a standalone subscription for eligible Microsoft 365 subscriptions and included with Microsoft 365 E7.
Admin center or portal path
Microsoft 365 admin center, Agents > Overview.

Change recorded: the Microsoft 365 agent registry documents Critical risk types including Shadow agent and No owner assigned. Governance gap: the registry can surface risk and ownership signals; it cannot retroactively create the business authorization that should have preceded operation.

Chapter 12

Exact product name

Microsoft Entra Agent ID

Verified August 15, 2026.
Release status as documented
Documentation states Agent ID is available for all Microsoft Entra customers, with no preview label. Tenant Governance status is resolved: Microsoft announced in the Microsoft Entra Blog post "Microsoft Entra Tenant Governance is now generally available" that Microsoft Entra Tenant Governance reached general availability on August 10, 2026. Microsoft Learn still showed preview language on August 15, 2026, which is recorded as documentation lag rather than an unresolved status conflict.
Admin center or portal path
Microsoft Entra admin center paths vary by Agent ID task; the cited overview does not publish one consolidated governance path.

Governance gap: Entra Agent ID can identify and secure agent identities. It does not answer who approved the agent's purpose or who accepted the business consequence of the action.

Chapter 13

Exact product name

Microsoft Purview

Capability names as written are Data Security Posture Management and Data Security Posture Management for AI (classic).

Verified August 15, 2026.
Release status as documented
Not documented on the cited page. Documentation states that managing these AI interactions might require enabling pay-as-you-go billing. Restricted SharePoint Search documentation, last updated July 6, 2026, says new enablement is blocked from July 31, 2026.
Admin center or portal path
Documented as in-product locations rather than a navigation path. Listed agents each have a dedicated Apps and agents page, and Data Security Posture Management has an additional AI observability page supporting Agent 365.

Governance gap: Purview can apply data-security, DLP, audit, and posture controls to supported AI interactions. It cannot prove that an agent's business intent remained authorized after the data environment or Microsoft control surface changed.

Chapter 17

Exact product name

Microsoft Agent Governance Toolkit

Published under the microsoft GitHub organization, abbreviated in-repo as AGT.

Verified August 15, 2026.
Release status as documented
README states public preview, production-quality Microsoft-signed releases, may have breaking changes before GA. MIT license.
Admin center or portal path
Not applicable, not a Learn-documented product. Documentation site at microsoft.github.io/agent-governance-toolkit.

Governance gap: the toolkit can help structure review work, but a toolkit output is not a signed authorization unless the organization binds it to a named authority and record-retention process.

Vocabulary of accountability

The eleven terms printed in the book

These entries mirror the printed front-matter spread. Shared industry terms are marked so the page does not present common language as original coinage.

Defined in the book

These terms are defined in Who Owns the Agent?. The annex preserves the printed definitions and keeps the supporting online records connected to the book.

Agent Authorization

Original

First public use: March 20, 2026

What it is
A decision, made before an agent operates, by a named person with the standing to make it, that this identified agent may act for a stated purpose within defined permissions, prohibitions, and review conditions.
What it is not
Not an identity, not a licence, not a connector consent, not a deployment. Each of those is something the organization did. This is something the organization decided.
The evidence it produces
A dated record bound to the agent's stable technical identifier, signed before the agent went to production.
Who is accountable
The approving authority for the decision itself, with the business owner and the technical operator accountable only for the parts of the record assigned to them by name.
The examination question it answers
What decision allowed this agent to begin operating, and who had the authority to make it?
Open vocabulary record

The Authorization Layer

Original

First public use: March 20, 2026

What it is
The layer of decisions that has to exist above a platform's controls: who decided this agent should operate, within what bounds, and on whose authority.
What it is not
Not a product, not a console, and not a control. No vendor ships it, because it is made of decisions rather than settings.
The evidence it produces
A dated, signed record naming a person, a scope, and a reconsideration trigger.
Who is accountable
The business authority with standing to accept the risk, not the team that built or administers the agent.
The examination question it answers
Who authorized this, and can you show me the decision rather than the configuration?
Open vocabulary record

The Authorization Record

Original

First public use: March 20, 2026

What it is
The single artifact that carries an agent's purpose, permitted actions, explicit prohibitions, data scope, accountable people, review triggers, and a signature that predates production.
What it is not
Not a change ticket, not an intake form, and not a deployment approval. Those record that something was done. This records that someone accepted it.
The evidence it produces
Itself. It is the evidence, which is why an undated one is worth nothing.
Who is accountable
The named signer, until the authorization is renewed, narrowed, or withdrawn. A successor acquires the role by transfer and the accountability only by signing again.
The examination question it answers
Show me the record of a named human being who understood this scope, weighed it, and accepted it.
Open vocabulary record

The Accountability Assumption

Original

First public use: March 20, 2026

What it is
The condition in which every function believes another function owns an agent's risk, and the belief is unanimous, reciprocal, and unwritten.
What it is not
Not negligence, and not a gap in the org chart. Every party is behaving reasonably; the failure is that reasonable behavior does not intersect anywhere.
The evidence it produces
None, and that absence is the diagnostic. The assumption is visible only as a missing record.
Who is accountable
The organization, without exception. Internally, no named person has accepted it, and that absence is the finding.
The examination question it answers
When four teams each name a different owner, which answer does the organization stand behind?
Open vocabulary record

Intent Architecture

Original

First public use: March 20, 2026

What it is
The practice of writing down what an agent is for, and what it may not do, before it is capable of doing anything.
What it is not
Not prompt engineering and not system instructions. Those tell a model how to behave. This tells the organization what it has agreed to.
The evidence it produces
A purpose statement and a prohibition list that were authored before deployment and can be shown to predate it.
Who is accountable
The business owner who defined the purpose, jointly with whoever approved the prohibitions.
The examination question it answers
What was this agent supposed to do, according to a document written before it did anything?
Open vocabulary record

The Chain Authorization Gap

Original

First public use: March 20, 2026

What it is
The condition in which each agent in a multi-agent chain is individually approved, no one approved the chain, and the original approval travels the whole length unrevisited.
What it is not
Not a permissions failure. Every hop is permitted. The aggregate authority is what no one granted.
The evidence it produces
A chain-level record produced before the chain runs, answering origin, authority, delegation, and effect boundary, with the trigger list that reopens it.
Who is accountable
The authority over the business process the chain executes, not the owner of any single agent in it.
The examination question it answers
Who approved what these agents can do together, as opposed to separately?
Open vocabulary record

Tenant Agent Reconciliation

Original

First public use: March 20, 2026

What it is
The periodic exercise of comparing every agent the platform can see against every agent the organization has authorized, and dispositioning the difference.
What it is not
Not an inventory. An inventory counts. Reconciliation compares two counts and forces a decision about each discrepancy.
The evidence it produces
A dated reconciliation report with a named disposition for every unmatched agent.
Who is accountable
The function that holds the authorization register, which must not be the function that operates the platform.
The examination question it answers
How many agents are running, how many did you authorize, and what did you do about the difference?
Open vocabulary record

The Authorization Coverage Lifecycle

Original

First public use: March 20, 2026

What it is
The path an organization travels from not knowing what it runs, to knowing, to preventing new unauthorized deployment faster than it accumulates.
What it is not
Not a maturity score and not a certification. It describes a condition, and organizations move backward through it without noticing.
The evidence it produces
A ratio: authorized agents over discovered agents, measured on a date, trending.
Who is accountable
Whoever owns the intake gate, because that is where the direction of travel is decided.
The examination question it answers
Is your authorized population growing faster or slower than your actual population?
Open vocabulary record

The Disposition Protocol

Original

First public use: March 20, 2026

What it is
The standing rule that every signal about an agent, whether a change, a failure, a departure, or a platform announcement, receives a recorded decision rather than a reaction.
What it is not
Not incident response and not change management. Those handle events. This handles the question of whether an authorization still holds after the event.
The evidence it produces
A disposition entry per signal: renewed, narrowed, suspended, retired, or accepted as-is, with a date and a name.
Who is accountable
The original signer where they remain in role, and an explicitly named successor where they do not.
The examination question it answers
This changed in March. Who decided the approval still stood, and when?
Open vocabulary record

Agent Sprawl

Shared term

A shared industry term. What this book adds is its measurement against an authorization register rather than against an inventory.

What it is
The accumulation of agents faster than any function can account for them.
What it is not
Not shadow IT renamed. Most sprawl is sanctioned, licensed, and visible. It is unauthorized, not unknown.
The evidence it produces
The gap between the platform's count and the register's count.
Who is accountable
Whoever permitted creation without an intake step, which is usually no one in particular.
The examination question it answers
Of the agents running today, how many entered through a gate?
Open vocabulary record

The Intent Gap

Shared term

A shared industry term. What this book adds is its application to agent authorization, where the gap sits between what was approved and what the agent now does.

What it is
The distance between what a system was intended to do and what it actually does.
What it is not
Not model drift. The model may be unchanged. The gap opens because the environment moved underneath a frozen decision.
The evidence it produces
A comparison of current behavior against the purpose statement in the authorization record.
Who is accountable
The reviewer named in the record, whose job is to notice that the two no longer match.
The examination question it answers
Does this agent still do what the approval said it would do?
Open vocabulary record

Digital Appendix A

Agent Authorization Record

The printed Appendix A is a blank one-page form. This digital version keeps the same fields in the same order so a team can fill it in during review, copy the labels into an internal workflow, or adapt it into its own control record.

If Explicit Prohibitions is blank, this record is incomplete.

This is a base template, meant to be adapted into the organization's own governance forms, not adopted verbatim. If Explicit Prohibitions is blank, this record is incomplete.

Adapted from Sougata Roy, "Agent Authorization Document," The Authorization Layer framework library, DOI 10.5281/zenodo.21245690, CC BY 4.0.

Open Zenodo DOI(opens in new tab)

Corrections log

Errata and updates

Corrections will be appended here as dated entries, with the page or chapter reference, what changed, and why the change was made.

Corrections log
DatePage or chapterWhat changedWhy
No corrections recorded as of August 15, 2026.

Framework-to-source mapping

Where each framework stands on the public record.

Every named framework in Who Owns the Agent? is the author's synthesis. None is a regulator's formal construct, and no agency should be read as having defined or endorsed any of them. The table below shows the public documents each framework is built to answer, so a reader can check the pattern against the record it stands on.

Framework-to-source mapping for Who Owns the Agent?
FrameworkPublic record it stands on
The Accountability AssumptionMoffatt v. Air Canada, 2024 BCCRT 149; Mobley v. Workday, Inc. (N.D. Cal.); FINRA, Emerging Trend in GenAI: Observations on AI Agents, January 27, 2026.
The Authorization LayerRoyal Commission into the Robodebt Scheme, Final Report, July 7, 2023; Federal Reserve SR 26-2; Regulation (EU) 2024/1689, Article 9; NIST NCCoE draft concept paper on agent identity and authorization.
Intent Architecture StackZillow Group Q3 2021 shareholder letter, Form 8-K; NIST AI Risk Management Framework; NIST NCCoE conveyance and logging questions.
Chain Authorization GapFINRA, Observations on AI Agents, scope and authority language; CISA and Five Eyes joint guidance on sub-agent spawning; NIST AI Agent Standards Initiative, February 17, 2026.
Authorization Coverage LifecycleFederal Reserve SR 26-2; federal banking agency examination manuals; EU AI Act high-risk obligations.
Disposition ProtocolSEC, In re Knight Capital Americas LLC, 2013; Earnest assurance of discontinuance; signal-source documentation.
Organizational Agent ControlsMicrosoft Learn documentation for Microsoft Entra Agent ID, Agent 365, and Microsoft Purview; UpGuard, By Design, on Power Apps disclosure.
Tenant Agent ReconciliationMicrosoft Entra Agent ID documentation; Agent 365 registry documentation.
Deployment Accountability MapMicrosoft shared responsibility documentation; Cyber Safety Review Board, Storm-0558 report; Cyber Safety Review Board, Log4j report.
Agent Substrate Readiness ModelMicrosoft Learn platform documentation; MSRC and CVE record for EchoLeak, June 11, 2025; Black Hat 2024 session record.
Governance Readiness MatrixMicrosoft Entra Agent ID documentation; Microsoft Agent Governance Toolkit, May 14, 2026.

Governance Debt, Agent Sprawl, and Intent Gap are shared industry terms, not this book's coinage. The book's contribution is their operationalization for agentic deployments on the Microsoft stack. Every named framework above is the author's synthesis. None is a regulator's formal construct, and no agency should be read as having defined or endorsed any of them.

Related research

Read the companion research library

The annex points back to the research record behind the book: the book page, the white paper, the authorization framework library, and the reusable governance record.