Key takeaways
- The four things. A written scope, a log, a tested off switch, and a named owner. If any one is missing you do not have a governed agent, you have a hope.
- It is product-neutral. The same page works for a Copilot Autopilot, a Claude Cowork task, a Claude Tag in Slack, a Copilot Studio agent or a Zapier flow. The product changes; the four questions do not.
- Who owns it. Not the person most excited about the agent. The owner is whoever would be asked "why did it do that?" and has the authority to switch it off without asking permission.
- Start with what exists. Most businesses already have agents nobody registered. Step one is finding them, using the 30-minute audit from our Anthropic post.
- Where training fits. Builders learn this as a build skill on the Level 4. The person who has to sign the page off and say no is the AU0010 leadership unit.
An agent is any AI that acts rather than answers: sends, files, approves, updates a system, replies to a customer, watches an inbox and decides what matters. In September 2026 that capability moved from something a developer set up to something a regional manager creates by typing a goal into a box. Microsoft's demo agent, "Dot", was given one instruction, make sure stores have stock for Black Friday, and then chose for itself which Teams channels, email threads and inventory data to monitor. That is useful. It is also a decision about what a piece of software is allowed to read and do in your business, made by nobody.
You do not need an AI policy to govern agents. You need one page per agent, four headings, and a person whose name is at the bottom.
The four things, and what "done" looks like for each
| What it is | What "done" looks like | What "not done" looks like | |
|---|---|---|---|
| Scope | A written statement of what the agent may read, what it may do, and what it must hand to a person. | Three lists: reads (which systems, which data), does (which actions, with limits), escalates (what it must never do alone: send money, delete records, email customers, change a booking). Reviewed when the agent's job changes. | "It helps the ops team." A goal typed into a box. Permissions inherited from whoever built it. |
| Log | A record of what the agent did, when, on what data, that a person can read after the fact. | Every action and the input that triggered it, kept for a defined period, readable by someone other than the builder. Checked weekly for the first month, then monthly. | "The vendor keeps logs somewhere." Nobody has opened them. Nobody knows how to. |
| Kill switch | A way for a named person to stop the agent immediately, without the builder, without breaking the rest of the process. | Runs under an identity or connection that can be disabled in one step. A written off-procedure that someone other than the builder has tested. A note of what stops when it stops, so the manual fallback is known. | "We'd ask Dave." Dave is on leave. The agent runs under Dave's login. |
| Owner | The person who answers "why did it do that?" and can switch it off without asking permission. | One name, not a team. Senior enough to stop it, close enough to the work to notice it going wrong. Named on the page. Told they own it. | "The team." "IT." The person who built it, who has since changed roles. |
Agent name and product. Purpose in one sentence. Reads: systems and data. Does: actions and limits. Escalates: what it must hand to a person. Log: where, how long, who checks, how often. Off switch: how, who, last tested on. What stops when it stops. Owner: name, role, date signed. Review date. That is the whole document. If it does not fit on a page, the agent's scope is too wide.
Applying it to what your staff can now create
The reason to make the page product-neutral is that your business will have several of these, from several vendors, by Christmas. Here is how the four things map onto the agents that launched this month.
| Copilot Autopilot | Claude Cowork | Claude Tag in Slack | |
|---|---|---|---|
| What it is | Always-on agent inside your Microsoft 365 environment with its own identity, memory and email address. Colleagues tag it in Teams. Private preview. | A long-running task handed to Claude inside a conversation, which keeps working after you close the laptop. Now built into every Claude plan. | @Claude in a Slack channel, now with personal connectors, in review-before-posting or auto mode. |
| Scope | Its own identity is the scope lever: grant it the permissions of a junior colleague, not of its creator. Microsoft's Agent 365 tools manage it like a user. | Scope is the connectors and files it can reach. Use a project with a defined library rather than "everything I have access to". | Review mode is scope. Auto-posting to a channel with customers in it is a decision, not a default. |
| Log | Microsoft 365 audit log under the agent's identity. Someone has to look at it. | The conversation and task history. Export or record what it changed, not only what it said. | The Slack channel is the log, which is convenient and public. Decide who reads it. |
| Kill switch | Disable the identity. Test that it stops the agent and does not break a workflow that depended on its email address. | Revoke the connector or stop the task. Know what half-finished state that leaves. | Remove from the channel. Simple, but make sure nobody else re-adds it. |
| Owner | Not whoever typed the goal. The manager of the process the agent runs. | The person who handed over the task. Fine for one task; for a recurring one, name the process owner. | The channel owner, in writing. |
| Billing | Usage-billed, off by default, admin caps per user or group. The owner needs to know the cap. | Plan-based. | Plan-based. |
Start with the agents you already have
Most businesses that ask us about agent governance are picturing the ones they are about to build. The urgent ones are the ones already running: the Zapier flow the marketing team set up in March that posts to LinkedIn, the Power Automate that files invoices, the chatbot on the website a supplier configured. The 30-minute audit in our Anthropic post finds them: per function, which tools, what data, does anything act automatically, who owns it, how is it switched off. Every "yes" in the "acts automatically" column gets a page.
Find them
Do: run the audit with each head of function. Include personal accounts and free tiers.
Why: the agent that hurts you is the one nobody registered.
Page the live ones first
Do: one page each for anything already acting, starting with whatever touches customers or money.
Why: the gym's agent changed bookings it should never have touched because nobody had written down that it should not.
Test every kill switch once
Do: have someone other than the builder switch each agent off and on, and write down what happened.
Why: an untested off switch is a theory. Half of them turn out to run under someone's personal login.
Make the page the gate for new ones
Do: no agent goes live without a signed page. That is the whole approval process.
Why: it takes twenty minutes, and it is the difference between a governed agent and a hope.
Name who can say no
Do: one person in the business, or one per function, who can reject an agent on governance grounds.
Why: if nobody can, the page is decoration.
Who in the business does this
Two roles, and they are rarely the same person. The builder writes the scope and sets up the log and off switch, because they know what the agent actually does. The owner reads the page, asks the awkward questions, and signs it, because they will be the one explaining it. Both need training that most businesses have not yet given them.
Where the programmes fit
Builders learn it as a build skill. Owners learn it as a decision skill.
On our AI & Automation Practitioner Level 4, the Month 4 agent does not go live until the apprentice has written its safety case: guardrails, monitoring, kill switch, escalation paths. That is this page, learned by doing, in whichever tools your business runs: the Copilot edition covers Copilot Studio and, as it rolls out, Autopilot; the Claude edition covers Cowork, Claude Code and Claude Tag; the agentic AI focus is for teams whose first job is building and governing agents.
For the person who signs the page, AU0010, AI Adoption, Procurement & Governance is a four-week Level 5 leadership unit on vendor selection, governance frameworks and what stays in the building, £750 per leader from the levy and fully funded for non-levy employers. It is designed for the owner, not the builder.
Send us your list of agents, or the one you are most worried about. We will send back a completed page for it, tell you which of the four things is missing, and say whether the fix is training, a process change, or switching it off. 30 minutes, no obligation.
Book a conversation →The honest summary
- The four things: scope, log, kill switch, owner. One page per agent.
- Product-neutral: Autopilot, Cowork, Tag, Zapier, Power Automate. Same page.
- Start with: the agents already running, especially the ones touching customers or money.
- Two roles: the builder writes it, the owner signs it. Train both.
Frequently asked questions.
What counts as an AI agent for governance purposes?
Anything that acts rather than only answers: sends messages or emails, files or updates records, approves or rejects, replies to customers, monitors data and takes action on it, or runs a multi-step task without a person confirming each step. That includes Copilot Autopilot, Claude Cowork tasks, Claude Tag in Slack, Copilot Studio agents, and no-code flows in Zapier, Make, n8n or Power Automate. A chatbot that only answers questions is lower risk; the moment it can change a booking, it is an agent.
What is a kill switch in practice?
A way for a named person to stop the agent immediately, without needing the person who built it, and without breaking the rest of the process. Concretely: the agent runs under an identity or connection that can be disabled in one step; there is a written off-procedure that someone other than the builder has tested; the agent cannot take irreversible actions such as sending money or emailing customers without a human step; and there is a log so you can see what needs unpicking once it is stopped.
Who should own an AI agent?
The manager of the process the agent runs, not the person who built it and not IT by default. The owner is whoever would be asked why the agent did something, and must have the authority to switch it off without asking permission. One name, in writing, with a review date. If the builder changes role, the page moves with the process, not the person.
Do we need ISO 42001 or a full AI policy before doing this?
No. ISO 42001 is a useful management-system framework and we teach it, but the one-page-per-agent approach is what a policy would require anyway, and you can start it this week. A policy without pages is a document; pages without a policy are governance. Do the pages first and write the policy from what they have in common.
How is Copilot Autopilot different from earlier Copilot agents?
Autopilot is Microsoft's name, launched 25 September 2026, for always-on agents that users create and name themselves. Each runs in the cloud inside your Microsoft 365 environment with its own identity, memory and email address, and can be tagged in Teams or Outlook like a colleague. It grew out of Microsoft's work on OpenClaw, which Satya Nadella earlier described as a security risk akin to a virus. It is in private preview and billed by usage, off by default with admin spending caps. The four things apply exactly as they would to any other agent; the identity is the main scope and kill-switch lever.
Which training covers this?
For the people building agents, the Level 4 AI and Automation Practitioner apprenticeship, where the Month 4 agent ships with a documented safety case, in Copilot, Claude or Gemini editions. For the person who signs the page and says no, the AU0010 AI Adoption, Procurement and Governance leadership unit, a four-week Level 5 unit at 750 pounds per leader from the levy.
Sources: Microsoft Copilot Autopilot description, executive quotations and billing model as reported by GeekWire, 25 September 2026; Claude Cowork merger and Claude Tag personal connectors as indexed by Releasebot, 16 and 24 September 2026; the gym incident as covered in our August post. The four-things framework and one-page template are ours. TESS Group delivers AI apprenticeships and leadership units and has a commercial interest in employers choosing structured training. TESS uses Claude, among other tools, in its own work, including in the drafting of this article.