#copilot
What we learn moving organisations onto the Microsoft cloud. Method, not opinion.

A Copilot agent manifest is a security boundary. Here is the linter for it.
Every scoping property in a Microsoft 365 Copilot agent manifest is optional, and in six places omitting one grants the widest scope instead of the narrowest. A JSON Schema validator approves those manifests, because nothing in them is invalid: something optional is missing. So we wrote the check that does catch it. It finds six problems in a manifest that passes every other test.

What to put in order before switching Copilot on
Copilot does not create permission problems. It makes the ones already there findable, and you no longer need to know what you are looking for.
Nothing matches your search.
