1300 CODIFY

Copilot Is the Latest Tech Toy, and IT Holds the Controls: A Practical Guide to Copilot Cowork Governance

by | 29 Sep, 2026 | Blog

Remember when everyone wanted a laptop, but nobody wanted to decide who actually needed one? Manager approvals piled up and IT became the referee. Microsoft Copilot Cowork risks becoming the same story, except the resource is agentic artificial intelligence, the cost is variable, and its reach extends across Microsoft 365.

Every Copilot rollout eventually creates the same question: who decides who gets access, who pays for it, and who is accountable for the outcomes?

In many organisations, those decisions land with IT by default. Access requests start arriving, managers point employees toward the help desk, and IT becomes responsible for approving, denying and justifying requests it doesn’t necessarily own. The result is often slower adoption, inconsistent decisions and an ever-growing approval queue.

Our view is simple: IT should design the guardrails, not decide access person by person.

Business leaders should own the outcomes, funding and acceptable use. IT should control the platform, security boundaries and governance settings that make adoption safe. When those responsibilities are clear, organisations can scale access without turning IT into an AI approval desk.

The better starting point is default access for a deliberately scoped group, backed by spending limits, clear policy and monitoring.

What Is Microsoft Copilot Cowork?

Microsoft describes Cowork as an agentic system, not an individual agent. Inside the Microsoft 365 Copilot app, it can perform multi-step work such as creating documents, sending emails, scheduling meetings and posting in Teams, with approval checkpoints before sensitive actions. Cowork for work and school accounts became generally available on 16 June 2026. It requires a Microsoft 365 Copilot User Subscription Licence and consumes Copilot Credits according to use.

There Is No Single Cowork Usage Policy

Cowork governance is assembled across usage-based billing spending policies, the Discovery setting, model controls, Cowork Browsing, plugins, Microsoft Purview and reporting. If your rollout plan says only “configure the usage policy”, it is too vague to execute or audit.

If IT isn’t going to approve every Copilot Cowork request individually, something else needs to take its place. A single setting or policy won’t be enough. What’s necessary is a collection of governance decisions covering access, spending, capabilities, data protection and reporting.

The six areas below provide a practical framework for enabling Cowork while keeping responsibility where it belongs: the business owns the outcomes, and IT owns the guardrails.

1. Decide the Default Before Requests Arrive

Cowork is off by default. Before making it discoverable, agree who owns the budget, which business outcomes justify access, which data is excluded and what happens when someone reaches a limit. Otherwise, visible but unavailable Cowork creates access requests and pushes IT straight into an approval queue.

There are three practical access postures:

Posture Benefit Trade-off
Approve one by one Maximum initial control Slow learning and turns IT into a gatekeeper
Enable a scoped group by default Faster feedback with predictable eligibility Needs caps, monitoring and clear data boundaries
Enable broadly Organisation-wide experimentation Highest cost and data-readiness exposure

For most organisations, a scoped default-on pilot passes the pub test. It creates faster feedback than individual approvals while keeping exposure bounded.

2. Scope Access with Microsoft Entra Groups

Define eligibility using role, business need, data readiness and willingness to provide feedback, then implement the cohort through a Microsoft Entra security group. Microsoft currently uses security groups to target specific users in spending policies. Give the group a clear business owner and a regular membership review. IT can administer it, but it should not invent the eligibility criteria alone.

3. Configure Spending Policies, Caps and Alerts

In the Microsoft 365 admin centre, go to Copilot, then Cost Management. Global or Billing Administrators configure the billing method, while AI or Licence Administrators can manage spending policies, limits and alerts.

Set a tenant monthly cap, then create a policy for the pilot security group with group and per-user limits, alert thresholds and named recipients. Confirm that the policy governs Copilot Cowork. Choose the billing method carefully because Microsoft states it cannot be changed on an existing policy. Publish the criteria for extra credits so requests do not become another unmanaged inbox.

4. Configure Discovery and Capabilities

Discovery controls visibility, while Cost Management controls access and spending. Leave discovery off until the pilot is ready, then review the available models, their retention implications, Cowork Browsing, Microsoft Edge restrictions and plugins. Record each decision, its owner and the review date.

5. Put Data Governance Ahead of Broad Access

Cowork works with the user’s existing permissions. Its isolated Microsoft 365 processing environment does not repair overshared SharePoint sites or stale access. Before expanding, assess oversharing with Microsoft Purview Data Security Posture Management for AI and confirm the required labels, audit, eDiscovery and lifecycle controls. As of 28 August 2026, Microsoft listed Data Loss Prevention, data classification and Compliance Manager as unsupported for Cowork, so recheck the capability matrix before publishing or rolling out to regulated workloads.

6. Monitor Adoption, Cost and Requests

Use the Cowork Usage report to track active users, tasks, retention and pending requests, and use Cost Management to review consumption by user, group and feature. Do not measure success by access alone. Look for repeatable use cases, useful outcomes and acceptable cost, then expand the security group based on evidence. Whether you use Microsoft’s native reporting or tools such as Codify’s M365 Copilot Monitor, visibility into adoption, governance and consumption is essential before broadening access.

When IT Owns the Controls, the Business Owns the Outcome

Copilot Cowork is more capable than a laptop, but the organisational failure mode is familiar. When leadership does not define outcomes, funding and eligibility, IT inherits the decisions through approvals and exceptions.

The better model is controlled enablement: a scoped Microsoft Entra group, spending policies, sensible caps, deliberate configuration, Purview guardrails and visible reporting. IT keeps the controls, while the business owns why the technology is being used.

If you are working through Copilot Cowork governance, adoption or Microsoft 365 readiness, get in touch with Codify for an obligation-free chat.

Ready to connect with Codify to discuss your next cloud project?

I know what I want:

I don’t know what I need:

Ready to connect with Codify to discuss your next cloud project?

I know what I want:

I don't know what I need: