1Security + Copilot Studio
Copilot Studio builds an agent in an afternoon. 1Security counts what the afternoon created.
Copilot Studio is the maker tool: a business team wires an agent over a chosen set of sites, files and connectors before the day ends. That speed is the point - and it is why Studio agents outnumber classic integrations in tenants that use it. 1Security puts every Studio agent in one inventory the day you connect, on the licenses you already own: its reach resolved to actual files and sites, its activity attributed to the people driving it, its credits imported and kept as history, and a warning before a burning credit pool takes it offline.
- Day 1Studio agents in the inventory through the standard read-only connection - no extra license
- 125%of prepaid credit capacity is where agents get auto-disabled - 1Security warns while it is still a budget problem
- 30 daysthe credits report's own history - imported on a schedule, it becomes a permanent record
What Copilot Studio does
The fastest way from an idea to a working agent.
Three design decisions that made Studio the tool business teams actually use - and the reason its output needs an estate view.
Maker velocity
A purpose-built assistant over chosen sites, files and connectors, assembled in an afternoon without a platform team. The barrier that used to filter out casual automations is gone - deliberately.
Credits as one meter
Copilot credits are the common currency across Studio features: classic answers, generative answers, agent actions, tenant graph grounding. One number to budget - and one number to watch.
Enterprise wiring
Connectors, knowledge sources, channels and Entra identities give a Studio agent the same building blocks as a platform-built one. A weekend project can hold production-grade access.
The estate question
Forty agents later, three consoles hold a third of the answer each.
The person building a Studio agent thinks about the task, not access control. The agent inherits what its knowledge sources and connections can reach - a finance site collects years of permission history, and a week-old agent stands on all of it. From inside the maker tool, that inheritance is invisible.
The estate questions - how many agents exist, which reach sensitive data, which are actually used, what does each one cost - span identity, content, activity and billing. Each console answers its own slice per agent; nobody holds the joined answer per estate.
And credits enforce themselves: a prepaid pool that runs dry does not just overspend, it switches agents off. A spend problem that becomes an availability incident is exactly the kind of thing a security platform should see coming.
What 1Security adds
The estate view: reach, usage, credits, one graph.
1Security reads the same tenant through the standard read-only consent and resolves every Studio agent like every other identity.
- 01
Inventory on day one
Studio agents arrive through their Entra identities and the audit log - no extra license involved. Each lands with its creator, blueprint, status and last activity, next to Copilot, Foundry and third-party agents, with the template layer governed as its own object.
- 02
Reach resolved, restrictions enforced in view
Knowledge sources and connections resolved to the actual files, sites and mailboxes behind them, ranked by the sensitive data inside. Declare a type off-limits to AI, and a Studio agent still reaching it is a listed violation with the declaration on record.
- 03
Usage and credits, with history
Interaction volume per agent comes from the audit log on plain E1. The Copilot credits report imports as a recurring export, putting authoritative per-agent credits next to it - and because the report itself holds 30 days, the import becomes the long-term record.
- 04
Warnings before they hurt
Volume spikes score against each agent's own baseline; injection payloads planted in grounding content are flagged before the agent reads them; and credit-pool burn raises an alert while it is still a budget conversation - before the auto-disable threshold turns it into an outage.
How the two fit together
Studio keeps building. 1Security keeps count.
Copilot Studio stays the maker tool - nothing changes for the people building agents. 1Security connects to the same tenant with the standard read-only consent, reads agent identities from Entra and activity from the audit log, and imports the credit reports through the same import flow as the agent registry. Governance rides on top of what exists: no gateway in front of your agents, nothing installed in Power Platform, and remediation - when you opt into write access - staged behind a review window like every other action.
The Monday after
The hackathon produced forty agents. Now what?
An AI hackathon or just a good quarter, and the tenant holds forty Studio agents: some brilliant, some abandoned, two wired to sites nobody intended. The maker wave is a feature - the Monday-after question is which of these are real, what can each one reach, and what do they cost to keep.
With the inventory in place it is an hour, not a project: sort by files in reach and review the top five; filter to agents idle for a month and retire them; declare the payroll data type off-limits to AI and read the violations list instead of guessing.
And the numbers keep answering after Monday: per-agent usage and credits accumulate as history, so the next quarterly review starts from a chart - which agents earn their keep, which pool needs a top-up before the auto-disable, and which experiment nobody switched off.
Integration status
Where the integration stands.
Studio agent identities and activity come through the standard read-only Microsoft 365 consent - Entra service principals and audit-log interaction records, attributed per agent and per user, on the licenses you already own. Per-agent credit numbers live in admin-center reports; 1Security imports those exports on a schedule through the same flow as the agent registry import, so the history outlives the report's own 30-day window. Restriction declarations, anomaly baselines and injection scanning apply to Studio agents exactly as to every other agent on the graph.
Count the agents the afternoon created.
Connect read-only and every Copilot Studio agent lands in the inventory the same day - reach resolved, usage attributed, credits kept as history.
Or find out about agent forty-one from the bill.