TL;DR
Microsoft Teams Members and Guests should not automatically receive access to view or edit the underlying Copilot Studio agent.
Team membership should grant permission to use the published agent only. Access to view its instructions, topics, knowledge sources and configuration, or to make any changes, should require explicit permission from the agent owner or an authorised administrator.
The current behaviour does not provide adequate separation between agent users and agent developers. It conflicts with the principle of least privilege and creates unnecessary security, governance and accidental-change risks for enterprise deployments.
Copilot Studio should provide separate permissions for Use, View, Edit and Manage. By default, Team Members and Guests should receive only the Use permission.
The current permission behaviour for Copilot Studio agents created in Microsoft Teams environments presents challenges for enterprise governance and access-control requirements...
Membership in a Microsoft Team should not automatically provide access to the underlying agent in Copilot Studio. Most Team Members and Guests are intended to be end users of a published agent. They should be able to interact with the agent in Microsoft Teams without being able to view, access or edit its configuration.
In our case:
• The agent was created in a Microsoft Teams environment.
• The agent owner is an Owner of the associated Microsoft Team.
• Another account is only a Member of that Team.
• The Member was not explicitly granted access to the agent in Copilot Studio.
• The agent owner cannot remove or change the Member's Copilot Studio access through the agent sharing settings.
• The Member still has access to the agent in Copilot Studio because of membership in the associated Team.
Microsoft Support confirmed that this is currently expected behaviour by design. However, the current design does not provide sufficient separation between agent consumers and agent contributors for enterprise scenarios.
This behaviour should be changed.
A user who has only been assigned the Team Member or Guest role should not automatically receive access to the agent's design and configuration. More importantly, Members and Guests should not be able to edit the agent unless an agent owner has explicitly granted them editing permission.
Team membership is not equivalent to agent development responsibility.
The Team may include operational users, business users, external collaborators or other stakeholders who need to use the published agent but have no responsibility for developing or maintaining it. Automatically exposing the agent through Copilot Studio creates an unnecessary access-control and governance risk.
Security and Governance Concern
The current permission model does not provide a clear separation between agent consumption and agent development responsibilities.
Users who only need to interact with the published agent should not automatically be given access to underlying design information such as:
• Agent instructions and prompts
• Topics, triggers and conversation flows
• Knowledge-source configuration
• Connection and integration details
• Internal business logic
• Test content and unpublished development work
• Other agent settings and implementation details
These artefacts may contain confidential business information, internal operating logic or intellectual property that should only be available to explicitly authorised agent owners and contributors.
If a Team Member or Guest can edit any part of the agent without being explicitly assigned an agent editing role, the risk is more serious. Unauthorised or accidental changes could affect how the agent responds, which information it uses and how it behaves for end users.
Access to use an agent and access to develop an agent are fundamentally different permissions. They should not be inherited together through Microsoft Teams membership.
Expected Permission Model
Copilot Studio should provide separate and independently assignable permissions for:
1. Use Agent
The user can interact with the published agent through Microsoft Teams or another approved channel but cannot access the agent in Copilot Studio.
2. View Agent Configuration
The user can inspect the agent in Copilot Studio but cannot make changes.
3. Edit Agent
The user can modify the agent's instructions, topics, knowledge sources and other authorised configuration.
4. Manage Agent
The user can control ownership, sharing, permissions, publishing and other administrative settings.
By default, Microsoft Teams Members and Guests should receive only the Use Agent permission.
View, Edit and Manage permissions should require an explicit assignment by the agent owner or an authorised administrator. These permissions should not be automatically inherited from general Team membership.
Expected Scenario
A typical enterprise deployment should support the following arrangement:
• Team Owner and Agent Owner: Can use, view, edit and manage the agent.
• Authorised Agent Contributor: Can use, view and edit the agent based on explicitly assigned permissions.
• Team Member: Can use the published agent but cannot view or edit it in Copilot Studio.
• Team Guest: Can use the published agent when permitted but cannot view or edit it in Copilot Studio.
For example:
User A owns the Microsoft Team and the Copilot Studio agent.
User B is a Member of the Microsoft Team and needs to use the published agent as part of normal business operations.
User B should be able to interact with the agent in Microsoft Teams. However, User B should not see the agent in Copilot Studio and should not be able to view or change its instructions, topics, knowledge sources or settings unless User A explicitly grants the required permission.
Requested Enhancement
Please change the Copilot Studio permission model for Microsoft Teams environments so that:
• Team membership grants access to use the published agent only.
• Team Members and Guests do not automatically receive access to the agent in Copilot Studio.
• Viewing the agent configuration requires explicit View or Edit permission.
• Editing the agent requires explicit Edit permission.
• Agent owners can remove or modify inherited access without removing the user from the Microsoft Team.
• Usage permissions remain separate from design and administrative permissions.
• Existing effective permissions and their sources are visible to agent owners and administrators.
Where access is inherited, Copilot Studio should clearly identify the source of that access and allow an authorised administrator to override it at the agent level.
Business Impact
The current behaviour makes it difficult to deploy Copilot Studio agents within existing Microsoft Teams structures while maintaining appropriate access control.
Organizations may have to choose between:
• Allowing broad access to agent configuration.
• Removing legitimate users from the associated Team.
• Creating separate Teams solely to control Copilot Studio visibility.
• Moving the agent to a different environment.
• Avoiding wider deployment of the agent.
These workarounds add administrative overhead, fragment collaboration and weaken the governance model.
The requested enhancement would support:
• Principle of least privilege
• Separation of duties
• Protection of confidential business logic and intellectual property
• Reduced risk of accidental or unauthorised changes
• Clearer ownership and accountability
• Safer enterprise adoption of Copilot Studio
Summary
The ability to use a published agent must be separated from the ability to view, edit or manage that agent in Copilot Studio.
Microsoft Teams Members and Guests should not automatically receive access to the agent's configuration merely because they belong to the associated Team. They should never be able to edit the agent unless an authorised agent owner or administrator has explicitly granted them editing permission.
Please provide agent-level permissions that allow organizations to give users access to the chatbot experience without giving them access to the chatbot's underlying design and configuration.