web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Copilot Studio / Clarification to permi...
Copilot Studio
Unanswered

Clarification to permissions for a Chat-Bot

(1) ShareShare
ReportReport
Posted on by 261
 Hello community,
 
I like to get a clear clarification for giving permissions to a Chat-Bot in an environment.
 
(1) There are two permission levels: Environment-Permission and BOT-App-Permissions
(2) Each user needs to get permission to the environment at first
(3) The permission can be managed by a AZURE security group only.
(4) I need to create a new custom security role
(5) The new Role includes the following permissions:  prvReadbot & prvReadbotcomponent
(6) I will add that role to the AZURE security group?
(7) I will add the AZURE security group to the BOT-App
 
(!) IMPORTANT: What kind of BOT type you are using WEB or TEAMS
(!) I will use as PowerPlatform Admin the Default Limits in "Limit Sharing in PowerPlatform"
 
Sharing rules in Dataverse for Teams environments don't affect sharing to a Teams team when you publish an agent to Teams. 
However, when a user attempts to share an agent with individuals or groups in a team other than the one bound to the environment, 
the sharing limits are enforced.
 
AND:
 
Members of a nested security group in an environment security group aren't pre-provisioned or automatically added to the environment. 
However, they can be added into the environment when you create a Dataverse group team for the nested security group.
 
AND:
 
The default environment is intended to be shared with all users in the tenant and the developer environment is intended for use 
by only the owner of the environment.
 
So that means the best approach is to create an explicit  BOT environment and to check the general Limit Sharing and do not use nested security groups.
And if you use multiple BOTs in different environments best to maintain is to use CoE-Kit otherwise you run in problems.
If you put all BOTs in one environment you can use Power Automate as follows to count the bots for example:
 
 
 
Anything or extras I have missed out?
 
Thanks in advance :)
 
Kind regards
Michael
 
Categories:
I have the same question (0)
  • Michael E. Gernaey Profile Picture
    53,963 Moderator on at
     
    FYI you are saying Bot, but I hope you meant Agent, as Bots are considered something else.
     
    So there is actually Tenant, Environment, App Layer and Bot permissions.
     
    Tenant (for features and licenses)
    Environments (for features and licenses)
    App Layer (such as Teams) / SharePoint
    Bot Permissions
    --Sharing Agent
    Connections
    Data Permissions
     
     
    This is true, however you can add others to your development environment so its not locked to having a single user
    The default environment is intended to be shared with all users in the tenant and the developer environment is intended for use 
    by only the owner of the environment.
     
    I am not sure I fully understand this. Sharing does matter and it is not a single "Agent" per Team or Environment so not sure what you mean on this one.
    Sharing rules in Dataverse for Teams environments don't affect sharing to a Teams team when you publish an agent to Teams. 
    However, when a user attempts to share an agent with individuals or groups in a team other than the one bound to the environment, 
    the sharing limits are enforced.
     
    The rest of what you said, I do not follow as it has nothing to do with permissions its a statement of how you feel it best to have an environment of bots, which I would never do.
     
     

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Season of Sharing Community Challenge Launch!

Jump in, show your community spirit, and win prizes!

Kudos to our 2025 Community Spotlight Honorees

Expanding mentorship, skilling, and AI innovation

Congratulations to the May Top 10 Community Leaders!

These are the community rock stars!

Leaderboard > Copilot Studio

#1
Valantis Profile Picture

Valantis 266

#2
Romain The Low-Code Bearded Bear Profile Picture

Romain The Low-Code... 184 Super User 2026 Season 1

#3
Vish WR Profile Picture

Vish WR 153

Last 30 days Overall leaderboard