Copilot Studio adds human approval for tool calls
Microsoft documents a human-approval mechanism for selected Copilot Studio tool calls before sensitive actions are executed.
Microsoft documents a human-approval mechanism for selected Copilot Studio tool calls before sensitive actions are executed.
Tool use in Copilot Studio could already be constrained through permissions and agent configuration.
Selected tool calls can additionally require an explicit human approval step per tool and agent.
Microsoft is adding a targeted human-approval mechanism for Copilot Studio tool calls. According to the roadmap, makers can configure individual tools so that an agent must obtain human approval before the action is executed.
When a protected tool call is reached, the agent pauses and presents an approval request describing the planned action. The user can approve it, allow it for the current session or reject it. Microsoft gives examples such as sending emails, closing tickets and triggering payments.
This is an important governance change because control is no longer expressed only through prompt instructions or broad permissions. Approval becomes a technical guardrail around selected tools, allowing an agent to research or plan autonomously while keeping consequential external actions human-gated.
Microsoft lists rollout beginning in September 2026. AgentenCode therefore records a documented introduction, not a claim that every tenant or region already has the feature. Availability for a specific agent, channel and tool still needs deployment-level verification.
Primary source
What this update is based on
AgentenCode publishes product changes only after source-first review. The original provider source remains authoritative for current details.
Continue checking
Full context in the Agent Profile.
The profile, trust evidence and history separate documented properties from Unknown.