Microsoft 365 & AI adoption

Copilot Cowork Governance: How to Manage Credits, Access, and Agent Sprawl

Copilot Cowork governance starts with who gets access. Get the credit math, a champion access table, scheduling rules and a skill approval process.

Microsoft 365 & AI Adoption9 min read

Published

IT leader reviewing Copilot Cowork governance settings and credit usage with a team of AI champions
Cowork governance is a people process: who gets access, what they delegate, and who approves the skills they build.

Copilot Cowork governance is not a settings page. It is three people decisions: who gets access first, what they learn to delegate, and who approves the skills they build.

Microsoft gives IT leaders real controls for Copilot Cowork: spending policies, credit limits, plugin settings and Microsoft Purview. They only hold if the decisions behind them are sound. This Copilot Cowork governance guide is for IT directors and CIOs. It covers how Copilot Credits billing works, who should get access first, when to schedule tasks, and how to stop skills becoming the next agent sprawl.

The short version

  • A spending policy that selects Cowork is an access grant, even with a 1 credit limit. Scope it to a named group, never to all users.
  • Start with a small group of champions chosen from usage data and manager support, not seniority.
  • Onboard Cowork like a new FTE: decide which tasks you would hand a new hire before anyone writes a prompt.
  • Schedule only work that recurs with stable inputs. Every run spends credits, read or not.
  • Skills, like agents, should be built by teams and vetted by their managers before they are shared.
  • Train in team based sessions that are 70 percent doing and ideating, 30 percent learning.

Why Copilot Cowork governance is a people decision

Cowork acts as the person who runs it. It inherits that user's permissions and can send, post and save on their behalf. So the question is less "what can Cowork do" and more "who should hand it work, and under what rules."

Microsoft made the starting point safe: Cowork is off by default and requires a Microsoft 365 Copilot licence plus usage based billing. The risk comes later, when access widens faster than people learn to use it.

The most common mistake is a quiet one. Per Microsoft Learn, anyone in scope of a spending policy that selects Cowork can use it, whatever the credit limit. In Microsoft's own example, a 5,000 credit pilot policy plus a 1 credit tenant budget policy gives every user access. The fix: remove Cowork from any policy scoped to all users.

How Copilot Credits billing works, and where the credits go

Cowork usage is billed in Copilot Credits on top of the Microsoft 365 Copilot seat. Microsoft lists pay as you go at $0.01 per Copilot Credit, with a discounted prepaid commitment (P3) for steadier usage. In the Cost Management dashboard, admins set limits at tenant, group and user level, with alerts and user credit requests.

Two details matter for forecasting. Credit limits are enforced asynchronously, so a user can start a task after hitting the limit; scope is the real gate. And people only see a task's cost after it runs, with the /cost command, so your first users must be people who check it.

In a recent champions session for a maritime shipping company, we ran one job three ways: turning an incident report into a fleet safety circular and a toolbox talk using the company's templates.

ApproachWhat it costWho did the workBest when
Copilot ChatNo Cowork creditsThe person, step by stepYou are still working out the task
A Copilot agentNo Cowork credits in this exampleBuild once, then fast reuseSteps repeat and nothing needs sending
Copilot Cowork735 credits (about $7.35 pay as you go), about 10 minutesCowork; the person approvedMany apps, an action, or over 30 minutes of work

All three reached the same output. Chat costs time, Cowork costs credits; balance the two.

Credits also follow context. Asking Cowork to open every file in a large folder burns a monthly limit fast. A short index document explaining what lives where lets Cowork navigate instead of reading everything.

Who should get Copilot Cowork access first

Give Cowork first to a small group of champions chosen by readiness, not seniority. In the session above, the client picked champions from Copilot usage data, not job titles. That protects both the budget and the learning curve.

CriterionWhat to look forWhy it matters for governance
Copilot usageActive, regular Copilot Chat usersThey can already brief AI, so credits go to work
Cowork shaped workTasks touching more than three apps, ending in an action, or taking over 30 minutesOtherwise Chat is enough and costs nothing extra
Manager supportA manager who protects time and reviews their skillsReinforcement and skill vetting
Willingness to shareDemos results and shares skillsPrevents duplicate skills

Executives get access when they have Cowork shaped work, not because of title. In practice: one Microsoft Entra security group, one spending policy that selects Cowork with per user limits and alerts, and no other policy selecting Cowork for all users. For the full rollout sequence, see how to drive adoption of Copilot Cowork.

Onboard Copilot Cowork like a new FTE

The frame we give champions: Cowork is a new team member you are onboarding. Which tasks would you give a new coordinator in week one? What would you never let them send without checking?

The learning part covers three things:

  • Chat, Cowork and agents. Chat thinks with you, Cowork does the work for you, and an agent is a specialist with a defined job. Default to Chat and move up only when the work needs it (more on choosing the right AI).
  • How to brief Cowork. State the outcome, the inputs, how it will know it is done, the constraints, and the approval step. "Show me everything before anything is saved or posted" keeps Cowork from acting before you check.
  • Real skills. Champions see working examples, such as a skill that brands a PowerPoint deck to company standards and one that writes the weekly steering committee update.

Then the session turns to the champions. Each team decides what it would hand its new FTE, picks one recurring job, and designs a skill for it. Learning is not the challenge. Ideation and solutioning is where the value shows up, which is why our sessions run 70 percent doing and ideating, 30 percent learning.

In ADKAR terms, the 30 percent builds Awareness and Knowledge. The 70 percent builds Desire and Ability, because people leave with something they made for their own team. Reinforcement comes from managers reviewing those skills and from monthly champion check ins.

When to schedule a Copilot Cowork task, and when not to

Cowork can run scheduled prompts and event driven tasks without anyone present. Each automated task runs with its creator's permissions, asks for approval before sending, posting or changing a shared system unless authorized in advance, has rate limits and loop protection, and is audited.

What Microsoft cannot decide is whether a task deserves to recur. A scheduled task nobody reads is a recurring charge for nothing.

Schedule itRun it on demand
The same job happens every week or monthIt is a one off or still exploratory
Inputs are stable in place and formatInputs change each time
Someone reads or uses the output every runThe output is only sometimes needed
It has run well by hand at a known /costIt has never run well by hand

Run it on demand until the brief stops changing, then schedule it with an approval step on anything it sends.

Skills are the next agent sprawl: team built, manager vetted

Skills are reusable instructions Cowork loads when a task calls for them. They are easy to make, which is the risk. Custom skills are not validated by Microsoft, so quality varies, and without a rule every team ends up with several versions of the same skill.

Our rule: skills, like agents, are solutions developed by teams and vetted by those teams' managers before they are shared.

  1. Name the job. The team picks one recurring task. One skill, one job.
  2. Build it with the skill builder. Cowork's guided creator asks questions and drafts the skill for you.
  3. Write it like a recipe. Define the output, show good and bad examples, and say what to do when information is missing.
  4. Test it on real work and note its /cost.
  5. Manager review. Right job, right sources, an approval step, and a cost the work is worth.
  6. Share it with one named owner instead of everyone building their own.
  7. Review quarterly and retire what nobody uses.

IT supports this with controls, not by approving every skill. Admins decide which plugins and model families, including Anthropic's, are available, and Purview auditing records when users add, remove or share skills and plugins. For agents across platforms, Microsoft Agent 365 adds a registry and visibility at $15 per user per month, or included in Microsoft 365 E7.

The same logic applies to tools. Before adding another agent platform, govern the one already inside Microsoft 365. More tools mean more spend to manage, more security exposure and more to train.

What Purview and permissions cover in Copilot Cowork today

Cowork only sees what the user can see, so oversharing is the main data risk. If a SharePoint site is open to everyone, Cowork can read it for anyone. Fix your most sensitive sites before widening access.

ControlStatus for Cowork at the time of writing
Sensitivity labelsSupported; highest label shown, and new Word, PowerPoint and Outlook content inherits labels
EncryptionHonoured; needs the right usage rights
Auditing, eDiscovery, retention, Insider Risk ManagementSupported
DSPM for AISupported, including oversharing assessments
Purview Data Loss PreventionNot yet supported for Cowork itself
Browser tasks in EdgeInherit your conditional access, DLP and browsing policies

Sources: Microsoft Purview for Copilot Cowork and Manage Copilot Cowork.

The quick rule: scope access to champions, cap credits by group, schedule only what recurs, and let no skill ship without a manager's yes.

Treat Copilot Cowork like a new hire. You choose who it works for, you decide what it may do without asking, and its manager signs off on how it does the job.

What IT leaders should do next

  1. Remove Cowork from any spending policy scoped to all users.
  2. Create one Entra group for champions with a single policy, per user limits and alerts.
  3. Select champions from usage data and manager support, each with Cowork shaped work.
  4. Fix oversharing on sensitive SharePoint sites and confirm labels are in place.
  5. Write manager approval of skills into your rollout plan.
  6. Run a team based session where each team designs at least one skill.
  7. Review credit use and skills monthly before widening access.

How Change Champions helps

We help organizations turn Copilot Cowork from a licence into a governed habit. Our approach is grounded in PROSCI and ADKAR, and built on more than a decade of technology adoption work with over 500 organizations. For Cowork, that means starting with the right people and the right work, not the widest rollout.

Ready to turn rollouts into real adoption?

Whether you're driving Microsoft 365 and AI adoption, reducing human risk, or leading a change program, a 30 minute discovery call is the fastest way to see if we're a fit.

Questions we get asked

What is Copilot Cowork governance?

Copilot Cowork governance is the set of decisions and controls that set who can use Cowork, how much they can spend, what data it reaches, and which skills and automated tasks are allowed. Spending policies, credit limits, plugin settings and Purview are the controls. Decisions about people and work make them effective.

How does Copilot Cowork billing work with Copilot Credits?

Cowork needs a Microsoft 365 Copilot licence, and usage is billed in Copilot Credits. Microsoft lists pay as you go at $0.01 per credit, with a discounted prepaid option. Admins set limits and alerts by tenant, group or user. Limits apply asynchronously, so policy scope is what controls access.

Should we give Copilot Cowork to everyone or start with a pilot group?

Start with a pilot group of champions chosen from Copilot usage data, manager support and work that needs Cowork, not seniority. Scope one spending policy to that group, learn how credits are really used, and widen access once you have proven use cases and a skill review process.

When should you schedule a Copilot Cowork task?

Schedule a Copilot Cowork task only when the job recurs, its inputs are stable, someone uses the output every time, and it has already run well by hand at a known cost. Run anything exploratory or one off on demand, and keep an approval step on tasks that send or post.

Who should approve Copilot Cowork skills?

The manager of the team that will use the skill. Teams build skills for their own recurring work, and their manager checks the job, the sources, the approval step and the credit cost. IT controls which plugins are available and audits skill activity rather than approving every skill.

Does Copilot Cowork respect sensitivity labels and SharePoint permissions?

Yes. Copilot Cowork only accesses content the user can already see, shows the highest sensitivity label used, and passes labels to new Word, PowerPoint and Outlook content. That makes oversharing the real risk, so fix broad SharePoint permissions first. Purview Data Loss Prevention does not yet apply to Cowork itself.

Keep reading

Ready to turn rollouts into real adoption?

Whether you're driving Microsoft 365 and AI adoption, reducing human risk, or leading a change program, a 30 minute discovery call is the fastest way to see if we're a fit.

Ready to turn rollouts into real adoption?

Book a 30-minute call to see how our programs fit your rollout.