Lyron
Microsoft 365 · AI

SharePoint Copilot Apps

Your SharePoint content becomes an agent – available where your people already ask. With a source, inside existing permissions and with a clear line where a human has to approve.

Context

The difference is not the answer, it is the action

Microsoft 365 Copilot has been answering from documents for a while. What is new is something else: a Copilot app may also act – trigger an approval, create a record, start a workflow. That shifts the decisive question from “is the answer right?” to “what is this thing allowed to do?”

So we do not build a Copilot app as a chat window but as a permission concept. For every action it is fixed in advance whether it is allowed, whether it needs an approval or whether it stays excluded – written down in a document your IT and your data protection officer can read.

Honesty about the state of the technology belongs here: SharePoint Copilot Apps have been in public preview since July 2026, with general availability announced alongside SPFx 1.24 for September 2026. We build pilots with real cases today – production rollouts we deliberately plan around the GA.

Use cases

Where to start

We start with a read-only use case. Write actions follow once the permissions are settled and the pilot holds up.

Safest starting point

Answers from your policies

The simplest and safest entry point: questions about rules, processes and responsibilities – answered from approved documents, with a source.

PoliciesProcess descriptionsResponsibilitiesForm help

Query a status

Where is my request, which tasks are open, what is stuck with whom. Read-only, so no approval needed.

Request statusOpen tasksDeadlines

Create records

Leave request, purchase requisition, fault report – the agent creates it, the approval stays with a human.

Create requestLog a reportCreate task

Find documents rather than search

Not full-text search but the question “which version applies?” – with a date and a pointer to the library.

Current versionVersion historyValidity

Onboarding new joiners

The questions of the first weeks that nobody likes asking a third time – answered around the clock.

First stepsWho is responsibleWhere do I find

Data from line-of-business systems

Connected to an ERP or inventory system the agent also answers questions about the specific case.

Order statusStock levelCustomer data
Example

What the agent may and may not do

The permission matrix of a pilot. It is signed off by IT and the department before development, not documented afterwards.

ActionData accessPermission
Answer a question about a policyreads approved document librariesallowed
State the status of a requestreads a SharePoint list, filtered to the person askingallowed
Create a leave requestwrites to the “Absences” listmanager approval
Raise a purchase requisitionwrites to a list, notifies purchasingpurchasing approval
Approve an invoiceno access configuredexcluded
View HR recordslibrary not shared with the agentexcluded
Delete or move a documentno write access to librariesexcluded

The three states are the same as everywhere on this site: green runs through, amber needs a human, plum is excluded.

Illustrative definition. Three of the seven rows are deliberately excluded – an agent allowed to do everything is not progress, it is a risk.

How it works

How the pilot comes about

  • Use case and feasibility

    One case, not ten. We check whether the necessary content exists in sufficient quality at all – and decline if it does not.

  • Prepare the content

    Which libraries are answerable, which version applies, what is outdated. This step is unspectacular and accounts for most of the result.

  • Define the permissions

    The matrix: what is allowed, what needs approval, what stays excluded. Signed off by IT and the department before anything is built.

  • Build on the SharePoint Framework

    Developed as an SPFx solution, surfaced in Microsoft 365 Copilot, Teams and SharePoint. Answers always cite their source.

  • Test the boundaries, then pilot

    We actively try to push the agent past its limits – asking for other people's data and for things it must not do. Only then does the pilot reach real users.

Impact

What changes day to day

Today

  • The same process questions land with the same three people
  • Answers depend on who you happen to ask
  • Nobody knows which version of a policy applies
  • New joiners spend weeks looking for responsibilities
  • Copilot answers generically instead of from your documents

With a Copilot app

  • Recurring questions are answered, with a source reference
  • The information is consistent because it comes from one source
  • The agent states the version and where it is filed
  • Onboarding questions are answered around the clock
  • Simple records are created by the agent, approval stays human
Limits

Where we deliberately say no

An agent that can act is a different thing from a chatbot. These four boundaries are fixed before the first line of code:

  • No bypassing permissions. The agent sees only what the person asking may see anyway. An agent with its own far-reaching rights would be more convenient and is exactly the mistake that turns a tool into a data protection problem.
  • Nothing approved that moves money. Invoices, orders above thresholds, contract changes: the agent can create and prepare them, a human approves. This boundary is not negotiable.
  • No HR records. Even where permissions would technically allow it, we do not configure agent access to personnel, health or application data. The benefit does not justify the risk.
  • Production only at GA. Copilot Apps have been public preview since July 2026; general availability is announced with SPFx 1.24 for September 2026. We build pilots with real cases today and plan a tenant-wide rollout afterwards. Anyone arguing otherwise is selling you a risk as a head start.
Systems

Runs on your Microsoft 365 foundation

Microsoft 365 CopilotSharePoint OnlineMicrosoft GraphMicrosoft TeamsEntra IDPower Automate
Scope and price

Scope and price

The entry price covers a pilot with one use case, the permission matrix and documentation. What moves the price, we say before the quote.

from €9,900 pilot
  • Feasibility check against your real content
  • Preparing the answerable libraries
  • Permission matrix, signed off by IT and the department
  • Copilot app built on the SharePoint Framework
  • Answers with source references, surfaced in Copilot, Teams and SharePoint
  • Boundary tests against permissions and disallowed actions
  • EU AI Act documentation, labelling and pilot support

What increases the price

  • Several use cases instead of one
  • Write actions with approval chains across several roles
  • Connection to line-of-business systems outside Microsoft 365
  • Large or unstructured content estates that need preparing first
  • Multilingual content with its own quality review

Several use cases with approval chains and line-of-business integration are quoted by effort. We give the binding fixed price after the feasibility check.

All prices excl. VAT · Copilot licences for your users are not included

Included

What you get

  • Copilot app in pilot operation

    Deployed in your tenant, available in Copilot, Teams and SharePoint

  • Signed-off permission matrix

    What is allowed, what needs approval, what stays excluded – as a document

  • Boundary test log

    Evidence that the agent actually stops at its limits

  • EU AI Act paperwork

    Purpose description, risk classification and labelling for your evidence obligations

Questions & answers

Frequently asked questions about SharePoint Copilot Apps

Copilot answers from what the search index knows. A Copilot app brings your own logic: specific sources, specific actions, specific limits. The practical difference is the action – an app can create a record or start a workflow. That is why it needs a permission concept that plain answering does not.
No. It accesses in the context of the person asking, so it sees exactly their permissions. What often surfaces: libraries shared too widely over the years. That is uncomfortable but better before the rollout than after – the permission review is part of the project.
Only within what the matrix allows – and there we configure no deleting or moving access. Write actions are limited to creating records in lists intended for it. Approvals involving money stay with a human on principle.
For a tenant-wide production rollout: yes. For the feasibility check, content preparation and permission review: no – that work takes weeks anyway and is independent of the version. Doing it now means you are ready at GA. More in our guide to SPFx 1.24 and Copilot Apps.
For surfacing in Microsoft 365 Copilot, yes, for the users concerned. That is a relevant cost factor we work through with you before quoting. If it does not add up, a standalone assistant without Copilot licences is often the more economical route.
Through boundary tests we log: asking for other departments' data, attempting disallowed actions, probing excluded topics. The log is part of the handover and the basis on which your IT signs the app off.

Which question should your agent answer?

In the free intro call we check your use case against real content – and say honestly whether it is viable today or whether the content has to be prepared first.

Book a free intro call