SharePoint Copilot Apps
Your SharePoint content becomes an agent – available where your people already ask. With a source, inside existing permissions and with a clear line where a human has to approve.
The difference is not the answer, it is the action
Microsoft 365 Copilot has been answering from documents for a while. What is new is something else: a Copilot app may also act – trigger an approval, create a record, start a workflow. That shifts the decisive question from “is the answer right?” to “what is this thing allowed to do?”
So we do not build a Copilot app as a chat window but as a permission concept. For every action it is fixed in advance whether it is allowed, whether it needs an approval or whether it stays excluded – written down in a document your IT and your data protection officer can read.
Honesty about the state of the technology belongs here: SharePoint Copilot Apps have been in public preview since July 2026, with general availability announced alongside SPFx 1.24 for September 2026. We build pilots with real cases today – production rollouts we deliberately plan around the GA.
Where to start
We start with a read-only use case. Write actions follow once the permissions are settled and the pilot holds up.
Answers from your policies
The simplest and safest entry point: questions about rules, processes and responsibilities – answered from approved documents, with a source.
Query a status
Where is my request, which tasks are open, what is stuck with whom. Read-only, so no approval needed.
Create records
Leave request, purchase requisition, fault report – the agent creates it, the approval stays with a human.
Find documents rather than search
Not full-text search but the question “which version applies?” – with a date and a pointer to the library.
Onboarding new joiners
The questions of the first weeks that nobody likes asking a third time – answered around the clock.
Data from line-of-business systems
Connected to an ERP or inventory system the agent also answers questions about the specific case.
What the agent may and may not do
The permission matrix of a pilot. It is signed off by IT and the department before development, not documented afterwards.
| Action | Data access | Permission |
|---|---|---|
| Answer a question about a policy | reads approved document libraries | allowed |
| State the status of a request | reads a SharePoint list, filtered to the person asking | allowed |
| Create a leave request | writes to the “Absences” list | manager approval |
| Raise a purchase requisition | writes to a list, notifies purchasing | purchasing approval |
| Approve an invoice | no access configured | excluded |
| View HR records | library not shared with the agent | excluded |
| Delete or move a document | no write access to libraries | excluded |
The three states are the same as everywhere on this site: green runs through, amber needs a human, plum is excluded.
Illustrative definition. Three of the seven rows are deliberately excluded – an agent allowed to do everything is not progress, it is a risk.
How the pilot comes about
-
Use case and feasibility
One case, not ten. We check whether the necessary content exists in sufficient quality at all – and decline if it does not.
-
Prepare the content
Which libraries are answerable, which version applies, what is outdated. This step is unspectacular and accounts for most of the result.
-
Define the permissions
The matrix: what is allowed, what needs approval, what stays excluded. Signed off by IT and the department before anything is built.
-
Build on the SharePoint Framework
Developed as an SPFx solution, surfaced in Microsoft 365 Copilot, Teams and SharePoint. Answers always cite their source.
-
Test the boundaries, then pilot
We actively try to push the agent past its limits – asking for other people's data and for things it must not do. Only then does the pilot reach real users.
What changes day to day
Today
- The same process questions land with the same three people
- Answers depend on who you happen to ask
- Nobody knows which version of a policy applies
- New joiners spend weeks looking for responsibilities
- Copilot answers generically instead of from your documents
With a Copilot app
- Recurring questions are answered, with a source reference
- The information is consistent because it comes from one source
- The agent states the version and where it is filed
- Onboarding questions are answered around the clock
- Simple records are created by the agent, approval stays human
Where we deliberately say no
An agent that can act is a different thing from a chatbot. These four boundaries are fixed before the first line of code:
- No bypassing permissions. The agent sees only what the person asking may see anyway. An agent with its own far-reaching rights would be more convenient and is exactly the mistake that turns a tool into a data protection problem.
- Nothing approved that moves money. Invoices, orders above thresholds, contract changes: the agent can create and prepare them, a human approves. This boundary is not negotiable.
- No HR records. Even where permissions would technically allow it, we do not configure agent access to personnel, health or application data. The benefit does not justify the risk.
- Production only at GA. Copilot Apps have been public preview since July 2026; general availability is announced with SPFx 1.24 for September 2026. We build pilots with real cases today and plan a tenant-wide rollout afterwards. Anyone arguing otherwise is selling you a risk as a head start.
Runs on your Microsoft 365 foundation
Scope and price
The entry price covers a pilot with one use case, the permission matrix and documentation. What moves the price, we say before the quote.
- Feasibility check against your real content
- Preparing the answerable libraries
- Permission matrix, signed off by IT and the department
- Copilot app built on the SharePoint Framework
- Answers with source references, surfaced in Copilot, Teams and SharePoint
- Boundary tests against permissions and disallowed actions
- EU AI Act documentation, labelling and pilot support
What increases the price
- Several use cases instead of one
- Write actions with approval chains across several roles
- Connection to line-of-business systems outside Microsoft 365
- Large or unstructured content estates that need preparing first
- Multilingual content with its own quality review
Several use cases with approval chains and line-of-business integration are quoted by effort. We give the binding fixed price after the feasibility check.
All prices excl. VAT · Copilot licences for your users are not included
What you get
-
Copilot app in pilot operation
Deployed in your tenant, available in Copilot, Teams and SharePoint
-
Signed-off permission matrix
What is allowed, what needs approval, what stays excluded – as a document
-
Boundary test log
Evidence that the agent actually stops at its limits
-
EU AI Act paperwork
Purpose description, risk classification and labelling for your evidence obligations
Frequently asked questions about SharePoint Copilot Apps
These solutions fit alongside
SharePoint Web Parts with SPFx
The same technical basis as an intranet surface – without needing Copilot licences.
AI Knowledge Base
The route without Copilot: a standalone assistant on the same content.
Approval Workflows
The approval chains the agent hands its records to.
SharePoint Intranet Suite
The surface for the same data when not everyone has a Copilot licence.
Which question should your agent answer?
In the free intro call we check your use case against real content – and say honestly whether it is viable today or whether the content has to be prepared first.
Book a free intro call