Copilot Mastery Pro ~8 min read Updated · August 2026

You already have one. On every site.

Most organisations spend months debating whether to build an internal knowledge bot. Meanwhile every SharePoint site in their tenant already has one, switched on, scoped to that site's content, answering strictly within whatever permissions the asker already has. Knowing the difference between that ready-made agent and a custom-built one is most of the skill here.

01 Two agents, one site

Ready-made agentCustom-built agent
Where it comes fromEvery SharePoint site ships with oneYou create it, with site edit permissions
ScopeAutomatically the content on that siteSites, pages and files you choose — including other sites
NameNamed after the site, or “Copilot” if the site is in the Copilot in SharePoint public previewWhatever you brand it
EditableNoYes — scope, identity, behaviour, custom prompts
ShareableNoYes — via the ellipsis, then Share, then Copy Link
Has an .agent fileNoYes
You cannot edit or share the ready-made agent. If someone asks you to “tweak the site's Copilot,” the answer is always to create a custom agent instead — there is no version of that request that works on the built-in one.

02 The permission model is the whole product

Microsoft's phrasing is precise and worth repeating: agents in SharePoint answer questions about content on any site or document library that the asker has permissions with. The agent doesn't widen access. It reads what the person asking could already have opened themselves — it just reads all of it, instantly.

That's genuinely reassuring and genuinely dangerous at the same time. It means a SharePoint agent will never leak a document someone couldn't already open. It also means that if your permissions are sloppy — the “everyone in the company” library that was supposed to be temporary in 2021 — the agent will find that content and surface it fluently, in seconds, to anyone who asks the right question. Oversharing that used to be theoretical becomes practical.

Do this first

Before you promote SharePoint agents internally, run the permissions audit you have been postponing. See Copilot security hygiene — the failure mode isn't the agent, it's what the agent can reach.

03 What you need

To interact with an agent: a Microsoft Copilot licence, or pay-as-you-go for SharePoint agents enabled by your organization. That second path matters — it means agents can reach people who don't have a full Copilot seat.
To edit an agent: one of the above, plus edit permissions on the SharePoint site where the agent lives.
To turn agents off: SharePoint admins can remove the ready-made agent through the restricted content discovery policy.

04 Building one that earns its keep

A custom agent is worth building when the ready-made one has the wrong scope or the wrong manners. Three levers:

The output goes well beyond retrieval. Microsoft's worked example asks a custom agent to write a competitive pitch script comparing two products, drawing on the R&D evidence for one of them — that's synthesis across sites, not a search box.

Try it now

Open the SharePoint site your team complains about most. Ask its ready-made agent the question new starters always ask — the one that currently gets answered by someone senior in a DM. If the answer is good, you just found a custom agent worth building. If it's bad, you found a documentation problem the agent has helpfully surfaced.

05 Where this sits against the others

SharePoint agents are the right answer when the knowledge is in documents. When the knowledge is in conversation, that's Channel Agent. When the work is execution rather than recall, that's Planner Agent. And when you need process logic, connectors and approvals rather than grounded answers, you've crossed into Copilot Studio.

Up next in Copilot Mastery

The Employee Self-Service agent

HR and IT questions answered without a ticket — and the per-query costs Microsoft publishes but nobody reads. Read the lesson →

Questions people ask

Straight answers

Do I have to create a SharePoint agent?
No. Every SharePoint site comes with a ready-made agent, automatically scoped to that site's content, with no building required by site admins or owners. It appears as the main agent for the site and is named after the site — or named Copilot if the site is part of the Copilot in SharePoint public preview.
Can a SharePoint agent show someone documents they shouldn't see?
No. Agents in SharePoint answer questions about content the person asking already has permissions to. The risk is not the agent granting new access — it is that existing oversharing, like an over-broad library, becomes far easier to stumble across because the agent answers fluently and instantly.
What licence do I need?
To interact with agents in SharePoint you need a Microsoft Copilot licence, or your organization needs to have enabled the pay-as-you-go service for SharePoint agents. To edit an agent you need one of those plus edit permissions on the site where the agent lives.
Can I edit the ready-made agent?
No. The ready-made agent that ships with a site cannot be edited and cannot be shared. If you need different scope, branding or behaviour, create a custom-built agent instead.
How do I share a custom SharePoint agent?
Find the agent in the agent list, select the ellipsis, then Share, then use Copy Link to get a link you can send like any other file. Whoever receives it can select the link to open the agent. This only works for agents that were created — not the ready-made one.
Can one agent cover more than one SharePoint site?
Yes, that is one of the main reasons to build a custom agent. With site editing permissions you can specify the sites, pages and files the agent should draw information from, so a single agent can span a team site, an R&D site and a product site.
How do we turn SharePoint agents off?
SharePoint admins can remove the ready-made agent through the restricted content discovery policy, which lets you switch off agents on sites holding restricted content.