Delegus

Look up an agent

Microsoft Copilot

What Microsoft Copilot’s own help pages, docs and terms said on 1 October 2026, by the same six questions we ask of every agent. We didn’t test it for this page. “Not documented” means we didn’t find it on the vendor’s pages; it doesn’t mean the feature is missing.

Assistant

Can you limit it?
Admin plugins and policies
Does it ask first?
Before sensitive acts; widen per session
Can you stop it?
Soft and hard pause
Is there a record someone outside can check?
Not documented
What about sub-agents?
Studio states a gap
Can you test it yourself?
Admin-approved plugins

What the vendor’s pages say

Cowork asks before sensitive actions, like sending an email, and you can widen that for the rest of a session to one recipient, one domain or "Always allow". It has a soft pause and a hard pause, which stops "immediately, including mid-step" (use Cowork). If a plugin is removed or revoked, "any session that's already in progress isn't interrupted", and Cowork can't delete files in OneDrive or SharePoint (FAQ). Purview audit records include the resources accessed, an agent id and a flag for a detected prompt-injection attack (audit). Copilot Studio's guidance says a connected agent "might have access to things the parent agent doesn't". Developers can switch off write confirmations for their plugin (confirmations).

Every statement above was checked on the vendor’s own page on 1 October 2026; each links to its source.

Run this test on yours

Delegus Check gives your agent a permission and a one-hour test server, then shows every action it tries and what was refused. It works today with agents that accept a custom MCP server, including Claude on any plan.

Run this test on yours

Corrections

Vendors and readers: if anything here is out of date, write to hello@delegus.ai and we’ll fix it. Each change is listed here with its date.

All 15 agents