When the agent idea first sounds useful
If you have ever searched the same SharePoint site for a policy, decision or project update more than once, an agent can sound like an obvious fix. Then the awkward questions begin. Should it live in SharePoint or OneDrive? Is Microsoft 365 Copilot Agent Builder the same thing? Can colleagues see files they should not see? Who checks the answers after the first enthusiastic demo?
An agent does not clean up your content or repair your permissions. It gives people a repeatable way to ask questions of sources they can already access.
Mark Kashman demonstrated these SharePoint and OneDrive scenarios in his May 2025 workshop, Unlock the Power of Agents inside SharePoint and OneDrive. The original session remains useful context, but you do not need to have watched it. You can use the decision table, worked example and checklist below on their own.
The short answer
Start with the smallest agent that solves a repeated question.
| Your situation | Best starting point | Check before you begin |
|---|---|---|
| You want to ask questions across a small set of your own project files | OneDrive agent | You need a work or school account with a Microsoft 365 Copilot licence |
| A team repeatedly searches a SharePoint site, library, folder or selected files | SharePoint agent | The creator needs a Microsoft 365 Copilot licence and permission to edit the SharePoint location |
| You want a reusable agent in Microsoft 365 Copilot with broader supported knowledge sources | Agent Builder in Microsoft 365 Copilot | Availability and knowledge options depend on your licence and tenant settings |
| The agent must call another service, run an action or use more complex logic | Copilot Studio | Involve whoever manages Power Platform, licensing and data access |
| Agents are appearing across many teams and need central oversight | Your Microsoft 365 administrators | This is where tenant controls and Microsoft Agent 365 may become relevant |
A SharePoint or OneDrive agent is a good first move when the job is mainly, "Help me find and understand information in these files." If the job is, "Update another system, start an approval or run a business process," you are moving into Copilot Studio territory.
Before you build: look for five yes answers
A useful agent normally starts with five clear answers:
- Repeated need: Do people ask the same question or search for the same kind of information often enough to justify an agent?
- Known source: Can you point to the specific site, library, folder or files that contain the answer?
- Content owner: Is someone responsible for keeping those sources current?
- Permission fit: Should the intended users already be able to open those sources directly?
- Testable result: Can you write five questions the agent should answer and three it should decline or admit it cannot answer?
If one of those answers is no, fix that gap first. An agent built over stale files, unclear ownership or messy access usually makes the existing problem easier to query rather than easier to solve.
Worked example: bring "Ask Iz" up to date
In Mark Kashman's original workshop, "Ask Iz" answered questions from podcast content stored in SharePoint. The current equivalent is a SharePoint agent scoped to the approved podcast transcripts or episode library.
The same pattern works for an onboarding, policy or project agent:
| Decision | "Ask Iz" example | Workplace equivalent |
|---|---|---|
| Repeated question | "Which episode covered this topic?" | "What is our current travel approval rule?" |
| Knowledge source | Approved podcast transcripts | The maintained policy library, not the whole intranet |
| Safe instruction | Answer from the selected transcripts and say when the answer is absent | Answer from approved policies, cite the source and do not invent a rule |
| Owner | Podcast content owner | HR, operations or the policy owner |
| Boundary test | Ask about an unreleased episode | Ask about a policy that is not in the selected library |
Before anyone shares the agent, test it with questions such as:
- one question with a clear answer in a selected file;
- one answer spread across two selected files;
- one question whose answer is not present;
- one question about a file the test user cannot open;
- one question where an older file conflicts with the current version.
A trustworthy result is not "the agent answered everything." It is "the agent answered supported questions from the right sources and was clear when it could not."
Create a SharePoint agent with the current route
Microsoft now lets an eligible editor create an agent directly from SharePoint. This is separate from Agent Builder inside the Microsoft 365 Copilot app.
You can begin from:
- New > Agent on a SharePoint site homepage;
- AI actions > Create an agent in a document library or list; or
- Create an agent from the menu for selected files.
Choose the narrowest useful source. A maintained folder or library is normally easier to test and own than an entire site.
Give the agent a plain name, explain what it is for and add an instruction that tells it what to do when the answer is missing. Then test the expected questions and the boundary questions before sharing it.
SharePoint stores the agent as an .agent file:
- an agent created from the site homepage is stored under Site Assets > Copilots;
- an agent created from a library or folder is stored in the location where it was created.
Current Microsoft guidance does not require a separate approval step before an agent can be used. An Approved folder can still be part of your internal way of organising reviewed agents, but it is not a product gate. A site owner can choose the site's main agent from Settings > Site AI.
The refreshed SharePoint app bar includes Discover, Publish and Build destinations. Do not use the presence of the Build destination as proof that a user can create this kind of agent. Creation still depends on the relevant licence, tenant configuration and SharePoint permissions.
Create a OneDrive agent for a personal file set
A OneDrive agent is useful when one person wants to question a defined set of working files without turning it into a site-wide resource.
Microsoft's current requirements say the creator needs a Microsoft 365 Copilot licence for a work or school account. In OneDrive on the web:
- Select the files and choose Create agent, or use Create or upload > Create an agent.
- Add up to 20 sources.
- Name the agent, adjust its behaviour and save it.
- Open the resulting .agent file to use or edit the agent.
Supported creation sources currently include Word documents, PowerPoint presentations, PDFs, text files, rich-text files and Markdown files. If you select a folder, it must contain no more than 20 files.
The agent is normally saved in the folder where it was created. If you start from Shared or Favourites, it is saved under My Files > Documents > Agents.
You can share the .agent file like another OneDrive file, but the recipient also needs access to the underlying source files. Sharing the agent does not silently grant access to its knowledge.
What permissions do and do not protect
SharePoint and OneDrive agents respond using content the person asking the question is allowed to access. Giving someone access to an agent does not grant new access to the underlying files.
That is useful, but it is not the same as saying the content is safe.
If a site already gives too many people access to an old salary sheet, draft contract or private working folder, an agent does not repair that oversharing. It may make permitted content easier to find. Before sharing an agent:
- review the exact sources you selected;
- check who can open them now;
- remove obsolete and duplicate versions;
- ask the content owner which version is authoritative; and
- test with an ordinary user account, not only the creator or site owner.
If the source contains sensitive information or the permissions are difficult to explain, stop and involve your SharePoint or Microsoft 365 administrator.
Troubleshoot the simple things first
If an agent gives no useful answer, check the setup before changing prompts at random:
- Is the relevant file, folder, library or site actually included?
- Can the person asking the question open that source directly?
- Can they open the .agent file?
- Does their licence, or the tenant's pay-as-you-go configuration where supported, allow them to use the agent?
- Is the answer genuinely present in a current, readable source?
- Does the instruction accidentally tell the agent to ignore or over-restrict the material?
Record the question, user, source and result when escalating the problem. That gives an administrator something testable instead of "the agent does not work."
Pre-sharing checklist
- The agent solves a repeated workplace question.
- Its knowledge is limited to named, maintained sources.
- A person owns those sources and knows the agent depends on them.
- Intended users can access both the agent and the underlying content.
- Sensitive, obsolete and conflicting files have been reviewed.
- The instructions tell the agent to admit when an answer is missing.
- Expected, boundary and permission tests have passed.
- The licence and tenant requirements have been confirmed.
- The agent has a named owner after launch.
- Users know where to report a wrong, stale or unsafe answer.
When to involve IT
For one team agent, the practical controls are usually narrow sources, existing permissions, a named owner and good testing.
Involve IT when users need pay-as-you-go access, agent sharing must be restricted, sensitive sites are involved, or agents are spreading across departments. Microsoft 365 administrators have controls for agent access, sharing and inventory. Microsoft Agent 365 adds central observation, governance and security capabilities for organisations operating a wider agent estate.
Do not buy or deploy an enterprise governance product simply because one team wants to question a folder. Escalate when the number of agents, sensitivity of the data or need for central oversight makes local ownership insufficient.
Evidence notes
Microsoft's documentation supports the current creation routes, storage behaviour, licence boundaries, permission model and administration options described here. It does not prove that your source content is accurate, your permissions are well designed or an agent will improve adoption.
Microsoft changes Microsoft 365 interfaces and licensing. Check the labels in your own tenant and review the Microsoft 365 Message Center before a wide rollout. Use the checklist as a decision aid, not as a security or compliance approval.
Source note
Briefing published by Collab365 Spaces, reviewed by Helen Jones on . Cite as "SharePoint and OneDrive agents in 2026: what to build and what to check first", Collab365 Spaces. 10 sources referenced.