The problem behind the new AI buttons
If you have ever opened the SharePoint admin centre to prepare for Copilot and found years of sites, sharing links, direct permissions and broken inheritance waiting for you, the awkward part is not creating an agent. It is deciding whether the content behind it is ready to become easier to query.
A SharePoint agent does not bypass permissions. It answers from content the person already has access to. That is useful, but it also means old oversharing remains old oversharing.
For a small Microsoft 365 admin team, the sensible move is not to enable every AI scenario at once. Choose one controlled pilot, prove that its content and access are sound, and keep the rest on hold until there is a real owner and use case.
The short answer
Start with one SharePoint agent on a well-owned, low-risk site or library.
- Pilot now: a narrowly scoped SharePoint agent where the content has a named owner and permissions can be reviewed.
- Pilot only with a cost owner: document processing or Autofill columns for one repetitive document workflow.
- Keep controlled during preview: Copilot in SharePoint, including AI-assisted site creation.
- Treat as separate user or governance work: OneDrive agents, Loop, Copilot Pages and Stream.
- Do not plan from the old instructions: the natural-language filtering steps previously attributed to Microsoft Lists are documented for Power Pages lists, not Microsoft Lists.
The meeting-ready sentence is:
We are not approving SharePoint AI tenant-wide. We are approving one bounded pilot after the site, content, permissions, licence route and stop conditions have been checked.
What should you enable, pilot or defer?
| 2023 scenario or current capability | Recommended decision | Check before you proceed | Why |
|---|---|---|---|
| SharePoint agents | Pilot now, narrowly | Named site owner, reviewed permissions, current content, defined agent scope, test users and a licence or billing route | This is the clearest way to test value without turning every site into a new AI surface |
| Document processing for Microsoft 365, formerly Syntex | Pilot for one document process | Azure pay-as-you-go owner, expected volume, selected sites and a manual fallback | It can extract or generate library metadata, but it creates consumption cost and is enabled broadly unless you restrict its site scope |
| Autofill columns | Pilot with document processing | One useful column, representative files, output review and cost monitoring | A narrow metadata task is easier to verify than a broad “understand our documents” promise |
| Copilot in SharePoint and AI-assisted site creation | Keep controlled during preview | Copilot licences, tenant and site availability, self-service site creation rules, naming, ownership and lifecycle | Microsoft is still changing the preview enablement model and the experience can create pages, lists and libraries that still need human review |
| OneDrive agents | Evaluate as a user feature | File access, sharing expectations, licence route and who owns the resulting agent | A personal file-based agent is not the same governance decision as a shared SharePoint site agent |
| Loop and Copilot Pages | Govern separately | Storage location, retention, eDiscovery, workspace ownership and departure handling | Loop content can live in OneDrive, SharePoint or SharePoint Embedded containers, and the controls are not identical in every location |
| Stream on SharePoint | Keep in your video governance plan | Transcript availability, recording ownership, sharing, retention and Copilot entitlement | Video is stored in SharePoint or OneDrive, but this is primarily a video lifecycle and user-adoption decision, not the first SharePoint AI pilot |
| SharePoint Embedded | No action unless an application uses it | Application owner, container administration, access and compliance responsibilities | It is an application storage architecture, not a feature most SharePoint admins need to enable for ordinary sites |
| Natural-language filtering in Microsoft Lists | Remove from this plan | Wait for a direct Microsoft Lists source before promising it | The previous steps came from Power Pages documentation and should not be taught as a Microsoft Lists feature |
The governance-first pilot checklist
1. Choose a site that will not hide surprises
Use a site or library with:
- a named business owner
- a clear purpose
- a small, known audience
- current, useful content
- no unresolved highly sensitive material
- enough real questions to test whether an agent helps
Do not choose the messiest site as your first proof of concept. That tests your cleanup backlog, not the agent.
2. Review access before you create the agent
Check:
- site owners, members and visitors
- Microsoft 365 group membership
- external guests
- “Anyone” and organisation-wide sharing links
- direct permissions
- broken inheritance
- folders or files with different access from the parent library
- sensitive content and existing labels or data loss prevention policies
The agent will answer as the person asking. It will not grant access they do not have. It can, however, make content they already have access to much easier to find and combine.
If a site is high risk and your licensing includes the relevant SharePoint Advanced Management controls, Restricted Content Discovery can temporarily keep that site's content out of organisation-wide search and Microsoft 365 Copilot while you review it. It does not remove permissions, and it should not become a permanent substitute for fixing access.
3. Decide how the pilot will be licensed
For the simplest pilot, use a licensed Microsoft 365 Copilot user who can add files to the site.
Microsoft also supports pay-as-you-go access to SharePoint-grounded agents for users without a full Microsoft 365 Copilot licence. That route needs an Azure resource, a billing policy and a security group. Shared tenant data generates consumption charges.
For a small team, record these four answers before the pilot starts:
- Who can create the agent?
- Who can use it?
- Which licence or billing policy covers each person?
- Who watches consumption and can stop the pilot?
Microsoft's agent documentation changes frequently and some pages describe creation rights differently from interaction rights. Confirm the exact entitlement in your tenant before inviting unlicensed users.
4. Keep the knowledge scope small
Start with one library or a selected set of well-understood files. Give the agent a plain purpose, such as:
Answer policy questions from the approved HR policy library. If the answer is not in those files, say that you cannot confirm it.
Set the permissions on the agent's .agent file deliberately. Access to the agent file and access to the underlying content are separate checks.
5. Test what the agent must not reveal
Use accounts with different permissions and run both positive and negative tests.
| Test user | Question | Expected result |
|---|---|---|
| Site owner | Ask about an approved document | Answer is grounded in the correct source |
| Site member | Ask about content they can read | Answer appears and cites the expected material |
| User without access to a restricted folder | Ask directly about that folder's content | Restricted content is not returned |
| User with access to old or duplicated material | Ask a question where versions disagree | The test exposes the content-quality issue for cleanup |
| Any pilot user | Ask a question outside the agent's scope | The agent says it cannot confirm rather than inventing an answer |
If a negative test fails, stop. Check the underlying SharePoint access and content before changing the prompt.
6. Record the decision, not just the demo
Copy this into the pilot ticket or decision log:
| Field | Record |
|---|---|
| Site and library | |
| Business owner | |
| Agent purpose | |
| Included content | |
| Excluded content | |
| Permission issues found and fixed | |
| Licence or billing route | |
| Pilot users | |
| Questions the agent must answer | |
| Questions or content it must not return | |
| Cost and usage owner | |
| Stop condition | |
| Review date | |
| Decision: expand, revise or stop |
A polished demo is not the approval test. The approval test is whether the owner, access model, content scope, cost and failure response are all clear.
If you do not have SharePoint Advanced Management
You can still run a bounded pilot.
Choose a small, well-owned site; review its permissions manually; remove unnecessary sharing; limit the agent to a narrow library; test with different user accounts; and keep the audience small. Do not compensate for missing governance tooling by widening the pilot.
Where document processing fits
Document processing for Microsoft 365 is the current name for the pay-as-you-go services previously associated with Microsoft Syntex. Prebuilt document processing and Autofill columns both require an Azure-linked billing setup outside the Copilot in SharePoint preview route.
After document-processing billing is linked, Microsoft documents the services as available across SharePoint sites by default. Restrict them to selected sites before inviting makers if you want a controlled pilot.
A good first use case has:
- one repetitive document type
- fields a human can verify quickly
- a known monthly volume
- a manual fallback
- a cost owner
- a sample set that includes awkward documents, not only clean examples
Do not approve it because the extraction works on three perfect files. Approve it when the errors, review step and cost are understood.
What changed since the 2023 session
The old session is still useful as a picture of where Microsoft was heading, but it is no longer a safe build guide.
- Microsoft Syntex services are now described as document processing for Microsoft 365.
- SharePoint agents can use sites, pages, libraries and files as knowledge, subject to each user's existing access.
- Agent access can be provided through Microsoft 365 Copilot licensing or configured pay-as-you-go billing.
- Copilot in SharePoint can help create sites, pages, lists and libraries, but it remains a preview experience whose tenant controls and rollout details must be checked.
- Loop content does not have one universal storage pattern; its location affects lifecycle and compliance administration.
- Stream is built on SharePoint and OneDrive, but its Copilot and transcript features belong in the video governance plan.
- The previous Microsoft Lists natural-language filtering instructions were for Power Pages and have been removed.
Evidence notes
Use Microsoft documentation to trust what the controls and products are designed to do. Do not use it as proof that your tenant is clean or that a pilot is safe.
- SharePoint agents respect the asking user's access to the underlying content. This does not prove that the existing access is appropriate.
- Restricted Content Discovery can temporarily reduce organisation-wide discovery while a site is reviewed. It does not change permissions or remove content from the search index.
- Microsoft documents licensing and pay-as-you-go routes, but your agreement, tenant configuration, rollout ring and cloud environment still determine what you can use.
- Preview documentation can change. Check the Microsoft 365 Message centre and the live tenant before sending instructions to users.
- Official product documentation proves capability and prerequisites. It does not prove adoption, accuracy, risk reduction or return on investment.
Your next move
Pick one candidate site and complete the decision record before creating anything. If you cannot name the owner, define the content scope, explain the access model and state how the pilot will be stopped, the site is not ready for an agent yet.
Source note
Briefing published by Collab365 Spaces, reviewed by Helen Jones on . Cite as "Which SharePoint AI Features Should You Enable in 2026?", Collab365 Spaces. 11 sources referenced.