Governance starts before the platform does
The usual story is a retrofit: hundreds of apps and flows, no inventory, a security team asking questions nobody can answer. It is a good problem — it means people are building — and it is the moment governance either becomes a capability or a crackdown.
But the better engagement starts earlier. We work with IT and enterprise architecture to settle policy and security guidance while those decisions are still cheap, then move through the Microsoft adoption framework to build a roadmap the team can measure against. Whether you are ahead of the sprawl or cleaning up after it, the sequence is the same: policy, then guardrails, then community.
Shadow AI is bigger than any one tool
Your people are already building with AI — not just prompting it, but shipping working tools and, increasingly, agents. Hundreds of licensed ChatGPT and Claude users inside a single organization are generating code-based tooling and sharing it through OneDrive, built by people who are not developers, distributed with none of the architecture review a traditional development team would apply. That is shadow IT’s newest form: agents live in the tenant with no inventory, no owner, and no one in IT who can see what they can reach.
Most organizations have noticed this and have exactly two responses available: ban it, or ignore it. Neither works. The tools and agents are too useful to ban and too consequential to ignore.
The piece most organizations are missing is agent-level visibility, not another review process. Microsoft Agent 365 is what makes that possible — it gives every agent in the tenant, sanctioned or not, an identity and a manageable lifecycle, the same way Entra already governs people and Intune governs devices. That is the key to the shadow IT problem itself; governing the output people produce is a related but narrower job. On that narrower piece, we have built one part of the answer: a Copilot agent that vets submitted HTML tools, routes them through architecture review in Azure DevOps, and publishes approved ones to SharePoint, so makers keep their speed and the organization gets provenance on what gets published. It is a review pipeline for output — Agent 365 is what governs the agents themselves.
Enablement is the other half of the job
Governance that only restricts gets routed around. The engagements that hold up are the ones where we also build the community: a Community of Practice with a real monthly cadence, champions who are identified and equipped to help their own teams, and SOPs published in a Microsoft Teams space makers already live in.
The same applies to AI adoption. In one Copilot program we put the initial policies and DLP settings in place, enabled the surrounding tools that make Copilot worth having — Azure DevOps, Dynamics 365 Sales, Cowork — and ran light training workshops so people understood the difference between Copilot Chat and Copilot Cowork and how to prompt either one well. That program now supports roughly 100 to 200 active agent developers serving about 1,200 end users.
Beyond Power Platform: the tenant view
The app and AI platform is where we focus, but its policies cannot contradict the tenant they run in. Purview governs how data is classified and protected. Intune governs the devices reaching it. The Microsoft Admin Center holds the tenant configuration underneath both. We work alongside your IT and security teams so the platform guidance and the tenant controls tell the same story — which is usually the difference between a policy that survives review and one that gets rewritten in six months.
A roadmap you can measure
Governance fails quietly when nobody can say whether it is working. We use the Microsoft adoption framework to turn the current state into staged, measurable progress: maker activity, policy and environment compliance, community participation, and how many requests resolve through self-service instead of escalation.
One program built this way supports roughly 1,500 active makers — pro and low-code — across the US, Europe, and Asia. That scale is only survivable because the guardrails, the intake, and the community were designed together rather than bolted on in sequence.