Skip to main content
Front cover of Who Owns the Agent? by Sougata Roy: a blank authorization form with an unsigned owner line and a red wax seal.

The Book | First Edition 2026

Who Owns the Agent?

Enterprise AI Accountability on the Microsoft Stack

Your tenant can prove what the agent did. Proving it was allowed to is a different record, and almost nobody has written it.

238 pages20 chaptersPaperback & KindleISBN 979-8-9971983-0-5
$39.99 paperback | $16.99 Kindle

The question the book is about

An examiner asks who authorized it. The room goes quiet.

She is not asking for logs. She has those. She is asking for the name of the person who decided this agent could read that mailbox, the date they decided it, and the scope they approved.

Enterprise AI agents now read email, move money, file tickets, and call other agents. Most were authorized once, by someone who has since changed roles, for a scope that no longer describes what the agent does. The record of the action survives. The record of the authorization was never created.

This book maps what Microsoft 365 Copilot, Copilot Studio, Power Platform, Microsoft Foundry, Agent 365, Microsoft Entra Agent ID, and Microsoft Purview can actually prove about agent authorization, where the gaps sit, and what has to be built on top of them.

The question is not whether your agents are governed. It is whether anyone could prove it on demand.

Chapter 19 | The Examiner Returns
20
Chapters
7
Microsoft surfaces
11
Original frameworks
1
Page appendix

Contents

Five parts, twenty chapters

Every chapter opens on a documented failure and closes on the question that failure leaves behind. Chapters can be read out of order without losing the argument.

01

The Question

Chapters 1-3

  1. 01The Examiner Walks In
  2. 02The Accountability Assumption in Microsoft Environments
  3. 03Why Microsoft Defaults Don't Answer Who Owns the Agent
02

The Microsoft Agent Stack

Chapters 4-9

  1. 04Microsoft 365 Copilot
  2. 05Copilot Studio Agents
  3. 06Power Platform Automation
  4. 07Azure AI and Microsoft Foundry Custom Agents
  5. 08Agent 365 and the Orchestration Layer
  6. 09Multi-Agent Scenarios and Chain Authorization
03

The Authorization Layer Beneath the Microsoft Stack

Chapters 10-13

  1. 10The Authorization Layer
  2. 11Intent Architecture for Microsoft Deployments
  3. 12Microsoft Entra Agent ID and What Identity Doesn't Solve
  4. 13Microsoft Purview as Governance Backbone (and Its Limits)
04

The Operating Model

Chapters 14-17

  1. 14Tenant Agent Reconciliation in Microsoft Environments
  2. 15Authorization Coverage Lifecycle Across Microsoft Tools
  3. 16The Disposition Protocol and Microsoft Signal Sources
  4. 17The Agent Governance Toolkit and What It Cannot Prove
05

The Record

Chapters 18-20

  1. 18Agent Authorization Document for Microsoft Deployments
  2. 19The Examiner Returns
  3. 20Forty Minutes That Prevent Four Months

What it builds

Instruments, not diagrams

Each framework arrives as the answer to a documented failure. Each is published openly and separately in The Authorization Layer library, so a team can cite it without buying the book.

01

The Intent Architecture Stack

The three organizational layers that have to exist before any agent goes live.

02

The Chain Authorization Gap

One approval, granted once, still covering a multi-agent chain nobody has revisited.

03

The Accountability Assumption

The belief that accountability sits with the platform, and what it costs when tested.

04

Tenant Agent Reconciliation

What your tenant contains, measured against what your organization approved.

05

The Authorization Coverage Lifecycle

Keeping approvals current while the agents underneath them change.

06

The Disposition Protocol

Converting detection signals into recorded governance decisions.

Also inside: the Organizational Agent Controls, the Deployment Accountability Map, the Agent Substrate Readiness Model, and the Governance Readiness Matrix. Open the framework library

Appendix A

The Agent Authorization Record

One page. Ten entries. One record per deployed agent, retained as evidence.

No diagrams, no YAML, no hexadecimal beyond a single identifier string. It is the least technical artifact in the book and the one that has been missing from every chapter of it.

  • 01Agent Name
  • 02Business Sponsor
  • 03Business Purpose
  • 04Technical Owner
  • 05Authorized Actions
  • 06Review Trigger Conditions
  • 07Explicit Prohibitions
  • 08Next Scheduled Review Date
  • 09Data Access Scope
  • 10Authorization Signature
Open the digital version in the annex

Who it is for

The person who has to sign

  • CISOs and security leadership

    Answering for agent behavior in environments they did not approve agent by agent.

  • CTOs and enterprise architects

    Designing the layer beneath the Microsoft agent estate.

  • Compliance, risk, and audit

    Examination readiness when the evidence request is about authorization, not activity.

  • VPs of digital transformation

    Deploying agents faster than the governance record is being written.

Written for banks, insurers, healthcare systems, and government contractors. No vendor marketing. No futurism.

Back cover of Who Owns the Agent?, showing the book description and author biography.

Sourcing standard

Every claim is dated, and the fast half lives online

Every Microsoft capability claim in the book was verified against published Microsoft documentation and carries the date it was checked. Every incident comes from a named primary source. Nothing is drawn from confidential or nonpublic information.

Platform detail moves faster than a print schedule can track. Console paths, license boundaries, preview status, and corrections to this edition are maintained in the companion annex, updated one detail at a time as the primary sources change. Open the companion annex

The author

Sougata Roy

Technology manager and enterprise AI governance researcher, with 26 years inside enterprise systems and 13 years on federal engagements at agencies including the SEC, CFTC, and NIH as a contractor.

He publishes The Governance Gap, a weekly newsletter on enterprise AI accountability, and maintains The Authorization Layer, an open framework library on authorization architecture. Views expressed are his own and do not represent any employer, client, or agency.

Portions of this book adapt and extend previously published work: the white paper Who Owns the Agent? The Intent Architecture Stack (May 2026, DOI 10.5281/zenodo.20481551) and The Authorization Layer framework library (July 2026, DOI 10.5281/zenodo.21245690).

Forty minutes of writing, or four months of remediation.

It is the same document either way.