Cowork — Agentic AI, Copilot & Claude Skills
TL;DR: Cowork skills help you govern and use Microsoft 365 Copilot, Copilot Studio and agentic AI. They cover Copilot readiness, agent identity and audit, plus RACE-framework prompts (Role, Action, Context, Expectation) for everyday work. Read-only unless stated.
Start with what is an AI skill and the agent governance guide. For tenant hygiene before rollout, see the Copilot readiness guide and the Copilot governance guide.
How do I check Copilot readiness and Copilot Studio governance?
- Copilot Readiness Assessment
- Copilot Control System Governance Validator
- Copilot Studio DLP Gap Check
- Copilot Studio Agent Inventory
How do I govern agent identities with Microsoft Entra?
How do I govern autonomous agents, Agent 365 and Work IQ?
- Copilot Wave 3 Autonomous Agent Governance
- Agent Audit Trail and Forensics Investigation
- Agent 365 Tools and MCP Server Governance Baseline
- Agent 365 Registry and Unmanaged Agent Discovery
- Work IQ API Access and Tool Call Governance Audit
- Computer-Using Agent Risk Assessment
- Copilot Notebooks Data Governance Review
Which everyday workflow prompts are included?
All Cowork skills
What Is an AI Skill?
Agent skills, Copilot skills and this library's read-only audit skills are three different things. Learn the difference and where to start.
Governing AI Agents in Microsoft 365
Govern AI agents in Microsoft 365: Entra Agent ID, Agent 365 registry, Copilot Studio DLP, shadow agents, Work IQ and computer use, with read-only skills.
Copilot Readiness Assessment
Scores a Microsoft 365 tenant for Copilot readiness across licensing, sensitivity labelling, oversharing, Conditional Access and audit retention.
Entra Agent ID Audit
Inventories every Microsoft Entra Agent ID, flags agents with no accountable sponsor, and reports Conditional Access coverage per agent.
Conditional Access for Agents
Turn an AI agent's risk profile and data tier into a Microsoft Entra Conditional Access policy specification for admin review, aligned to Essential Eight.
Copilot Studio DLP Gap Check
Check Copilot Studio agents against the tenant DLP policy to flag missing, weak or bypassed Data Loss Prevention, aligned to Essential Eight.
Copilot Studio Agent Inventory and Connector Audit
Inventory every Microsoft Copilot Studio agent with its connectors, knowledge sources, sharing scope and DLP coverage, then flag ungoverned agents.
Copilot Control System Governance Validator
Validates Microsoft 365 Copilot Control System: data security policies, agent publishing approvals, and sensitivity-label enforcement for Copilot.
Secure Meeting Minutes
Draft formal minutes from notes or a Teams transcript in Microsoft 365 Copilot, with the meeting's sensitivity label, routing actions to named owners.
Stakeholder Update Email
Converts project notes into a concise 200-300 word stakeholder email with a consistent four-section RAG structure, drafted in Microsoft 365 Copilot.
Policy Document Template
Generate a consistently structured policy or procedure document with required governance sections in Microsoft 365 Copilot, ready for review and approval.
Onboarding Checklist
Work a new-starter onboarding checklist in Microsoft 365 Copilot: draft artefacts and raise access requests without auto-approving, for leader review.
Copilot Wave 3 Autonomous Agent Governance
Assess Microsoft 365 Copilot Wave 3 autonomous agent governance: approval-workflow coverage, data-scope limits, audit-log setup and human overrides.
Entra Agent Identity Sponsorship Lifecycle
Audit Microsoft Entra agent identity sponsorship: confirm every agent has an active human sponsor and flag agents without one for decommissioning review.
Agent Audit Trail and Forensics Investigation
Reconstruct what a Copilot or Copilot Studio agent did from the Purview unified audit log: actions, data accessed and who authorised each one.
Agent 365 Tools and MCP Server Governance Baseline
Audit the Agent 365 tools catalogue: available and blocked MCP servers, pending BYO MCP requests and per-agent tools in Defender, for a governed baseline.
Agent 365 Registry and Shadow AI Discovery
Compare registered and unmanaged AI agents using the Agent 365 registry, Shadow AI page and Defender for Endpoint local agent discovery. Read-only.
Work IQ API Access and Tool Call Governance Audit
Audit which agents hold Work IQ API grants to Microsoft 365 calendar, email, org chart and files, and check tool calls stay in the tenant trust boundary.
Computer-Using Agent Risk Assessment
Inventory Computer-Using Agents in Copilot Studio, the apps they can drive, human approval gates and audit log coverage for CUA actions.
Copilot Notebooks Data Governance Review
Review shared Copilot Notebooks: grounding sources, sensitivity label inheritance on outputs, guest and external access, and Australian data residency.