Governing Copilot and AI Agents Over Dynamics 365 Data You Do Not Fully Trust
For the leader asked to deploy Copilot this quarter over CRM data everyone knows is unreliable: what works today, what to expose, how to pilot safely, and what drives the cost.
Do not switch Copilot on across Dynamics 365 data you know is unreliable. First decide which records are trustworthy enough to expose, by measuring completeness, duplicates and staleness on the tables Copilot actually reads. Scope a pilot to a trusted cohort of users and records, keep it read-only before any agent is allowed to write, and put human review in front of anything touching personal or regulated data. Keep an audit trail of what the assistant saw and did through Dataverse auditing, Microsoft audit logging and agent transcripts. Control cost by knowing what drives spend: features included with Dynamics 365 licences versus Copilot Studio agents consuming capacity, capacity packs versus pay-as-you-go, and actions that consume more than answers.
Why is switching Copilot on over unreliable Dynamics 365 data the wrong first step?
Copilot does not fix data; it summarises and drafts from whatever the user can already see. If account records are duplicated, opportunity notes are years out of date and case histories mix two customers, the assistant produces fluent, confident summaries of the wrong facts, and it does so faster than a person reading the record would. The board sees a demo on clean sample data; the sales team sees a summary that names the wrong decision maker.
The pressure to deploy is real, and refusing outright rarely survives the next board meeting. The defensible position is a sequence: measure the data Copilot will read, expose only what passes, pilot narrowly with review, and widen scope on evidence. That turns "we are not ready" into a plan with a date attached to each gate rather than a veto.
- Wrong facts stated confidently: a summary built from a stale or duplicated record reads as authoritative.
- Over-exposure: an assistant respects security roles, so any over-broad access the security model already grants becomes easier to discover.
- Unreviewed personal data in drafts: an email draft can pull details from notes that should never leave the organisation.
- Cost without a baseline: consumption starts before anyone has agreed what a useful outcome would look like.
What can Copilot in Dynamics 365 actually do today that justifies the cost?
The honest answer is narrower than the marketing and more useful than the sceptics admit. Copilot works best where the value is saving a person from reading a lot of history they already have access to, or from writing the first draft of something a human will check. It works worst where it is asked to generate new facts over data nobody trusts. Exact feature names and availability depend on your licences, region and release wave, so treat the table as categories to test, not a feature list.
| Use | Works today when | Does not work when |
|---|---|---|
| Summarising long case, opportunity or email history | The timeline is attached to the right record and the history is broadly complete. | Activities are logged against the wrong account, or the important context lives in personal inboxes. |
| Drafting emails and replies | A human reviews every draft before sending, and tone and content come from approved wording. | Drafts go out unreviewed, or the source notes contain opinions and personal data that should not reach a customer. |
| Drafting proposals from approved templates | The structure, clauses and product descriptions come from controlled templates, and Copilot fills context from trusted fields. | The model is expected to invent pricing, terms or commitments; those belong in the quote and pricing engine. |
| Context at the point of work | A seller or agent gets a record briefing before a call, with links back to the source records. | The briefing is treated as the source of truth instead of a pointer to it. |
| Answers grounded in knowledge articles | Articles are current, owned and retired when obsolete. | The knowledge base is a dumping ground of drafts and outdated procedures. |
| Generation or analysis over untrusted data | Rarely, and only with a clearly labelled, reviewed output. | Forecasts, account health or next best action are produced from pipelines everyone already knows are fictional. |
Which Dynamics 365 tables and columns does Copilot read, and how do you measure their quality?
Start from the scenarios you intend to pilot, not from the whole database. Each scenario reads a small, knowable set of tables: the record itself, its related parent records, the activity timeline, notes and attachments, and, for knowledge-grounded answers, the knowledge articles or other sources an agent is connected to. Measure those, with numbers you can recompute every month, and publish the results before anyone argues about readiness.
The measurement below is a readiness check, not a full audit. If the numbers are poor across the board, or the security model itself is in doubt, run the Dynamics 365 health check and technical audit first, which covers data quality, security roles and configuration in depth, rather than repeating that work inside a Copilot project.
| What Copilot reads | Quality measure | Why it matters for AI output |
|---|---|---|
| Accounts and contacts | Suspected duplicates by name, domain and tax or registration identifier; share of records with an owner who still works there. | Duplicates split history, so a summary sees half the relationship. |
| Opportunities and cases | Records with no activity in a defined period but still open; required qualification fields empty; stage age. | Stale open records produce summaries of deals and issues that are already dead. |
| Activities and email tracking | Share of activities regarding the correct parent record; volume of emails tracked per active user. | Missing or misfiled activities are the most common cause of confident but incomplete summaries. |
| Notes and attachments | Sampled for personal data, opinions about individuals and content that should not appear in customer-facing drafts. | Anything in a note can surface in a draft; this is where compliance review concentrates. |
| Knowledge articles | Articles with an owner, a review date in the future, and no duplicate on the same topic. | Grounded answers are only as current as the least maintained article in scope. |
| Security roles and sharing | Roles and sharing rules granting broader read access than the job needs. | The assistant sees what the user sees, so over-broad access becomes more visible. |
How do you define and scope a trusted cohort for a Copilot pilot?
A trusted cohort is a set of users and records that passes your quality measures, is small enough to review, and represents real work. Built-in Copilot features generally work on whatever the signed-in user can access, so the practical levers are who gets the feature and what those users can see. Copilot Studio agents add a further lever, because you choose the knowledge sources and data an agent is grounded in.
- Pick one team and one scenario, for example key account managers summarising account history, or a single service queue summarising cases.
- Mark the trusted records explicitly, for example with a data quality status column set by a reviewed cleanup, so the cohort is auditable rather than a vague agreement.
- Scope the users through a security group or team, enabling the feature only for them where the product allows it, and keep everyone else on the current process.
- Where an agent is involved, ground it only in the views, tables and knowledge sources that belong to the cohort, not in the whole environment.
- Write down the exit criteria before the pilot starts: what reviewers must find acceptable, how often, and what would stop the pilot.
- Keep a control group doing the same work without Copilot, so the value discussion rests on comparison rather than enthusiasm.
Why should a Copilot pilot be read-only before any agent is allowed to write?
Reading and drafting fail safely: a bad summary is ignored and a bad draft is edited. Writing fails into the system of record, where a wrong update is copied to reports, integrations and the next summary. So the order is fixed: summaries and drafts first, then actions proposed by the assistant and confirmed by a person, and only then narrowly scoped actions that run unattended.
When an agent does need to change data, such as updating a case or creating a lead, build that action as a governed flow with validation and logging, as described on our Copilot Studio agent development page, rather than granting broad write access. The same flow is where you enforce which fields may change and who is recorded as having changed them.
| Stage | What the assistant may do | Gate to move on |
|---|---|---|
| 1. Read and summarise | Summaries and briefings for the cohort; no drafts leave the organisation. | Reviewers agree summaries are accurate on the sampled records. |
| 2. Draft for review | Email and proposal drafts that a person edits and sends. | Draft edits are light, and no personal or regulated data has leaked into drafts. |
| 3. Propose and confirm | Suggested record updates or next steps that a person confirms. | Confirmed updates are correct, and the audit trail shows who confirmed what. |
| 4. Act within limits | Specific actions through governed flows, on specific tables and fields. | Owner, monitoring and rollback exist for every action. |
Where do human review gates and compliance checks belong when PII or regulated data is involved?
Before rollout and at every point where content leaves the screen of the person using the assistant. Compliance review is easier when it is asked concrete questions about a defined pilot than when it is asked to approve "Copilot" in general. Solzet does not give legal or regulatory advice; your data protection and compliance teams make the calls, and we supply the technical facts and build the controls they choose.
- A data protection impact assessment scoped to the pilot scenario, the tables in scope and the users in the cohort.
- Confirmation of where prompts and responses are processed, including any tenant or environment settings that allow data to move across geographies for generative AI features, and a decision recorded on each.
- Column security or removal from scope for special category data, health data, financial identifiers and anything the regulator treats as sensitive.
- A rule that no AI-drafted customer communication is sent without a named person approving it during the pilot.
- A review of retention for transcripts and logs, so the audit trail does not itself become an unmanaged store of personal data.
- Staff guidance that states plainly what the assistant is for, what it must not be used for, and how to report a wrong or inappropriate output.
How do you produce an audit trail of what the assistant saw and did?
Assemble it from several layers, because no single log answers every question an auditor asks. Decide before the pilot which question each layer answers, confirm what is actually captured for the specific features you enable in your tenant, and test that you can retrieve an example end to end.
| Question | Where the evidence comes from | What to set up |
|---|---|---|
| Who changed a record, and was it an agent or a person? | Dataverse auditing on the tables and columns in scope, plus the identity the flow or agent runs as. | Auditing enabled for the environment, tables and columns, with a retention period agreed with compliance. |
| What did the user ask and what did the assistant respond? | Audit logging Microsoft provides for Copilot activity where available for the feature, and conversation transcripts for Copilot Studio agents. | Audit logging enabled and retained; transcript storage and retention decided deliberately. |
| What data was the assistant grounded in? | The documented scope of the pilot: cohort definition, knowledge sources and agent configuration, versioned in solutions. | Agent and configuration changes deployed through managed solutions, not edited live. |
| What was sent to a customer? | The sent email or document on the record timeline, with the approving user. | A review step that records the approver before sending. |
| Is the pilot still within its limits? | A periodic report of usage, actions performed and exceptions. | An owner who reads it and the authority to pause the pilot. |
What drives Copilot consumption cost, and how do you cap it?
We do not quote prices, because Microsoft sets and revises them, but the cost drivers are stable enough to plan around. Some Copilot capabilities in Dynamics 365 apps are included with qualifying Dynamics 365 licences, subject to region and admin settings. Copilot Studio agents are billed on consumption, in units Microsoft defines per type of interaction, bought as prepaid capacity or billed pay-as-you-go through an Azure subscription. Generative answers and agent actions generally consume more than simple scripted responses, and autonomous agents triggered by events consume without anyone typing a message. Check the current Microsoft licensing guide for the specifics that apply to your agreement before committing a budget.
- Know which of your scenarios use included app features and which need Copilot Studio capacity; the budget conversation is different for each.
- Allocate capacity to specific environments so a pilot cannot draw down capacity intended for production agents.
- For pay-as-you-go, set Azure budgets and alerts on the billing subscription, so overspend is noticed in days rather than on the invoice.
- Limit channels and audiences: an internal agent in Teams for a cohort costs a fraction of the uncertainty of a public website agent.
- Review autonomous triggers carefully; an event-driven agent on a busy table can consume steadily without any user involved.
- Measure consumption per scenario during the pilot and use that, not a vendor estimate, to model wider rollout.
When is a different tool, or no AI at all, the better answer?
We recommend the right solution - whether that's Microsoft Dynamics 365, Power Platform, or a custom-built CRM. Some businesses need the Microsoft ecosystem. Others need full control without licensing. We deliver both.
The same honesty applies to AI. If the underlying process is not in the CRM at all, a Copilot rollout adds cost to a system people avoid; fixing the process and the data comes first, and for sales teams our Dynamics 365 Sales implementation page describes that work. If answers must be fully deterministic and traceable at every step, a structured app or automated flow is better than a conversation. If Microsoft licensing does not fit the organisation, a custom CRM on React, Node.js, PostgreSQL or .NET can include narrowly scoped AI features where you control the model, the data sent and the logging.
Is Dynamics 365 with Copilot the right platform, or would a custom CRM fit better?
Can afford licensing and want the Microsoft ecosystem
Dynamics 365
Microsoft 365, Teams and Outlook integration, a mature partner ecosystem, Copilot, and apps for sales, service and field operations that are configured rather than built.
Need full control and zero licensing
Custom CRM
A CRM built on React, Node.js, PostgreSQL or .NET that you own outright: your data model, your hosting, no per-user subscription, and features shaped exactly to your process.
Not sure which fits
We help you decide
A short discovery weighs licensing budget, process complexity, integrations and long-term ownership, then recommends one path. We deliver both, so the recommendation has no reason to lean.
How does Solzet run a Copilot readiness and governance engagement?
Senior consultants with 8+ years of Dynamics 365 Customer Engagement and Power Platform delivery run it as a short sequence with a decision at each gate. It produces a pilot you can defend to the board and to compliance, or a documented reason to wait.
- Scenario selection with the business owner: which one or two uses are worth testing and what a useful outcome looks like, described qualitatively rather than as a promised return.
- Readiness measurement on the tables those scenarios read, or a full health check where the wider build is in doubt.
- Cleanup of the trusted cohort, security scoping and the compliance pack: scope, data flows, settings decisions and review gates.
- Pilot configuration, including any Copilot Studio agents and governed flows, deployed through managed solutions.
- Audit trail and consumption monitoring set up and tested before users start.
- A pilot review against the written exit criteria, with a recommendation to widen, adjust or stop.
What do people ask us?
Should we deploy Copilot in Dynamics 365 if our CRM data is messy?
Not across the whole system. Measure the quality of the tables your chosen scenarios read, clean and mark a trusted cohort of records, and pilot with a small group of users on that cohort, read-only first and with human review of anything sent to customers. Widen scope only when reviewers agree the outputs are accurate. Messy data does not make Copilot useless, but it makes unscoped rollout risky.
What can Copilot in Dynamics 365 do that is worth the cost?
The most dependable value is summarising long case, opportunity and email history for someone who would otherwise read it all, drafting emails and proposals from approved wording for a person to review, and giving context before a call or case. It is least dependable when asked to generate forecasts, analysis or commitments over data nobody trusts. Availability of specific features depends on your licences, region and release wave.
Is AI drafting of proposals and emails inside Dynamics 365 worth it for a sales team?
Often, if the drafts start from approved templates and trusted fields, and a seller reviews every draft before it is sent. It saves writing time rather than thinking time. It is not worth it if the source records are stale or duplicated, or if drafts are expected to invent pricing and terms, which belong in the quote and pricing process.
What should a compliance review cover before a Copilot rollout?
A data protection impact assessment scoped to the pilot, where prompts and responses are processed and any settings that allow data to move across geographies, which sensitive columns are excluded, the human approval rule for customer communications, retention for transcripts and logs, and staff guidance. Your compliance team decides; Solzet supplies the technical facts and builds the controls, and does not give legal advice.
How do we keep an audit trail of what Copilot or an agent saw and did?
Combine Dataverse auditing on the tables in scope, the audit logging Microsoft provides for Copilot activity where available for the feature, conversation transcripts for Copilot Studio agents, versioned agent configuration in managed solutions, and a record of who approved each customer-facing output. Confirm what is captured for the exact features you enable and test retrieving an example before users start.
What drives Copilot Studio cost, and how can we cap it?
Consumption by agents, in units Microsoft defines per interaction type, bought as prepaid capacity or billed pay-as-you-go through Azure. Generative answers, agent actions and autonomous triggers are the main drivers. Cap it by allocating capacity per environment, setting Azure budgets and alerts for pay-as-you-go, limiting channels and audiences, reviewing event triggers, and measuring consumption per scenario during a pilot. We do not quote prices; check the current Microsoft licensing guide.
Can a Copilot Studio agent update Dynamics 365 records safely?
Yes, once reading and drafting have proved reliable. Build each write as a governed flow limited to specific tables and fields, with validation, logging and a clear identity recorded as the changer, and start with actions a person confirms before moving to unattended ones. Avoid granting an agent broad write access to the environment.
Does Solzet build the Copilot pilot as well as assess readiness?
Yes. We measure readiness, clean and scope the trusted cohort, prepare the technical input for compliance, configure Copilot features and Copilot Studio agents, build governed flows, and set up audit and consumption monitoring. Where the whole implementation is in doubt, we start with a health check instead.
Where should you go next?
Copilot Studio agent development
Agents grounded in Dataverse and SharePoint, with governed actions, Teams deployment and capacity planning.
Dynamics 365 health check and technical audit
Data quality, security roles, configuration and ALM assessed with evidence before you build on top.
Dynamics 365 Sales implementation
The sales process, data model and Copilot features configured deliberately rather than left on by default.
Custom CRM Development
CRM on React, Node.js, PostgreSQL and .NET for organizations that need full control without Microsoft licensing.
Power Platform ALM
Managed solutions and pipelines so agent and configuration changes are versioned and reversible.
Which solution is right for your business?
Tell us what you need. A senior consultant replies within one business day with a recommendation - Dynamics 365, Power Platform, or a custom-built CRM - not a sales script.