All insights
Industry newsSep 02, 2026Source: Orchestry

Orchestry launches Microsoft 365 AI agent inventory and risk controls

A Microsoft 365 governance team reviews agent owners, content access, connectors, and risk findings

Orchestry launched AI & Agents on September 1, 2026 for Microsoft 365 governance. The new Enterprise feature creates a tenant-wide inventory across Microsoft 365 agent sources, links each agent to its owner, content, access, and Power Platform dependencies, assigns a risk score with named findings, and lets authorized administrators remove an agent while retaining its deleted status in history.

The governance consequence is practical. Microsoft 365 agents can be created across several administrative surfaces and inherit access to existing content. A list of agent names is not enough to show which information an agent can read, which connector it can use, who owns it, or whether a cleanup action was recorded.

What Orchestry released

Orchestry's product article describes a single roster assembled from Microsoft 365 admin surfaces, Power Platform, SharePoint, and Teams-related agent sources. The roster includes agent type, status, creator, creation date, publication scope, and named governance findings.

For each agent, the product presents:

The company also describes a scoped AI & Agents Admin role that can be assigned to people or groups without granting wider platform administration. Assignment changes are logged. AI & Agents is rolling out on the Enterprise plan, while AI readiness scoring remains available on other plans. Orchestry says the feature works with existing Microsoft 365 E3 and E5 licensing.

These are product and vendor statements. PR Newswire reproduces the company announcement and confirms the launch details, but it is not an independent performance test. The public evidence does not establish detection completeness, risk-score accuracy, deletion reliability, or operating outcomes across representative tenants.

Why agent inventory needs context

An agent inventory becomes useful when it connects the agent to authority and exposure. The same agent name can represent very different risk depending on who created it, what it reads, which tools it can call, and who can invoke it.

Inventory fieldGovernance reason
Owner and creation dateestablishes responsibility and supports review when roles change
Publication and access scopeshows who can invoke the agent
Knowledge sourcesidentifies content the agent may retrieve or expose
Connector and environmentreveals external systems and deployment context
Data-loss-prevention policyshows which platform restrictions should apply
Risk finding and score basislets reviewers inspect the reason behind a priority
Status and deletion historypreserves evidence of remediation and change

The score should guide attention, not replace judgment. A composite number can hide a severe single exposure or overstate a combination of lower-impact conditions. Reviewers need the findings, thresholds, source records, and current system state behind the score.

Controls for a Microsoft 365 agent inventory

  1. Define discovery coverage. Record which Microsoft 365 agent types, environments, sites, and lifecycle states are included. Mark unsupported or not-yet-covered objects rather than assuming completeness.
  2. Resolve owners to accountable people. A creator may have left, changed teams, or built an agent for someone else. Add a business owner and technical owner where consequences differ.
  3. Inspect inherited content access. Review anonymous links, tenant-wide sharing, broken inheritance, sensitive sites, and permissions held through the creator or another connection.
  4. Map connectors to capabilities. A connector is not only a technical dependency. It defines what data an agent can read and which external actions it may take.
  5. Separate visibility from authority. The people who review risk do not always need broad tenant administration. Scoped roles and logged assignments reduce unnecessary privilege.
  6. Review destructive actions. Deleting an agent should require the correct identity, clear target, impact statement, and evidence that the intended object was removed. Retain the decision and result.
  7. Track change over time. New knowledge sources, connectors, sharing rules, versions, and ownership can change risk after the initial review.
  8. Validate the risk model. Sample high and low scores, inspect thresholds, record disagreements, and test whether remediation changes the underlying finding as expected.

Maetra's AI agent inventory guide explains how to connect agents, repositories, tools, data access, owners, and changes. The AI audit evidence guide helps preserve review and remediation records.

What remains uncertain

Orchestry says one referenced enterprise tenant contained more than 3,000 links shared with anyone before cleanup. That is a vendor-reported example, not a general prevalence estimate. It should not be used to predict another tenant's exposure.

The public materials do not provide an independent benchmark for discovery recall, false positives, scan timing, risk-score calibration, or deletion behavior across every Microsoft agent source. The product article also identifies future work around content-level analysis, agent review policy, access management, usage and cost analytics, and proactive cleanup. Those roadmap items are not current release features unless separately confirmed.

Maetra analysis

The significant part of this launch is the attempt to join discovery with evidence and action. Teams need more than an agent registry. They need to know what each agent can reach, which platform objects grant that access, who owns the result, and what changed after a review.

A credible inventory should keep uncertainty visible. If one agent source is not covered, if an owner cannot be resolved, or if a risk score depends on incomplete content analysis, the record should say so. Governance improves when the inventory exposes gaps and assigns them, not when a dashboard turns incomplete discovery into a precise-looking number.

Sources

OrchestryMicrosoft 365AI agent inventoryAI governance
Orchestry launches Microsoft 365 AI agent inventory and risk controls | Maetra Insights