Step-by-Step Guide to Creating SharePoint Agents

Part 3 of the series is all about creating SharePoint Agents! From a quick summary of what they are to a step-by-step guide, by the end of this video, you’ll be ready to create one yourself.

Watch my 90+ courses on Pluralsight (opens in a new tab)

Video Summary

  • Creating SharePoint Agents: You can create agents directly from the site homepage or specific document libraries. The default grounding will be the site or library where you clicked the button.
  • Permissions and Approvals: Members can create agents, but they won’t be visible to everyone until a site owner approves them. Be cautious with permissions, as members can edit or delete agents unless restricted.
  • Managing Agents: Approved agents are moved to a special folder. Site owners can restrict members’ permissions to prevent unauthorized edits or approvals.
  • Restricted Content Discovery (RCD): Enabling RCD on a site will prevent it from having Copilot agents and being used as a source for other agents. This is a secure way to protect sensitive content.
  • Practical Tips: Always ensure agents are grounded in relevant content for better quality responses. Use the least amount of high-quality data to improve the agent’s performance.

For more information, read the transcript blog below, or watch the video above!

Video Transcript

Do you ever feel like the results you get from Copilot are not based on the information you expected, or do you wish you had an agent specialized in or that only looks at a subset of your Microsoft 365 data, but you don’t know how to code? Well, you’re in luck because I don’t know how to code either, but I’m able to create that thanks to SharePoint agents.

In this series, I’m joined by Sebastien Levert, an amazing developer and principal PM manager at Microsoft on the Copilot DevX team. Seb, welcome back. Thank you for having me. This one is a bit funny because you’re going to lead most of the episodes in the series, but we’re now at the second episode, and this one has no code.

Yes, so I’ll take the lead on that. I’ll do all the stuff with no code, and I’ll let you do all the code stuff, or not all of them actually have code inside after, but still, most of them will. For those of you that are just joining us for the series, this is the third episode. So if you haven’t watched the series intro and the terms and concepts, after this video, I invite you to go back there, see why we’re doing this series, and especially the terms and concepts video covers that important foundation that you need so we know we speak the same language, you know the terms we use, and all of that. But with that out of the way, let’s get started talking about Copilot agents in SharePoint.

It’s not the first time I cover Copilot agents in SharePoint on the channel, but it’s the first time since they went generally available. SAA announced them at Microsoft Ignite in November 2014, and today you have an agent in every single site that is grounded only in the content of that site. So whether you want SharePoint agents or not, every site has an agent built in, and site members and site owners can build additional agents.

Okay, so we’re now in this SharePoint agents demo site, and you will notice that at the top right, I have the Copilot icon over here, which will open my agents. The default agent that you have has the same name as the site, so my site name is SharePoint agents demo, my agent name is SharePoint agents demo, and it even shows that this is the default agent for the site. We’ll be able to change that in the future.

This agent will be grounded in all of your data inside the site, or almost all of it. I said that I’m not going to do slides, but there’s one slide that I want to get back up here because the question that I get the most often is, is the agent trained on SharePoint lists? And it is not right now, and I’m not going to name all of them because you can read the screen, but on the screen right now, you have all the data that Copilot agents in SharePoint are being trained on.

Today, it does not include images, meeting recordings, videos, and OneNote notebooks, but Microsoft said it will be supported in the future, so maybe by the time you watch this video, it will be there, but no lists as of today. Now, let’s go and create our own agent. So I can go here at the drop-down, and I can create an agent. Just doing that is really funny because you just click that, and then you have your agent ready. You haven’t even customized anything, entered anything, and you have an agent. But let’s go and edit it a bit more.

First thing I need to do is to give it a name. Seb, how should we name it? I think we should call it the Poutine agent. The Poutine agent, and I feel like the editor will need to add a bit of a definition on screen of what is poutine with maybe some images. Yeah, a lot of images. A lot of images. I love to see one there, there, there, there, everywhere. The screen filled with poutine. So this is an agent created based on the content from this site and specialized in poutine questions. Well, that’s not the content I kind of prepared for the demo, but we’ll roll with it. So this is the identity. So really, what will it look like? Let me see. Do I have any images or logos here that I can add? Let’s go to downloads. I have a logo here. Let’s go and change it. If I go to pictures, do I have anything? Camera roll. I’ll just put a picture of myself like this. What can go wrong? But please work with your marketing department to get proper pictures, proper names, and all of that. But this way, we have a picture there, and you can see what it will look like as you build your agent.

You always have the agent tester. I don’t think that’s the official name, but I call it the agent tester right here. Then you can go and taste test. We talked about poutine, so I said taste instead of test. You can test your agent. Really important. What you’re probably going to want to do is to filter the sources. You can choose up to 20 sources for each agent. By default, it will add the entire site that you’re currently on, so you can either source it from there, or you can add only certain document libraries from that site. In this site, I had two different libraries. I had the Teams knowledge base and the Tech Plus knowledge base. Let’s go for the Teams one here. Can I just select this? Yes.

So all the documents inside that document library, but you’ll notice that it left me, if I want to, I can say all those documents plus this one over here. So you can even select one specific document from the list of approved documents that we looked at earlier. A little bit of a tip here. I think to build a great agent, try to limit the amount of content that you ground your agent in. Sometimes you’re going to have these contexts of it’s this entire site, and that’s basically what it is. But when you can really elect sources, folders, document libraries, that is your key content. The response coming back from Copilot will have greater quality because it’s going to make a decision on less content. So think about that when you build it. The least amount of good quality data that you have, the better your result will be. That is the goal. But something that is really cool, I can even add other SharePoint sites.

So for example, let’s call it conference resources. I know I have a site. I have two sites apparently that are named the same thing. I can also go and find some document libraries or some documents in that specific site. So it doesn’t only have to be on one single site. It can be on more SharePoint sites. But always remember what Seb said, the least amount of good quality data. That should be your goal. Also, I’ll remove it for now, but also really important, if you choose the root site of a hub, all the sites part of that hub site will be added. So let’s say you add your intranet, but your intranet has 50 other sites connected to it, and that is your root hub. All 50 sites will become the source by default if you select that whole site to be the source. So be careful. Make sure you use as little data as possible. And then we have the behavior. Now, this is something that you covered when we talked about the terms and concepts. How do we want the agent to act? First of all, I have my welcome message here. So I can say, “Okay, welcome. I am Poutine Agent 007, here to answer all your questions about Microsoft Teams and poutine.” There we go. Like this. I can say, “This is what people see.” And then I have my starter prompts. Those are, you know, when somebody opens your agent and they have no idea what to ask it, what are some of the example questions that you think will give them the most value if they ask? So I can say, for example, even if it’s the poutine agent, we kind of have it trained on Teams content. So I can ask, “What is a Microsoft 365 group? What are the different ways to enable external sharing in Teams? And can I turn off stickers inside Teams?” So those will be my starter prompts. And you can see it live over here in the poutine agent on the right. Everything you do, even before you click on save, is live.

And then I have my instructions. So I’m giving this agent its identity because right now it’s just a generic agent. I can tell it, “You are a tech support agent that helps IT professionals answer support questions about Microsoft Teams. Your answers should be short and professional.” And after that, because it’s the poutine agent, I’ll say, “And every answer with a fun fact about poutine.” And just to be clear, I’ll just put here, “The Quebec food dish,” maybe just because I don’t know what else is going to come up with. So the more exact you are, the better it will be. So here, let’s ask it, “What is a Microsoft 365 group?” Let’s go see if it will be able to go in here. It should only go inside the sources I selected, and the answer should be there. So like it finished, okay, I won’t look at the fun fact yet. We have a Microsoft 365 group is a collection of resources in Office 365 and the whole definition. I look at the source where it comes from. It comes from the file inside that library. Perfect. I don’t want it to ever go outside. I don’t want it to go to the web, to a random Reddit post. I want it to only answer stuff from my current site. And then at the end, I added a fun fact about poutine. Did you know that the word poutine is Quebec slang for a mess? It’s a fitting name for this deliciously messy dish. Today I learned that; I did not know that before. It’s great to learn new things every day. You see, it comes from this site. You know what it does exactly what I want. Before I click on save, you do have the option to add advanced customizations in Copilot Studio. We’ll talk about that in a future video.

Today, we’ll only stay inside of SharePoint. Let’s click on save here. So, where is this agent saved? You’ll see it here at the bottom right. I’ll even zoom in a little bit. The agent is saved under Copilux, the poutine agent. This basically goes into site assets. If we take a look at how to get here without that link, you go to site contents, then you go to site assets, Copilux. I wouldn’t be surprised if this gets changed to agents in the future, but for now, it’s Copilux, and then you have the poutine agent. Now, I will show you something. Let me download this here. Let’s see, do I have Notepad++ here open? If not, I can just open it with Notepad. It doesn’t really matter. This is, and let me drag it in here. You probably need to prettify it to see. Oh, did they change that? I think here, what you see right now is the comp of your image. It’s your image transformed as a Base64 thing. You are right. Let’s go here. Can we go on pretty JSON, not pretty little things? JSON formatter, I like this one. Make CR, there we go. Now it’s a lot easier to consume. Can I make this one full screen with this thing? Yeah, you’re right. You see, the whole thing that I thought was encrypted is just my super image. Exactly.

Okay, if we scroll down past the image, it might be up. You think I passed it, and that’s just the image at the end. This became so big, I don’t even see my scroll bar anymore. Okay, so everything, all the fun things are at the top, right? Yeah, okay, so I went down there for nothing. But anyway, this is your agent definition. You can see that you have a custom Copilot config. You can see your conversation starter list, exactly what I typed in the UI option. I can have it here, the welcome message, the GPT definition, and a lot of the things that we talked about, the terms and concepts such as the capabilities of an agent. You can see them in the definition here. However, really important, it’s not supported to just build your own agent by creating the JSON or modifying the JSON through here. Can you do it? I haven’t tested it yet, but it’s definitely not supported to do it. But this is really cool if ever you want to inspect it or if ever you want to, I don’t know, let’s say you want to source control it. You could download it, put it somewhere to keep what it was at a certain point in time, something that you could do.

Great, now if I test it here, let’s go here to Copilot. I can switch to, and it just decided to not appear yet. It does have a certain amount of caching. Let me do Control-R, Control-F5, all the control refreshes for good luck. The more you do, the more chances you have of it being good. Let’s go here, Copilot again. Give it a few seconds. It’s shy. You got this, Copilot. Copilot is on break right now. Copilot, Copilot, it’s time for lunch probably. There we go, it opened, and now I still do not see my poutine agent. If ever this happens to you and you just cannot wait to actually go try it out, you can always go back to site assets, and you should be able to just click on the poutine agent here, and you can interact with it in this view rather than the sidebar. It’s just a caching thing. Also, pro tip, make sure you check your spelling when you do your starter prompts or the description because there’s an F missing over here.

So, can I turn off GIFs inside a specific team, and how about the whole tenant? Let’s see if it’s able to answer that based on the content I have there. I’m not sure if I have the whole tenant in there. The reference, it did take the right one, and it told me how to do it too. So, I go to the Teams admin center, manage teams, and under settings, you can disable the use of GIFs and how to do it for the whole tenant with messaging policies. Pretty good. Fun fact, the word poutine has originated from the English word pudding. Interesting. We learn new things every day. So, every day, I didn’t learn, I didn’t know that many things about poutine ever. But now, let’s move on to the next thing I want to cover. I kind of wanted to show before I show you the next cool thing. Also, Seb, did you know that from the Copilot agent here, from the Copilot pane, you actually see your agents in other sites as well as recommended for you? So, you don’t only see the agents in this site. They’re always available. They’re following you, right? They’re following you around. You can get rid of agents like you can get rid of Copilot marketing. Whatever site you go to, it will be there. But okay, before we go test it, I want to show you something. So, I’ll log here as Vanessa, and you’ll see Vanessa is basically a member, not an owner of the site. And Vanessa here will not see the agent that we just created. This is because in order for it to show for everybody, that agent needs to be approved for the site. How do we do that? You need to go as an owner. So, let me go back. There’s multiple ways to do it. The way that I like to do it here, we can go to site assets, we can go to Copilot. Let’s go here, open this Copilot. You can go and set it as approved. Do you want to set this one as an approved agent for the site? Yes, I do. Let’s do it. Great. Give it a few seconds. That’s good.

Let’s do here a refresh, and you see my agent file is not here anymore. It got moved to the approved folder. Now, if I go back to the homepage here, and I go to the Copilot icon, and here, first of all, I’m back to Vlad. This agent will show up under approved for this site, so I can switch to it. And if I go to Vanessa, let’s do a refresh here. I should now see it. There might be a bit of caching. It can take a few minutes, but with a little bit of luck, I should see. There we go, the poutine agent, and Vanessa can use this agent. Remember that the file permissions will always win. So, even if Vanessa can access this agent, if this agent is trained on or has a knowledge base of things that Vanessa does not have access to, those sources will not be returned. That data will not be returned to Vanessa. So, it’s still secure by default. You cannot trick Copilot by creating a SharePoint agent that has access to everything, and then everybody kind of has access to that, like a service account or things like that that we used in the past. Always the file permissions will win. If Vanessa doesn’t have access to something, even if that knowledge base, that SharePoint site is inside the agent definition, it will not be taken into consideration. Exactly, and it means that answers will be different from one user to the next. They’re going to be grounded in the content that they’re allowed to hear. Potentially, Vanessa will learn about poutine facts without real grounding if she doesn’t have access to any of the files. What I mean, she has access to one or two, and then the entire grounding will be just for these files. Awesome.

Now, a few things before we finish. We kind of covered how to do the basic things, but a few things I want to show you. First of all, I showed you how to do the agent. Kind of from here, creating a new agent. Members, see, I’m with Vanessa here. She can also create agents, but they will not be visible for everybody until a site owner approves them. Also, you can create an agent from here on the page, and even if you go to a specific document library—I’ll zoom out just a little bit so you see it more in a normal view as you would work. We’re very zoomed in. You also have “Create an Agent.” So if I go to the Tech Plus KB here, where I have data, if I click on “Create the Agent,” it will automatically be grounded on the library where I clicked the button. So my default grounding is if I’m on the site homepage, it will be the site. If I’m in the document library, it will be the document library. I’m curious now if I do a folder, and I’ll put “Test Folder,” will it just be that folder? Let’s click on “Create” here.

Let me go into the test folder, and if I create an agent here—okay, it still does the document library, so not the folder-specific, but still, it will be grounded on where you told it to. Also, really important, let me just do “Edit” here, Vlad, just to add something to it. Click on “Save.” It will be saved directly in the document library. So if I do a refresh here, if you create it from a document library, it will be saved in that document library. You will need to be careful with permissions, especially if you’re a SharePoint admin or governance, because remember that members have added permissions by default. So a member, any member, if I go to the “Manage Access” here, not only Vanessa, but any member part of this site can edit or delete this file. So I can go here, I can delete it. Something else you need to be careful with—I’ll go, and again, I’m Vanessa. Remember Vanessa, a member here. Microsoft made it to be super easy that everybody can do it. So I will edit this. I’ll call it the “Better Puttin Agent” here and “Puttin Sources.”

It doesn’t really matter. I just want to create an agent here. I’ll save it. You see, this will go to the site AXS, but what do we know is that the only way that SharePoint knows if an agent is approved or not is if it’s in the approved folder. Now, if we look at the approved folder permissions—so let me go to “Manage Access” here—we see that the demo members have added permissions to this folder. So nothing stops an ill-intentioned user or a user that just knows SharePoint really well to go in and drag and drop this folder to approved, even if through the UI. So if it doesn’t matter, I’ll just—if I go from here, I couldn’t set one as approved. So just to show it to you real quick, now if I go to agents, I see the “Better Puttin Agent” as approved, but from the user interface, that would not work. So I’ll move it back to Copilux. Give it a second. From the user interface here, I should not have the “Set as Approved” option, but really be careful because a user that knows SharePoint could just go and drag and drop it. And assume here that there are opportunities to secure either that folder or to bring some approvals as part of Power Automate or these kinds of things, right? I’m not sure about that. Okay, so the official Microsoft answer is that you cannot block just site members from creating and modifying agents. And I know this is a different team than you that manages all of that. Two things that I want to show you before—so the way that I found, which I’m not 100% sure on supported yet, but technically nothing stops you from going here, breaking permission, and saying, “You know what? They can only view.” And now the members can only view stuff and approve. They cannot edit it anymore. It also means that the owner of an agent that just got approved now cannot edit their agent anymore. Exactly. Okay, so that’s the downside.

Once an agent is approved, a site owner can do it. Only a site owner can do it. And I also tried—I’m an IT pro, I like to break things, you know—but now this, because we only changed it on the approved one, this doesn’t stop Vanessa from creating new agents, which is kind of cool. So Vanessa, my member, can still go here. I should have probably given it a different name so we know which one. “Agent Vanessa One” here. Let’s click on “Save.” You see, I can still create it, but I cannot move it to approved. Good. Something that I tried, because you know I like to break things, I tried to go in and—what happens if I break the inheritance on all the things here on the Copilux folder completely? So, well, let’s do it. There’s no better way to learn than to actually do things. Let’s change it. Great, now it’s done. Can I still create an agent as a member here? Let’s go to here, “Create New Agent.” I’ll edit. I’ll say here, “Vlad Two.” This is as Vlad, by the way, so this is as an owner. This should work. Yes. But if I go do it as Vanessa—so new agent based on the whole site—let’s click on “Edit Agent.” Vanessa Three, I forgot what we were at. Click on “Save.” You don’t really get a nice error. I don’t think that’s supported to play with all those permissions, but it’s still fun for—I’m testing it for you—what would happen. You don’t get a pretty error. You really get an error like this. Yes, that’s what you can do. But remember, I can probably still—I’m curious, can I still create an agent over here? I’ll call it “Documents Agent Two.” Click on “Save.” No. So because I broke permissions on that library, I cannot even create it in a document library, which is maybe what some of you might actually want as administrators. But now, if you want to do it the right way, let me search for a site here. Am I as Vanessa here? That’s why I cannot find it.

Let me go as Vlad. And there is a site that I have called “Sam 7 RCD.” RCD stands for Restricted Content Discovery, and it’s part of SharePoint Premium Advanced Management, which as of Ignite is included for everybody that has Copilot licenses. What do you notice? This site here doesn’t have the Copilot icon at the top. Any site that has RCD enabled will not have Copilot agents in SharePoint enabled and also cannot be used as a source in any other agents. So if, again, I go back to Vlad, so I have access to that site. Let me go create a new agent, edit it. I’ll put here “Plus Sam 7.” If I go to sources, I put the URL. It does not find that site. So if you want to protect a site from being used with SharePoint agents, turn on RCD on it. I have a full video on it on my YouTube channel. The link will be in the description below. But that’s the proper way to restrict a SharePoint site from having agents. The permission way, the way that I did it here, I tested it for you, is not the official or recommended way. It works, but you shouldn’t do it.

Did I miss anything else for SharePoint? I don’t think so. I think that’s a great coverage of the capabilities, and I’m really looking forward to seeing that. I know at Microsoft we’re using heavily the agents in SharePoint for building tailored experiences inside SharePoint as you’re navigating our intranet or HR web and all of that. So it’s great to see how these things can be built. But also, I think it’s going to be great to also give you the option of how you can do that directly from within Copilot to achieve similar results there. So that’s going to be great in the next follow-up of the series. Well, I hope you found this video valuable, and if you enjoyed the series so far, please connect with us on social media. You’ll have all the links for both Sebastien and myself below. Again, really hope you found this video valuable. Make sure to check out the next episode in the series, which should be on your screen right about now. And of course, make sure you hit that subscribe button to get notified as soon as new episodes are available. And on this, are we going to start doing code in the next one or not yet? Not yet. Not yet? Okay, we’re still going to be no code in the next one. So I’ll see you there. Cheers.