Is your business exposed? Run a free domain security audit in 60 seconds
CyberBITS
Microsoft Copilot 18 July 2026 · 9 min read

Your First Microsoft Copilot Agent: A Safe Setup Guide for Manufacturing & Engineering Firms

Thinking of using Microsoft Copilot agents in your manufacturing or engineering business? Here's how to switch one on safely — without exposing years of drawings, quotes and shared files. A practical guide for West Midlands SMEs.

rob-shaw-founder

Founder

Robert Shaw

An engineer reviewing technical drawings on a laptop beside a CNC machine, illustrating a safe Microsoft Copilot agent setup for a manufacturing business

Short answer: A Copilot agent can only see what the person using it can see — but in most manufacturing and engineering businesses, that's the problem. Years of technical drawings, customer quotes, supplier pricing and tender documents have quietly accumulated in over-shared folders, and the person running the agent can usually see far more than anyone realises. So the safe way to start is: tidy your permissions first, then switch on one ready-made agent — we'd suggest Microsoft's Researcher agent, which is included with a Microsoft 365 Copilot licence and needs no build work — and roll it out to a small pilot group before anyone else. Here's how to do that, step by step.

The one thing to understand before you switch anything on

Every Copilot agent inherits the permissions of whoever runs it. It doesn't get special access, and it doesn't bypass your security — it simply works with everything that user could already open, whether or not they knew they could.

That last part is the catch. In a 10–30 person firm that's been on Microsoft 365 for a few years, almost nobody could tell you exactly what they have access to. Folders were shared in a hurry to hit a tender deadline. A drawing pack was put somewhere convenient so a subcontractor could get at it. Someone set a folder to "Everyone" in 2021 because permissions were getting in the way that week. None of it caused a problem, because finding those files meant knowing where to look.

An agent removes that obstacle. Ask it a question and it will cheerfully pull together an answer from anything the user's account can reach — including the salary spreadsheet saved to a shared drive by mistake, the quote you did for one customer's competitor, and the commercial terms from a tender three years ago. Nothing has been breached. Your permissions are simply being read back to you, accurately, for the first time.

So the honest framing isn't "is Copilot safe?" It's "is our file sharing in a fit state for a tool that actually uses it?"

Why this bites harder in manufacturing and engineering

Every business has some file sprawl. But the manufacturing and engineering firms we work with across South Staffordshire and the wider West Midlands tend to have a particularly potent version of it, for reasons that are baked into how the work happens:

  • Projects generate a lot of files, fast. Drawing revisions, specs, BOMs, quality documents, customer correspondence — a single job can produce hundreds of documents, and the folder gets shared with whoever needs it that month.
  • The sensitive and the routine live side by side. The folder with the CAD drawings often also holds the costing sheet. The tender submission sits next to the supplier pricing that went into it. ISO and audit documents mingle with HR paperwork.
  • External sharing is normal. Subcontractors, clients, machine suppliers and consultants all get links. Some of those links were set to "anyone" and never expired.
  • People leave, access doesn't. An estimator who left two years ago may still be in the membership of half your project folders — and the person who inherited their login inherits all of it.

None of this makes anyone careless. It's the natural sediment of running a project-based business. But it's exactly the environment where switching on an AI tool without looking first can surface things you'd much rather stayed buried.

Lock down first: a practical pre-flight check

You don't need an enterprise governance programme. For a firm of 10–30 people, a focused half-day covers most of it:

  1. Find out what's shared with everyone. In the SharePoint admin centre, review which sites and folders are shared broadly — anything granted to "Everyone" or "Everyone except external users" goes on the list. These are the folders an agent will treat as fair game for every member of staff.
  2. Hunt down "Anyone with the link" shares. These links work without a login and never show up in your mental model of who can see what. Review them, expire the old ones, and change the tenant default so new links go to specific people rather than anyone.
  3. Check the commercially sensitive folders by name. Quotes, tender documents, costings, supplier pricing, payroll, HR. For each, ask one question: who can open this today, and should they? This is where the real damage lives, so do it deliberately rather than hoping the general tidy-up catches it.
  4. Remove leavers and lapsed external access. Anyone who's left the business, and any subcontractor whose job finished, comes out of the folder memberships. Ten minutes per name, and it's a Cyber Essentials expectation anyway — so if you're certified, this is work you're supposed to be doing regardless.
  5. Pick a pilot group. Two or three people whose access you've just verified. The agent goes to them first, not the whole company. What they find in the first fortnight will tell you whether the clean-up worked.

If step one makes your heart sink because nobody in the business knows how to open the SharePoint admin centre, that's not a reason to abandon the idea — it's a sign the review is worth doing properly, with help. More on that at the end.

Your first agent: Researcher

Once the ground is prepared, you don't need to build anything. Microsoft ships ready-made agents with Copilot, and the one we'd point most firms at first is Researcher — built by Microsoft, included with a Microsoft 365 Copilot licence, and already pinned into Copilot chat for licensed users. There's no coding, no configuration project, nothing to maintain.

What makes Researcher a good first agent is that it does multi-step research work — pulling together information from the web and from your own files into a reasoned, structured answer — which maps neatly onto jobs that eat hours in an engineering business:

  • Before a sales meeting: "Give me a briefing on [prospective customer] — what they make, recent news, who their customers are, and anything in our files from previous contact with them." What used to be an hour of Googling and inbox archaeology becomes a ten-minute review of a drafted briefing.
  • Standards and compliance: ask it to summarise what a lengthy standard or a customer's compliance requirement actually asks of you, section by section, before the management review meeting. It won't replace your quality manager's judgement — but it gets them to the judgement part faster.
  • Tender context: market background, competitor context, and what your own past submissions said, gathered into one starting point instead of five open tabs and a folder crawl.

Notice that every one of those examples touches your own files — past correspondence, previous submissions, quality documents. That's why the pre-flight check comes first. The same capability that makes Researcher useful is the one that makes unreviewed permissions a liability.

How to switch it on

The mechanics are short, and there's no development work involved:

  1. Licensing. Copilot agents need a Microsoft 365 Copilot licence — the Business or Enterprise add-on that sits on top of an eligible Microsoft 365 subscription, currently around £22–£25 per user per month depending on the bundle. You only need it for the pilot group to start, not the whole company.
  2. Enable and assign in the Microsoft 365 admin centre. Under Agents, an admin can see the catalogue of ready-made agents from Microsoft and verified partners, review what data each one can touch, and choose exactly who gets it — just the pilot group, in this case. Researcher itself comes pre-pinned in Copilot chat for licensed users, so for your first agent there's genuinely little to do beyond deciding who's licensed.
  3. Users find agents in the Agent Store. For any further ready-made agents you enable later, staff install them from the Agent Store inside the tools they already use — Teams, Outlook, Word, Excel. No new app to learn.
  4. Run the pilot for a few weeks. Ask the pilot group two questions: what did it save you, and did it ever show you something you didn't expect to have access to? The second answer matters more than the first.

Why we're not suggesting you build your own agent yet

You'll see plenty of content about building custom agents in Copilot Studio — agents wired into your job costing system, your CRM, your production data. Some of that will genuinely be worth doing eventually. But it's a build-and-maintain commitment, it needs the paid Copilot licensing in place across everyone who'll use it, and it multiplies the governance questions before you've answered the basic ones. A ready-made agent gives you most of the early value with none of the build risk — and teaches you, cheaply, what your business would actually use an agent for before you spend money building one.

For what it's worth, Microsoft's answer to "what happens when a business is running lots of agents?" is a governance layer called Agent 365 — central visibility of every agent, what it can access and what it's doing. That's where this road leads as you grow, and it's reassuring that it exists. But for a first agent in a 20-person firm, the governance layer you need is the permissions review above, done honestly.

Frequently asked questions

Can a Copilot agent access files the user can't? No. Agents work within the user's existing Microsoft 365 permissions. The risk isn't the agent gaining access — it's the agent efficiently using access that was granted too broadly and then forgotten.

Is our data used to train the AI? No — under Microsoft's commercial terms, your prompts, files and Copilot's responses stay within your Microsoft 365 tenant boundary and aren't used to train the underlying models.

Do we need an extra licence for the Researcher agent? No. Researcher is built by Microsoft and included with the Microsoft 365 Copilot licence. Ready-made agents from the Agent Store generally don't need development work — an admin enables them, users install them.

We've never reviewed our SharePoint permissions. How bad is that? It's normal, and it's fixable. Most firms your size have never done it — the difference now is that Copilot makes the consequences of over-sharing visible. A structured review typically takes a day or less for a small business, and it improves your security whether or not you ever switch Copilot on.

Does any of this matter if we're not buying Copilot yet? Yes. Over-shared folders are a risk today — to leavers, to phished accounts, to plain human nosiness. Copilot just raises the stakes. The permissions work is worth doing on its own merits.

Before you switch anything on, know what it will see

If you're weighing up Copilot agents — whether you're a precision engineering firm in Four Ashes, a fabricator in Cannock, or anywhere across the West Midlands — the sensible first step is a Copilot readiness review: we go through your sharing settings, flag what's over-exposed, fix the defaults, and leave you with a tenant that's actually ready for an agent to be let loose on it. Book a free discovery call and we'll tell you honestly how much tidying stands between you and a safe first agent.

This article is general guidance based on Microsoft 365 Copilot capabilities and pricing as of mid-2026, and is not formal security advice. Licensing, features and agent availability change over time — check current details with us or with Microsoft before you budget.

Tagged

  • Microsoft Copilot agents
  • Copilot for Manufacturing
  • Copilot security
  • SharePoint Permissions
  • Microsoft 365 Copilot
  • West Midlands
  • South Staffordshire

Share this post

Ready to talk?

Let's see if we can help.

A short, no-pressure conversation about whatever IT problem is bugging you most.