Orchestry Debuts AI Governance Tool to Curb Unchecked Microsoft 365 Agents
Vancouver-based Orchestry has unveiled a new governance feature designed to map, score, and manage AI agents within Microsoft 365 environments. By integrating agent activity with Power Platform data, the tool aims to provide IT teams with the visibility needed to mitigate security risks posed by rapid, employee-led AI deployment.

The proliferation of AI agents has created a significant blind spot for enterprise IT departments. Employees can build functional agents in minutes, often drawing from vast pools of existing content without formal approval or oversight. In one enterprise instance involving 40,000 users, Orchestry identified over 3,000 links shared with 'anyone,' creating a massive vulnerability where any connected agent could potentially access sensitive data.
Michal Pisarek, CEO of Orchestry, argues that simply listing agents is insufficient. The true risk resides in the underlying content permissions and the specific environment where the agent operates. The new platform allows administrators to drill down from a tenant-wide view to a specific agent's risk score, environment policies, and connectors. Security teams can now manage these risks through scoped administrative roles, ensuring that agents can be audited or deleted without requiring excessive tenant-wide privileges.
Beyond individual agents, the software evaluates overall tenant readiness using 13 distinct governance signals, including data oversharing and safeguard efficacy. These metrics provide a dynamic score that shifts as IT teams remediate underlying permissions issues. The feature is currently rolling out to Orchestry Enterprise plan users, requiring standard Microsoft 365 E3 or E5 licensing to function.
Comments (0)
No comments yet. Be the first!