An agent is only as good as its context

the order to build the agentic enterprise on Microsoft

Most agent programmes I am asked to look at started at the top. Someone saw a copilot answer a question well, or an agent book a meeting, and the programme began there: with the agent. Six months later the agent is still a pilot. It gives confident answers that are slightly wrong, it cannot see half the data it needs, and nobody can say who approved what it did.

The agent is rarely the problem. An agent is only as good as the context it is given and the control it runs under, and both of those live in the layers underneath it. Microsoft’s own model of its AI and Agent Platform makes this visible: six layers, from the foundation platform at the bottom to the experience at the top, with a trust axis running through all of them.

Microsoft’s platform as three layers, with trust running through every one. Each control plane lights where it reaches.

So the question I start with is the order to build in. This is the order I would follow on Microsoft, and roughly how long each stage takes in the organisations I work with.


Stage 1: the foundation data estate (months 0 to 3)

Agents reason over data. If the ERP, the CRM, the service desk and the document stores each hold their own version of a customer, a supplier or an asset, the agent will meet all of those versions and choose one.

The first stage brings those sources into one governed estate. On Microsoft that means Microsoft Fabric, with OneLake as the single store, so data is landed, classified and governed once, and every later project uses it. It also means the Azure landing zone underneath: identity, networking and policy set up before any AI workload arrives, so the controls are in place on the first day.

This is the least visible stage and the one most often skipped. It is also the one that decides whether everything above it can be trusted.

Stage 2: semantic intelligence (months 3 to 6)

Clean data is still not understanding. A table called ORD_HDR does not tell an agent what an order is, which orders matter, or that “dispatched” in one system means “shipped” in another.

The second stage gives agents a shared understanding of the business. Microsoft calls this foundation Microsoft IQ:

  • Work IQ: how work happens, from calendars, files, meetings and the way work moves between teams across Microsoft 365.
  • Fabric IQ: how the business operates: its semantic models, metrics and ontologies, built on Power BI semantic models.
  • Foundry IQ: the managed knowledge layer that brings these sources together, so agents can find and reuse knowledge through one governed retrieval endpoint.
  • Web IQ: current context from the web, where an agent needs it.

Defining the semantic layer is business work as much as technical work. The people who own the processes have to agree what the terms mean, once, so every agent uses the same definitions.

Stage 3: platform and reasoning (months 6 to 12)

Only now does the model layer matter. Microsoft Foundry is where models are chosen, grounded on your own data through Azure AI Search, and evaluated before anything relies on them: for accuracy, for groundedness, and for content safety.

The decision that matters most at this stage is the one between no-code, low-code and pro-code. Copilot Studio is the right place for a great many agents. Some need the control of a pro-code build on Foundry. Choosing per use case, against the architecture, avoids two expensive mistakes: forcing everything through one tool, or building custom code where configuration would do.

Stage 4: agentic build and actions (months 12 to 18)

This is where most programmes want to start, and where they can now succeed. Agents move from answering to acting: raising the purchase order, updating the supplier record, reassigning the work order, through actions written back to your systems of record.

Microsoft is moving the same way inside Microsoft 365. Copilot Cowork, now in Microsoft’s Frontier programme, lets people hand Copilot a piece of work to carry out across Outlook, Teams, Word and Excel, drawing its context from Work IQ. It shows where the platform is heading, and why the stages underneath matter: delegated work is only as good as the context behind it.

Acting changes the risk. An agent that writes needs a defined list of actions, thresholds set by the business, a named person who approves above them, and a record of everything it did. Sibylle set out those controls in her article, Before an agent writes to your systems, and they belong in the design of this stage from the start.

Governance, at every stage

Trust is the one part of the platform that runs the full height of the stack, and it is the part that cannot be added at the end.

  • Identity: every agent is an identity of its own through Entra Agent ID, with the same conditional access and least privilege as any user. Agents built in Foundry receive one automatically.
  • Data protection: Purview classifies data and enforces the boundaries agents work within.
  • Threat protection: Defender watches agent workloads like any other.
  • Agent governance: Microsoft runs two control planes for agents. Agent 365, generally available since May 2026, gives IT and security one registry and one set of policies for every agent in the tenant; the Foundry Control Plane gives developers observability, evaluation and runtime controls from build to production.

Microsoft now sells much of this together: Microsoft 365 E7, which it calls the Frontier Suite, bundles Microsoft 365 E5, Microsoft 365 Copilot, the Entra Suite and Agent 365 in one licence.

It also helps to know which parts of the platform are network-isolated and which rely on tenant isolation. Of the eight control planes in Microsoft’s platform, three give genuine network-level isolation; the other five rely on tenant isolation, regional residency, customer-managed keys and least-privilege access. That is Microsoft’s design, and for regulated and sovereign work it should be decided before the build, plane by plane.

Stage 5: the autonomous enterprise (ongoing)

Once the layers below hold, autonomy grows in steps. Agents take on more actions as their records show they can be trusted with them, thresholds rise after a quarter of clean decisions, and new agents reuse the semantic layer, the grounding and the controls that the first ones paid for.

That reuse is the real return on building in order. The first agent carries the cost of the foundation. Every agent after it is cheaper, faster and safer to build.


Questions to ask before you start at the top

  1. Which sources will the agent need, and are they in one governed estate today?
  2. Who has agreed what the business terms mean, and where is that definition kept?
  3. How will the agent’s answers be evaluated before anyone relies on them?
  4. Is each use case a Copilot Studio agent or a pro-code build, and who decided?
  5. What exact actions will the agent take, and who approves above the thresholds?
  6. Which parts of the platform it uses are network-isolated, and which rely on tenant isolation?
  7. Which identity does the agent run as, and what can that identity reach?

If the first three have no answer yet, the agent is early. Start one stage lower.


Talastron designs, builds and runs governed agentic AI in your own Microsoft Azure tenant. The full six-layer architecture is at talastron.com/platform/architecture. If you would like to know which stage your own estate is at, we would be glad to talk it through: talastron.com/contact.

Sources

  1. Microsoft Tech Community. “The Microsoft AI and Agent Platform.” July 2026.
  2. Microsoft Azure Blog. “Microsoft Build 2026: Building agentic apps with Microsoft Fabric and Microsoft Databases.” 2026. azure.microsoft.com
  3. Microsoft Tech Community. “Foundry Control Plane and Agent 365: two control planes walk into an enterprise.” 2026. techcommunity.microsoft.com
  4. Microsoft Learn. “Microsoft Agent 365 integration with Foundry.” learn.microsoft.com
  5. Microsoft. “Powering Frontier Transformation with Copilot and agents.” March 2026. microsoft.com

Not sure whereto start?

Tell us where you are today, and we’ll recommend the right starting point.