Aug. 8, 2026

The Architecture of Intelligence- Why the Chatbox is the Wrong Model for Enterprise AI

The Architecture of Intelligence- Why the Chatbox is the Wrong Model for Enterprise AI
The Architecture of Intelligence- Why the Chatbox is the Wrong Model for Enterprise AI
M365 FM Podcast
The Architecture of Intelligence- Why the Chatbox is the Wrong Model for Enterprise AI

Artificial intelligence was supposed to transform how organizations access information, make decisions, and execute work. Microsoft Copilot, enterprise AI agents, and generative AI promised to remove the barriers between employees and organizational knowledge. But many companies are discovering a fundamental problem: employees can ask AI better questions and receive better answers, yet they still have to navigate SharePoint, Excel, business applications, approval systems, and other tools to actually complete the work. The intelligence improved, but the workflow often did not. This episode explores a much larger architectural shift happening across Microsoft 365, SharePoint, Copilot, SPFx, MCP, governance, security, and enterprise AI. The argument is simple: the chatbox may be the wrong primary interface for enterprise intelligence. The future is not simply better prompts or better conversational AI. It is an environment where AI becomes an orchestration layer capable of presenting the exact interface, data, action, or workflow a user needs at the moment they need it.

THE CHATBOX BOTTLENECK
Chat interfaces are extremely effective for asking questions, summarizing information, brainstorming, and discovering knowledge. But enterprise work rarely ends with an answer. Employees need to approve requests, update records, modify documents, change statuses, trigger workflows, review dashboards, and make auditable decisions. That creates the chatbox bottleneck. A user asks Copilot about a purchase order and receives an excellent summary, but then still needs to locate the procurement system, find the corresponding record, and execute the approval. AI accelerated information retrieval without necessarily accelerating task completion. Every additional application switch introduces navigation time, cognitive load, and another potential break in the audit trail. The more important enterprise AI metric therefore isn't simply how quickly an AI produces an answer. It is the distance between “I need something done” and “the task is complete.”

COPILOT DOESN'T CREATE BAD PERMISSIONS — IT EXPOSES THEM
One of the biggest enterprise concerns around Microsoft Copilot is security. But the episode challenges the assumption that Copilot itself creates an entirely new permission problem. Instead, AI dramatically increases the discoverability of information users could already access. A poorly governed SharePoint environment may contain years of permission drift, broadly shared sites, inherited permissions, old sharing links, and sensitive information that is technically accessible but historically difficult to discover. Natural-language AI removes much of that discovery friction. Information that once required knowing the correct SharePoint site, library, folder, filename, or search terminology can potentially become much easier to find. That means Copilot can function as a permission magnifier. The underlying governance weakness may already exist; AI simply makes the consequences visible much faster.

FROM CHAT TO ACTION
The alternative to the chat-first model isn't necessarily abandoning conversational AI. It is changing what happens after the conversation begins. Instead of asking Copilot a question, receiving text, and navigating elsewhere, imagine Copilot presenting an interactive form, approval interface, dashboard, list, or action directly inside the experience. The user receives both the intelligence required to make a decision and the interface required to execute it. This represents a shift from text as the interface toward actions as the interface. Interactive components can dramatically reduce the distance between decision and execution.

SHAREPOINT, SPFX AND THE NEW INTERACTION MODEL
This shift gives SharePoint Framework a potentially much larger role in enterprise AI architecture. SPFx has traditionally been associated with SharePoint customization: web parts, dashboards, intranet experiences, list interfaces, and specialized business applications. In the architecture described in this episode, those skills become relevant to something broader: building interactive experiences that can participate in AI-driven workflows. Instead of thinking only about where a component appears on a SharePoint page, developers increasingly need to think about how that component becomes part of an orchestration flow. The user expresses intent, the AI identifies the appropriate capability, an interface is surfaced, the user takes an action, and the result feeds back into the process. The component stops being merely a destination. It becomes an actionable building block of enterprise intelligence.

THE OLD MODEL VS. THE NEW MODEL
Traditional enterprise information architecture assumes that humans are the navigation layer. Employees are expected to know where information resides, understand organizational structures, navigate applications, search folders, interpret documents, and then locate another interface to execute an action. The emerging model reverses that relationship. AI increasingly becomes the navigation and orchestration layer. Instead of teaching employees where every system lives, the organization exposes governed capabilities that AI can surface when appropriate. The human concentrates on the decision while the architecture handles discovery and execution. That is a much more significant transformation than adding a chatbot to an existing application.

MCP VS. SPFX: TWO DIFFERENT ARCHITECTURAL PATHS
The episode also examines two important approaches to building interactive enterprise AI experiences: Model Context Protocol (MCP) and SharePoint Framework-based experiences. MCP provides a more open integration model. It can expose tools and capabilities to AI systems and can be valuable when enterprise information is distributed across Microsoft platforms, custom applications, ERP environments, CRM systems, data platforms, and external services. That flexibility introduces additional architectural responsibility. Identity propagation, authentication, external infrastructure, security controls, logging, credential management, API governance, and cross-system auditing all become important considerations. SPFx represents a more Microsoft 365-centric path. Where SharePoint already acts as a major system of record or operational platform, organizations can potentially build on existing Microsoft 365 identity, permissions, governance, and development investments. The decision therefore isn't simply MCP versus SPFx. It is a governance and architecture decision based on where the organization's data lives, how portable integrations need to be, and what security boundaries the organization is capable of managing.

THE AGENT FABRIC
At the center of the discussion is the idea of an Agent Fabric: an enterprise environment in which AI doesn't simply answer questions but can select and invoke governed capabilities. The basic cycle becomes: Intent → Reasoning → Tool → Interactive Experience → Human Action → Result An agent can determine that a particular capability is needed, invoke it, surface the relevant information or interface, receive the user's action, and continue the workflow. This changes Copilot from primarily a conversational layer into an orchestration layer. But that architecture only works safely when identity, authorization, permissions, auditability, data protection, and human approval are designed into the foundation.

GOVERNANCE BEFORE AI ARCHITECTURE
This leads to one of the most important arguments of the episode: governance must precede architecture. Buying Copilot licenses first and fixing governance later reverses the correct sequence. Organizations need to understand who has access to information, where sensitive data resides, whether permissions reflect actual business requirements, how data is classified, and whether actions can be audited before AI dramatically increases the speed at which that information can be discovered and used. The recommended sequence is therefore: Governance → Architecture → Implementation → Measurement → Expansion Weak permissions do not disappear when AI arrives. They become easier to exploit accidentally. Poor classification doesn't become less important. It becomes more important. Missing auditability becomes increasingly dangerous as AI moves from generating answers toward executing actions.

SHAREPOINT PERMISSION AUDITS BECOME CRITICAL
Organizations preparing for enterprise AI should examine SharePoint permissions as an architectural foundation rather than routine administration. Broad organizational access, old sharing links, unnecessary external sharing, broken inheritance, overshared libraries, and sensitive documents stored inside broadly accessible collaboration spaces all deserve renewed attention. The objective isn't to restrict information unnecessarily. It is to ensure that the permission model accurately represents the organization's real business and compliance requirements before AI makes discovery dramatically easier. Sensitivity labels, DLP policies, appropriate access boundaries, audit capabilities, and systematic permission reviews therefore become part of the AI architecture itself.

Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.

🚀 Want to be part of m365.fm?

Then stop just listening… and start showing up.

👉 Connect with me on LinkedIn and let’s make something happen:

  • 🎙️ Be a podcast guest and share your story
  • 🎧 Host your own episode (yes, seriously)
  • 💡 Pitch topics the community actually wants to hear
  • 🌍 Build your personal brand in the Microsoft 365 space

This isn’t just a podcast — it’s a platform for people who take action.

🔥 Most people wait. The best ones don’t.

👉 Connect with me on LinkedIn and send me a message:
"I want in"

Let’s build something awesome 👊

1
00:00:00,000 --> 00:00:06,320
Here is the promise we were all given. Artificial intelligence was going to democratize every piece of information in your company.

2
00:00:06,320 --> 00:00:12,560
It would close the gap between having data and making a decision. Teams would move faster. Compliance would be a breeze.

3
00:00:12,560 --> 00:00:18,320
Your organization would finally turn years of hidden knowledge into a massive competitive advantage.

4
00:00:18,320 --> 00:00:21,280
That was the pitch, and that is why you signed the checks for the licenses.

5
00:00:21,280 --> 00:00:26,640
But here is what is actually happening. Your teams are spending more time engineering prompts than actually doing their jobs.

6
00:00:26,640 --> 00:00:33,280
They ask co-pilot a question, they get back a massive wall of text, then they have to navigate back to SharePoint to find the source document.

7
00:00:33,280 --> 00:00:38,960
They jump over to Excel to pull the numbers, they switch to Outlook to send the final approval, somewhere in all that switching.

8
00:00:38,960 --> 00:00:43,280
The efficiency just evaporates, the problem isn't the AI itself, the problem is the interface.

9
00:00:43,280 --> 00:00:46,880
We have built the wrong model for how intelligence should work inside a business.

10
00:00:46,880 --> 00:00:52,560
We took the chatbot idea from consumer apps, text in, text out, and we dropped it into complex business processes.

11
00:00:52,560 --> 00:00:56,240
We never stopped to ask if a text box is the right way to get work done.

12
00:00:56,240 --> 00:00:59,760
It isn't, and the structural cost of that mistake is forcing a change.

13
00:00:59,760 --> 00:01:01,760
On July 1st, the math changes for everyone.

14
00:01:01,760 --> 00:01:04,720
Microsoft 365 base prices are going up.

15
00:01:04,720 --> 00:01:10,400
Even more importantly, the co-pilot features currently sitting inside your apps are moving behind a license gate.

16
00:01:10,400 --> 00:01:17,120
SPFX version 1.24 hits preview in a few weeks, bringing the first real alternative to this chat first world.

17
00:01:17,120 --> 00:01:22,640
By the end of 2026, the shift from chat as an interface to actions as an interface will be the only way forward.

18
00:01:22,640 --> 00:01:28,160
By the end of this video, you will see why the shift is a structural necessity rather than just another feature update.

19
00:01:28,160 --> 00:01:32,800
You will see how the company's preparing right now will be operating 18 months ahead of everyone else.

20
00:01:32,800 --> 00:01:37,040
And you will understand exactly what has to change in your governance model to make it work.

21
00:01:37,040 --> 00:01:39,360
The chatbox bottleneck.

22
00:01:39,360 --> 00:01:41,520
We have to start with a fundamental misdiagnosis.

23
00:01:41,520 --> 00:01:45,840
The story we're told about co-pilot is that text is efficient, we're told it's high density.

24
00:01:45,840 --> 00:01:49,680
You can ask a question in 20 words and get back 200 words of perfect context.

25
00:01:49,680 --> 00:01:52,400
That feels like speed, but in reality, it's the opposite.

26
00:01:52,400 --> 00:01:57,280
That efficiency is great for the machine, but it's a disaster for the human trying to finish a task.

27
00:01:57,280 --> 00:01:59,360
Think about the actual pattern in your office.

28
00:01:59,360 --> 00:02:02,640
A user in your operations team needs to approve a purchase order.

29
00:02:02,640 --> 00:02:03,840
They open co-pilot.

30
00:02:03,840 --> 00:02:07,040
They ask for the status of requisition 47382.

31
00:02:07,040 --> 00:02:11,120
Co-pilot gives them a clean paragraph with the order details, the approval chain and the timeline.

32
00:02:11,120 --> 00:02:14,160
The user reads it, they understand it, but then what?

33
00:02:14,160 --> 00:02:17,840
They still have to navigate back to the procurement system to click the approve button.

34
00:02:17,840 --> 00:02:22,000
If that requisition lives in a SharePoint list, they have to go search for it all over again.

35
00:02:22,000 --> 00:02:23,280
The text didn't finish the job.

36
00:02:23,280 --> 00:02:26,880
It just created a parallel track that the human now has to manually fix.

37
00:02:26,880 --> 00:02:31,040
When you multiply that by every user and every task, you see the real cost.

38
00:02:31,040 --> 00:02:32,640
This is the friction we aren't measuring.

39
00:02:32,640 --> 00:02:37,200
Every time someone jumps from a chat window to an action, they are burning mental energy.

40
00:02:37,200 --> 00:02:38,720
They are leaving the flow of their work.

41
00:02:38,720 --> 00:02:42,960
If you actually track the time from, "I need to do this too," this is finished.

42
00:02:42,960 --> 00:02:44,240
The bottleneck isn't the question.

43
00:02:44,240 --> 00:02:45,680
It's the jumping between systems.

44
00:02:45,680 --> 00:02:47,440
The chat was supposed to stop the searching.

45
00:02:47,440 --> 00:02:48,720
Instead, it just moved it.

46
00:02:48,720 --> 00:02:52,320
In regulated industries, this turns into a compliance nightmare.

47
00:02:52,320 --> 00:02:55,520
Every prompt is a new record to track every time a user switches context,

48
00:02:55,520 --> 00:02:57,360
you create a gap in the audit trail.

49
00:02:57,360 --> 00:03:00,880
When an employee manually matches what Copilot said with what the system shows,

50
00:03:00,880 --> 00:03:02,560
you've hit a control failure.

51
00:03:02,560 --> 00:03:04,240
You are paying for high-level intelligence,

52
00:03:04,240 --> 00:03:06,240
but running it through a broken structure.

53
00:03:06,240 --> 00:03:09,040
In operations, every small delay starts to add up.

54
00:03:09,040 --> 00:03:12,640
A decision that takes 10 minutes to reach should only take 3 minutes to finish.

55
00:03:12,640 --> 00:03:16,000
If it takes 10 minutes just to navigate to the right screen and execute,

56
00:03:16,000 --> 00:03:17,600
you've killed the value of the AI.

57
00:03:17,600 --> 00:03:18,960
You haven't solved the bottleneck.

58
00:03:18,960 --> 00:03:20,320
You've just built a new one.

59
00:03:20,320 --> 00:03:23,760
The core issue is that we've borrowed the model from chat GPT and Gemini.

60
00:03:23,760 --> 00:03:27,120
Those systems were built for individuals asking questions for personal use.

61
00:03:27,120 --> 00:03:30,000
When we dropped that model into the enterprise without asking if it fit,

62
00:03:30,000 --> 00:03:30,640
it doesn't.

63
00:03:30,640 --> 00:03:34,400
And that realization is what should be changing your entire architecture right now.

64
00:03:34,400 --> 00:03:36,640
Permission magnification, not a new risk.

65
00:03:36,640 --> 00:03:38,560
The security conversation needs a reframe.

66
00:03:38,560 --> 00:03:40,720
Most people think Copilot creates new risks.

67
00:03:40,720 --> 00:03:42,320
They think it's a data leakage vector.

68
00:03:42,320 --> 00:03:44,400
They think you have to shut it down or restrict it,

69
00:03:44,400 --> 00:03:46,960
because it might expose things you never intended to share.

70
00:03:46,960 --> 00:03:48,240
That narrative is wrong.

71
00:03:48,240 --> 00:03:50,080
It's a symptom of a deeper misunderstanding.

72
00:03:50,080 --> 00:03:52,000
Copilot doesn't create security risks.

73
00:03:52,000 --> 00:03:54,560
It exposes permission problems that already existed.

74
00:03:54,560 --> 00:03:58,000
And that distinction changes everything about how you approach this.

75
00:03:58,000 --> 00:03:59,520
Here is how it actually works.

76
00:03:59,520 --> 00:04:02,720
Copilot uses the same security trimming as SharePoint Search,

77
00:04:02,720 --> 00:04:05,520
the same filtering logic, the same access control model.

78
00:04:05,520 --> 00:04:07,120
When you ask Copilot a question,

79
00:04:07,120 --> 00:04:09,600
it isn't pulling data from outside your tenant boundary.

80
00:04:09,600 --> 00:04:11,600
It queries the same index that Search uses

81
00:04:11,600 --> 00:04:13,840
and that index respects your existing permissions.

82
00:04:13,840 --> 00:04:14,640
Full stop.

83
00:04:14,640 --> 00:04:18,080
A user cannot see content in Copilot that they couldn't see in Search.

84
00:04:18,080 --> 00:04:20,720
They cannot access a document through the AI

85
00:04:20,720 --> 00:04:22,880
that they wouldn't be able to open manually.

86
00:04:22,880 --> 00:04:25,440
Technically, Copilot isn't a new access vector.

87
00:04:25,440 --> 00:04:27,040
It's using the one you already have.

88
00:04:27,040 --> 00:04:28,880
But here is the amplification effect.

89
00:04:28,880 --> 00:04:30,880
And this is where the real conversation starts.

90
00:04:30,880 --> 00:04:34,720
If your SharePoint has anyone with the link shares on sensitive files,

91
00:04:34,720 --> 00:04:36,480
Copilot doesn't change that.

92
00:04:36,480 --> 00:04:37,920
That problem was already there,

93
00:04:37,920 --> 00:04:39,360
but the discovery time changes.

94
00:04:39,360 --> 00:04:42,400
Copilot makes that data discoverable in seconds instead of hours.

95
00:04:42,400 --> 00:04:45,040
Someone asks a natural language question.

96
00:04:45,040 --> 00:04:46,960
What are our contract terms with Acme?

97
00:04:46,960 --> 00:04:49,440
Find me the competitor analysis from Q3.

98
00:04:49,440 --> 00:04:50,880
They don't need to know the site name.

99
00:04:50,880 --> 00:04:52,640
They don't need the library path.

100
00:04:52,640 --> 00:04:54,480
They don't need to understand the document structure.

101
00:04:54,480 --> 00:04:55,760
They just get an answer instantly.

102
00:04:55,760 --> 00:04:57,120
Is Copilot the problem?

103
00:04:57,120 --> 00:04:57,840
No.

104
00:04:57,840 --> 00:04:59,600
The problem is that someone could share a document

105
00:04:59,600 --> 00:05:01,200
with anyone in the first place.

106
00:05:01,200 --> 00:05:02,800
Copilot didn't create that risk.

107
00:05:02,800 --> 00:05:04,240
It just made it visible.

108
00:05:04,240 --> 00:05:05,680
Architects usually miss this.

109
00:05:05,680 --> 00:05:07,680
They see Copilot surfacing sensitive data

110
00:05:07,680 --> 00:05:08,480
and they blame the tool.

111
00:05:08,480 --> 00:05:09,840
So they restrict access.

112
00:05:09,840 --> 00:05:12,000
They block sites from being indexed.

113
00:05:12,000 --> 00:05:14,400
They treat the symptom, but they don't fix the disease.

114
00:05:14,400 --> 00:05:17,840
The structural flaw is that most organizations have flat permissions.

115
00:05:17,840 --> 00:05:19,840
But hierarchical compliance requirements.

116
00:05:19,840 --> 00:05:21,440
Flat permissions look like this.

117
00:05:21,440 --> 00:05:23,760
You have a site called shared resources.

118
00:05:23,760 --> 00:05:25,600
Everyone in the department can access it.

119
00:05:25,600 --> 00:05:27,200
Everyone can see every folder.

120
00:05:27,200 --> 00:05:28,560
Everyone can edit documents.

121
00:05:28,560 --> 00:05:29,280
It's open.

122
00:05:29,280 --> 00:05:30,400
It's collaborative.

123
00:05:30,400 --> 00:05:32,080
And in a certain context, it makes sense.

124
00:05:32,080 --> 00:05:34,000
hierarchical compliance looks different.

125
00:05:34,000 --> 00:05:36,240
Some documents in that site are contract terms.

126
00:05:36,240 --> 00:05:37,760
Only legal should see those.

127
00:05:37,760 --> 00:05:39,760
Some are budget-focused for finance.

128
00:05:39,760 --> 00:05:41,520
Some are employee records for HR.

129
00:05:41,520 --> 00:05:44,560
But they all live in the same site with the same flat permission model.

130
00:05:44,560 --> 00:05:46,720
This gap is what Copilot makes visible.

131
00:05:46,720 --> 00:05:49,040
It's the distance between how you structured permissions

132
00:05:49,040 --> 00:05:51,360
and what your governance actually requires.

133
00:05:51,360 --> 00:05:54,160
When Copilot surfaces budget data to an individual contributor,

134
00:05:54,160 --> 00:05:55,760
the reflex is to blame the AI.

135
00:05:55,760 --> 00:05:58,400
The actual fix is to go back and restructure your permissions.

136
00:05:58,400 --> 00:06:01,520
You have to enforce compliance at the site and library level.

137
00:06:01,520 --> 00:06:03,280
Not assume it at the behavioral level.

138
00:06:03,280 --> 00:06:05,520
This is why the licensing change matters so much.

139
00:06:05,520 --> 00:06:07,920
Organizations with messy permissions will see Copilot

140
00:06:07,920 --> 00:06:09,120
and think it's too risky.

141
00:06:09,120 --> 00:06:10,640
Organizations with clean permissions

142
00:06:10,640 --> 00:06:13,680
will see Copilot and think it's their primary interface for work.

143
00:06:13,680 --> 00:06:14,720
One group blocks it.

144
00:06:14,720 --> 00:06:15,920
One group accelerates it.

145
00:06:15,920 --> 00:06:19,760
And that decision determines which group you're in by 2027.

146
00:06:19,760 --> 00:06:22,320
The July 1st cliff, licensing is architecture.

147
00:06:22,320 --> 00:06:24,880
What's happening on July 1st isn't just a price adjustment.

148
00:06:24,880 --> 00:06:27,520
It's the moment when licensing becomes a statement

149
00:06:27,520 --> 00:06:29,680
about how you architect AI into your business.

150
00:06:29,680 --> 00:06:30,640
Two things happen at once.

151
00:06:30,640 --> 00:06:33,120
Microsoft 365 base plan prices increase.

152
00:06:33,120 --> 00:06:35,760
E3 goes from $36 to $39.

153
00:06:35,760 --> 00:06:39,600
Business standard goes from $12.50 to $14.

154
00:06:39,600 --> 00:06:41,280
At scale, those numbers add up.

155
00:06:41,280 --> 00:06:44,160
But the pricing changes secondary to what happens to the features.

156
00:06:44,160 --> 00:06:45,920
Right now, if you have a Microsoft license,

157
00:06:45,920 --> 00:06:47,520
you get some AI assistance.

158
00:06:47,520 --> 00:06:48,320
It's limited.

159
00:06:48,320 --> 00:06:50,000
It's often in preview, but it's there.

160
00:06:50,000 --> 00:06:51,600
Starting July 1st, that changes.

161
00:06:51,600 --> 00:06:54,880
Users without an explicit $30 per month Copilot license

162
00:06:54,880 --> 00:06:56,160
lose the embedded AI.

163
00:06:56,160 --> 00:06:57,440
It disappears from Word.

164
00:06:57,440 --> 00:06:59,920
It disappears from Excel, PowerPoint, and OneNote.

165
00:06:59,920 --> 00:07:01,360
And it extends to SharePoint.

166
00:07:01,360 --> 00:07:03,360
If you rely on Copilot for list management

167
00:07:03,360 --> 00:07:04,800
or document workflows,

168
00:07:04,800 --> 00:07:07,440
that feature vanishes for anyone without the paid seat.

169
00:07:07,440 --> 00:07:09,520
Microsoft calls these premium features

170
00:07:09,520 --> 00:07:10,800
that's the marketing.

171
00:07:10,800 --> 00:07:11,520
Pay more.

172
00:07:11,520 --> 00:07:12,560
Get the better version.

173
00:07:12,560 --> 00:07:14,080
But the structural reality is different.

174
00:07:14,080 --> 00:07:15,360
This isn't about feature tiers.

175
00:07:15,360 --> 00:07:18,400
This is about declaring who operates inside the agent fabric.

176
00:07:18,400 --> 00:07:19,600
And who operates outside it?

177
00:07:19,600 --> 00:07:21,360
Think about what that means for your operations.

178
00:07:21,360 --> 00:07:22,880
You have a thousand person organization.

179
00:07:22,880 --> 00:07:26,640
Maybe 30% of those people do work that actually benefits from AI.

180
00:07:26,640 --> 00:07:28,320
The decision makers, the operators,

181
00:07:28,320 --> 00:07:29,920
the people managing workflows.

182
00:07:29,920 --> 00:07:32,400
For a thousand person org, that's 300 people.

183
00:07:32,400 --> 00:07:36,960
Licensing 30% of your staff at $30 a month is $108,000 a year.

184
00:07:36,960 --> 00:07:38,400
That's a budget conversation.

185
00:07:38,400 --> 00:07:39,840
But you aren't just buying a feature.

186
00:07:39,840 --> 00:07:41,920
You aren't even buying access to Copilot.

187
00:07:41,920 --> 00:07:43,920
You are declaring an architectural boundary.

188
00:07:43,920 --> 00:07:45,760
You're saying these 300 people work in a world

189
00:07:45,760 --> 00:07:48,000
where AI is integrated into their tools.

190
00:07:48,000 --> 00:07:51,600
The other 700 work in a world where AI is optional.

191
00:07:51,600 --> 00:07:52,560
Or peripheral.

192
00:07:52,560 --> 00:07:53,200
Or off limits.

193
00:07:53,200 --> 00:07:54,640
That's a governance decision.

194
00:07:54,640 --> 00:07:56,320
And it shapes everything downstream.

195
00:07:56,320 --> 00:07:58,000
Once you decide who gets the license,

196
00:07:58,000 --> 00:07:59,200
everything else follows.

197
00:07:59,200 --> 00:08:00,880
If operation staff have Copilot,

198
00:08:00,880 --> 00:08:02,320
but customer service doesn't,

199
00:08:02,320 --> 00:08:03,840
they are using different tooling.

200
00:08:03,840 --> 00:08:05,760
If project managers have AI in Excel,

201
00:08:05,760 --> 00:08:08,240
but their teams don't, you've created asymmetry.

202
00:08:08,240 --> 00:08:10,960
That asymmetry either becomes a competitive advantage

203
00:08:10,960 --> 00:08:12,480
or it fragments into friction.

204
00:08:12,480 --> 00:08:15,040
It all depends on how you architect the handoff points.

205
00:08:15,040 --> 00:08:16,880
Organizations that haven't thought about this

206
00:08:16,880 --> 00:08:18,560
will hit July 1st and react.

207
00:08:18,560 --> 00:08:20,400
They will either buy too many licenses

208
00:08:20,400 --> 00:08:22,320
or they will restrict it more than they should.

209
00:08:22,320 --> 00:08:23,760
Then they'll live with those consequences

210
00:08:23,760 --> 00:08:26,240
for 18 months while they try to find the right model.

211
00:08:26,240 --> 00:08:28,400
The organization is thinking about this now.

212
00:08:28,400 --> 00:08:29,440
Move differently.

213
00:08:29,440 --> 00:08:31,760
They see licensing as an architecture decision.

214
00:08:31,760 --> 00:08:32,560
Not a cost decision.

215
00:08:32,560 --> 00:08:34,880
They've mapped which workflows need embedded AI.

216
00:08:34,880 --> 00:08:36,880
They have clarity on their governance boundaries.

217
00:08:36,880 --> 00:08:38,560
They understand that the licensing choices

218
00:08:38,560 --> 00:08:40,720
the constraint that forces discipline.

219
00:08:40,720 --> 00:08:42,640
This moment matters because it reveals the shift

220
00:08:42,640 --> 00:08:44,000
in how enterprises operate.

221
00:08:44,000 --> 00:08:45,520
The change isn't arbitrary.

222
00:08:45,520 --> 00:08:48,400
It's the inflection point where chat stops being an option

223
00:08:48,400 --> 00:08:50,320
and becomes a declared operational boundary.

224
00:08:50,320 --> 00:08:53,520
Beyond text, the headless UI model.

225
00:08:53,520 --> 00:08:55,520
If the diagnosis is that chat is a bottleneck,

226
00:08:55,520 --> 00:08:57,920
the question becomes, what is the alternative?

227
00:08:57,920 --> 00:08:59,520
The answer isn't better chat.

228
00:08:59,520 --> 00:09:01,200
It is not about optimizing prompts

229
00:09:01,200 --> 00:09:03,040
or training people to ask smarter questions

230
00:09:03,040 --> 00:09:04,560
or getting faster response times.

231
00:09:04,560 --> 00:09:06,320
The answer is to stop relying on text

232
00:09:06,320 --> 00:09:08,080
to be the interface for action.

233
00:09:08,080 --> 00:09:09,520
Let me reframe what is actually happening

234
00:09:09,520 --> 00:09:11,040
with SharePoint co-pilot apps.

235
00:09:11,040 --> 00:09:12,960
This isn't about adding a feature to co-pilot.

236
00:09:12,960 --> 00:09:15,680
This is about fundamentally changing the interaction model.

237
00:09:15,680 --> 00:09:17,600
In the old way, a user asks a question,

238
00:09:17,600 --> 00:09:18,720
co-pilot returns text,

239
00:09:18,720 --> 00:09:20,800
and the user then has to navigate to a system

240
00:09:20,800 --> 00:09:22,960
to manually act on that text.

241
00:09:22,960 --> 00:09:24,160
The new model looks like this.

242
00:09:24,160 --> 00:09:25,680
A user asks a question,

243
00:09:25,680 --> 00:09:28,080
co-pilot surfaces an interactive component,

244
00:09:28,080 --> 00:09:30,400
a form, a button, or a dashboard,

245
00:09:30,400 --> 00:09:32,160
directly in the chat canvas,

246
00:09:32,160 --> 00:09:34,160
and the user interacts with that component

247
00:09:34,160 --> 00:09:35,760
so the action happens in context.

248
00:09:36,240 --> 00:09:37,360
That is the shift.

249
00:09:37,360 --> 00:09:39,440
That is what beyond text actually means.

250
00:09:39,440 --> 00:09:42,560
The technology enabling this is SharePoint co-pilot apps

251
00:09:42,560 --> 00:09:45,040
which enters preview in July of 2026.

252
00:09:45,040 --> 00:09:47,760
What it does is let SharePoint framework components,

253
00:09:47,760 --> 00:09:49,920
web parts you have already built for your internet,

254
00:09:49,920 --> 00:09:50,880
your dashboards,

255
00:09:50,880 --> 00:09:52,720
and your list management interfaces

256
00:09:52,720 --> 00:09:55,440
render directly inside the co-pilot canvas.

257
00:09:55,440 --> 00:09:58,160
These are not static images or pre-formatted responses.

258
00:09:58,160 --> 00:09:59,520
These are interactive components

259
00:09:59,520 --> 00:10:01,680
where you can click a button, fill out a form,

260
00:10:01,680 --> 00:10:03,840
approve something, or update a status,

261
00:10:03,840 --> 00:10:05,440
and all of that happens in line

262
00:10:05,440 --> 00:10:07,120
without leaving the conversation.

263
00:10:07,120 --> 00:10:08,160
Why does this matter?

264
00:10:08,160 --> 00:10:11,280
Because it collapses the distance between decision and action.

265
00:10:11,280 --> 00:10:13,440
Right now, if someone asks co-pilot,

266
00:10:13,440 --> 00:10:15,280
what is the status of this project?

267
00:10:15,280 --> 00:10:17,920
And co-pilot returns a paragraph describing the status.

268
00:10:17,920 --> 00:10:19,360
The user still needs to navigate

269
00:10:19,360 --> 00:10:20,880
to the project management system

270
00:10:20,880 --> 00:10:22,640
to actually update something.

271
00:10:22,640 --> 00:10:24,480
With the interactive component model,

272
00:10:24,480 --> 00:10:27,120
co-pilot surfaces a status dashboard in line,

273
00:10:27,120 --> 00:10:29,600
which means the user can see the data in context

274
00:10:29,600 --> 00:10:32,320
and hit a button right there to update it immediately.

275
00:10:32,320 --> 00:10:33,600
That is not just faster,

276
00:10:33,600 --> 00:10:35,280
that is a different operational reality.

277
00:10:35,280 --> 00:10:38,080
From a governance perspective, this changes everything.

278
00:10:38,080 --> 00:10:39,920
Every interaction stays inside your tenant.

279
00:10:39,920 --> 00:10:41,600
Every action is logged automatically

280
00:10:41,600 --> 00:10:44,400
because it is happening through your own sharepoint infrastructure

281
00:10:44,400 --> 00:10:47,280
and every component respects the same permission model

282
00:10:47,280 --> 00:10:49,440
that governs your regular sharepoint access.

283
00:10:49,440 --> 00:10:51,120
If you do not have permission to see a list,

284
00:10:51,120 --> 00:10:53,360
the component will not show your data from that list

285
00:10:53,360 --> 00:10:55,600
and if you do not have permission to modify something,

286
00:10:55,600 --> 00:10:57,600
the update button will not even be active.

287
00:10:57,600 --> 00:10:59,360
Nothing happens outside your audit trail.

288
00:10:59,360 --> 00:11:00,800
Nothing escapes your security boundary.

289
00:11:00,800 --> 00:11:03,040
This is critical because it means the agent fabric

290
00:11:03,040 --> 00:11:04,640
isn't some external AI system

291
00:11:04,640 --> 00:11:07,440
that you are integrating with and managing separately.

292
00:11:07,440 --> 00:11:10,160
It is an evolution of the infrastructure you already have.

293
00:11:10,160 --> 00:11:12,160
You are not layering a new security model on top.

294
00:11:12,160 --> 00:11:14,560
You are extending the one that exists for developers.

295
00:11:14,560 --> 00:11:16,000
This is the inflection point.

296
00:11:16,000 --> 00:11:18,560
You have probably spent years building SPFX webpots

297
00:11:18,560 --> 00:11:20,000
for sharepoint pages,

298
00:11:20,000 --> 00:11:21,120
so you know how to build them,

299
00:11:21,120 --> 00:11:23,200
how to structure data and how to call APIs.

300
00:11:23,200 --> 00:11:25,760
That expertise, which was valuable for Internet work,

301
00:11:25,760 --> 00:11:29,200
is now your primary asset for operationalizing enterprise AI.

302
00:11:29,200 --> 00:11:30,960
This isn't about learning a new framework.

303
00:11:30,960 --> 00:11:32,240
It is not about retraining.

304
00:11:32,240 --> 00:11:35,200
It is about understanding that the skills you have already built

305
00:11:35,200 --> 00:11:36,800
are now the primary mechanism

306
00:11:36,800 --> 00:11:38,960
for moving intelligence into the hands of people

307
00:11:38,960 --> 00:11:40,160
who need to act on it.

308
00:11:40,160 --> 00:11:41,920
The component appears in co-pilot.

309
00:11:41,920 --> 00:11:43,440
The user interacts with it.

310
00:11:43,440 --> 00:11:44,560
The action is logged.

311
00:11:44,560 --> 00:11:46,000
The permission is enforced.

312
00:11:46,000 --> 00:11:47,440
The result is immediate.

313
00:11:47,440 --> 00:11:49,280
That is the operational model shift.

314
00:11:49,280 --> 00:11:51,200
That is what changes everything downstream.

315
00:11:51,200 --> 00:11:53,520
And it only works if you understand what comes next.

316
00:11:53,520 --> 00:11:56,000
The difference between how we have been organizing work

317
00:11:56,000 --> 00:11:58,240
and how we are about to have to organize it,

318
00:11:58,240 --> 00:12:00,240
that is the old model versus the new model.

319
00:12:00,240 --> 00:12:03,120
And that distinction is where the real architecture decisions happen.

320
00:12:03,120 --> 00:12:05,760
The old model versus the new model,

321
00:12:05,760 --> 00:12:07,840
to understand why this transition is unavoidable,

322
00:12:07,840 --> 00:12:09,440
you need to see exactly what changes

323
00:12:09,440 --> 00:12:12,320
when you move from text-based chat to interactive components.

324
00:12:12,320 --> 00:12:13,840
The difference isn't cosmetic.

325
00:12:13,840 --> 00:12:15,040
It is structural.

326
00:12:15,040 --> 00:12:17,680
And it reveals why most organizations are currently stuck

327
00:12:17,680 --> 00:12:19,440
in a place they did not intend to be.

328
00:12:19,440 --> 00:12:21,200
Here is how work happens in the old model.

329
00:12:21,200 --> 00:12:22,400
You are in operations.

330
00:12:22,400 --> 00:12:23,600
You need to approve a budget.

331
00:12:23,600 --> 00:12:25,440
You navigate to SharePoint.

332
00:12:25,440 --> 00:12:28,240
You know the site name, finance operations.

333
00:12:28,240 --> 00:12:29,920
So you get there directly.

334
00:12:29,920 --> 00:12:31,200
You look for the folder.

335
00:12:31,200 --> 00:12:33,840
It is in shared documents under Q4 approvals.

336
00:12:33,840 --> 00:12:35,200
You find the spreadsheet.

337
00:12:35,200 --> 00:12:37,520
You download it or open it in line.

338
00:12:37,520 --> 00:12:39,280
And then you read through the line items

339
00:12:39,280 --> 00:12:41,440
to see the budget code, the amount,

340
00:12:41,440 --> 00:12:43,760
the department, and the justification.

341
00:12:43,760 --> 00:12:45,760
Now you understand what you are approving.

342
00:12:45,760 --> 00:12:47,600
But you are not in the approval system yet.

343
00:12:47,600 --> 00:12:48,800
That is in a different place.

344
00:12:48,800 --> 00:12:49,840
So you navigate there.

345
00:12:49,840 --> 00:12:51,440
You search for the same budget item.

346
00:12:51,440 --> 00:12:52,800
You find it in the workflow.

347
00:12:52,800 --> 00:12:54,480
And you finally hit approve.

348
00:12:54,480 --> 00:12:55,440
And add your comments.

349
00:12:55,440 --> 00:12:56,720
So the action is logged.

350
00:12:56,720 --> 00:12:57,520
Start to finish.

351
00:12:57,520 --> 00:12:58,720
That took 15 minutes.

352
00:12:58,720 --> 00:13:00,640
Most of that time was not decision making.

353
00:13:00,640 --> 00:13:02,640
It was navigation, searching.

354
00:13:02,640 --> 00:13:04,320
Context switching between the document

355
00:13:04,320 --> 00:13:05,680
and the approval interface.

356
00:13:05,680 --> 00:13:07,760
Now let's look at why that model is breaking.

357
00:13:07,760 --> 00:13:09,440
The friction points are cumulative.

358
00:13:09,440 --> 00:13:11,680
You are switching contexts multiple times.

359
00:13:11,680 --> 00:13:13,600
And each switch costs cognitive load

360
00:13:13,600 --> 00:13:15,040
because your brain has to reset.

361
00:13:15,040 --> 00:13:16,080
You are doing manual search

362
00:13:16,080 --> 00:13:18,240
because you might not remember exactly where things live.

363
00:13:18,240 --> 00:13:20,480
And if the organization has changed the folder structure

364
00:13:20,480 --> 00:13:22,560
or renamed sites, you are lost.

365
00:13:22,560 --> 00:13:24,720
The content you are reading is separated from the action

366
00:13:24,720 --> 00:13:25,520
you are taking.

367
00:13:25,520 --> 00:13:27,680
So you are holding mental state in working memory.

368
00:13:27,680 --> 00:13:29,760
And all of that extends the time between

369
00:13:29,760 --> 00:13:31,120
I need to make a decision.

370
00:13:31,120 --> 00:13:33,600
And the decision is actually recorded.

371
00:13:33,600 --> 00:13:34,640
That is the old model.

372
00:13:34,640 --> 00:13:36,640
And it is the way most organizations

373
00:13:36,640 --> 00:13:38,080
have built their share point.

374
00:13:38,080 --> 00:13:40,240
The new model is different from the ground up.

375
00:13:40,240 --> 00:13:42,880
You ask co-pilot, what budgets need my approval?

376
00:13:42,880 --> 00:13:44,480
Co-pilot does not return a paragraph

377
00:13:44,480 --> 00:13:46,000
describing what needs approval.

378
00:13:46,000 --> 00:13:48,000
Instead, it surfaces a custom component.

379
00:13:48,000 --> 00:13:50,320
That component shows you the pending items

380
00:13:50,320 --> 00:13:52,160
displaying the budget code, amount,

381
00:13:52,160 --> 00:13:53,600
department and justification

382
00:13:53,600 --> 00:13:55,200
all in a formatted view

383
00:13:55,200 --> 00:13:57,360
in line in the co-pilot canvas.

384
00:13:57,360 --> 00:13:59,680
If you want more detail, you can expand an item.

385
00:13:59,680 --> 00:14:01,120
And if you are ready to decide,

386
00:14:01,120 --> 00:14:02,960
there is an approved button right there.

387
00:14:02,960 --> 00:14:03,760
You click it.

388
00:14:03,760 --> 00:14:05,200
The action is recorded.

389
00:14:05,200 --> 00:14:06,000
You are done.

390
00:14:06,000 --> 00:14:07,360
Start to finish.

391
00:14:07,360 --> 00:14:08,560
That took two minutes.

392
00:14:08,560 --> 00:14:09,520
No navigation.

393
00:14:09,520 --> 00:14:10,320
No search.

394
00:14:10,320 --> 00:14:11,840
No context switching.

395
00:14:11,840 --> 00:14:14,000
No cognitive overhead of holding the budget details

396
00:14:14,000 --> 00:14:16,320
in your head while you jump to another system.

397
00:14:16,320 --> 00:14:20,000
The architectural difference is subtle but fundamental.

398
00:14:20,000 --> 00:14:22,880
In the old model, humans are the primary navigation layer.

399
00:14:22,880 --> 00:14:23,840
You know where things are.

400
00:14:23,840 --> 00:14:24,880
You know how to find them.

401
00:14:24,880 --> 00:14:27,280
The system assumes you are going to navigate manually.

402
00:14:27,280 --> 00:14:29,200
AI is an optional help tool.

403
00:14:29,200 --> 00:14:31,120
You ask it questions, it gives you answers

404
00:14:31,120 --> 00:14:32,480
and you go find the thing.

405
00:14:32,480 --> 00:14:35,360
In the new model, AI becomes the navigation layer.

406
00:14:35,360 --> 00:14:37,200
You tell co-pilot what you need.

407
00:14:37,200 --> 00:14:39,040
It does not just answer your question.

408
00:14:39,040 --> 00:14:41,360
It presents the actionable interface directly.

409
00:14:41,360 --> 00:14:42,800
You interact with the component.

410
00:14:42,800 --> 00:14:44,000
You do not navigate separately.

411
00:14:44,000 --> 00:14:45,840
The system assumes you are going to engage

412
00:14:45,840 --> 00:14:46,800
through co-pilot first.

413
00:14:46,800 --> 00:14:49,520
This is why most organizations are stuck between the two.

414
00:14:49,520 --> 00:14:51,280
They have spent years building sharepoint

415
00:14:51,280 --> 00:14:52,400
around the old model.

416
00:14:52,400 --> 00:14:54,080
Sites are organized around navigation.

417
00:14:54,080 --> 00:14:55,840
Documents are structured for discovery.

418
00:14:55,840 --> 00:14:58,000
Workflows require manual entry points.

419
00:14:58,000 --> 00:15:00,000
The entire information architecture assumes

420
00:15:00,000 --> 00:15:01,600
humans are searching and navigating.

421
00:15:01,600 --> 00:15:03,360
Migrating to the new model requires

422
00:15:03,360 --> 00:15:05,280
rethinking that entire structure.

423
00:15:05,280 --> 00:15:06,560
It is not a technical change.

424
00:15:06,560 --> 00:15:08,000
It is a governance change.

425
00:15:08,000 --> 00:15:09,280
That is why some organizations

426
00:15:09,280 --> 00:15:12,160
that have already restructured their information architecture

427
00:15:12,160 --> 00:15:13,520
classified their data,

428
00:15:13,520 --> 00:15:14,720
built permission boundaries

429
00:15:14,720 --> 00:15:16,720
that match compliance requirements

430
00:15:16,720 --> 00:15:19,840
and invested in sensitivity labels and DLP policies

431
00:15:19,840 --> 00:15:22,160
can move to this new model immediately.

432
00:15:22,160 --> 00:15:24,240
Their governance foundation supports it

433
00:15:24,240 --> 00:15:26,480
for organizations that have not done that work.

434
00:15:26,480 --> 00:15:28,560
The new model creates visibility problems

435
00:15:28,560 --> 00:15:30,240
before it creates efficiency gains.

436
00:15:30,240 --> 00:15:32,480
This is observable in early adoption data.

437
00:15:32,480 --> 00:15:34,480
Organizations moving to the new model

438
00:15:34,480 --> 00:15:37,680
are seeing 40 to 60% reduction in time to decision

439
00:15:37,680 --> 00:15:38,960
for structured workflows.

440
00:15:38,960 --> 00:15:40,480
That is not marginal improvement.

441
00:15:40,480 --> 00:15:42,800
That is the difference between operational efficiency

442
00:15:42,800 --> 00:15:44,160
and operational friction.

443
00:15:44,160 --> 00:15:47,200
And this is why SPFX 1.24 isn't just a feature release.

444
00:15:47,200 --> 00:15:49,760
It is the moment when you have to make an explicit governance

445
00:15:49,760 --> 00:15:52,640
choice about which model your organization is operating in.

446
00:15:52,640 --> 00:15:53,920
You are choosing right now

447
00:15:53,920 --> 00:15:55,680
whether to keep building for the old model

448
00:15:55,680 --> 00:15:57,760
or start architecting for the new one.

449
00:15:57,760 --> 00:16:00,640
Why SPFX 1.24 is the inflection point.

450
00:16:00,640 --> 00:16:03,040
This is the moment where the architecture becomes real.

451
00:16:03,040 --> 00:16:04,320
It stops being theoretical.

452
00:16:04,320 --> 00:16:07,280
SharePoint co-pilot apps.

453
00:16:07,280 --> 00:16:09,280
The actual mechanism for surfacing components

454
00:16:09,280 --> 00:16:12,320
in co-pilot enters preview in July 2026

455
00:16:12,320 --> 00:16:15,120
and it arrives alongside SPFX 1.24.

456
00:16:15,120 --> 00:16:17,440
That timing isn't a coincidence.

457
00:16:17,440 --> 00:16:19,520
It is the point where every technical decision you make

458
00:16:19,520 --> 00:16:21,760
about SharePoint becomes an architectural decision

459
00:16:21,760 --> 00:16:22,960
about how you run your AI.

460
00:16:22,960 --> 00:16:25,200
We need to be clear about what actually changed here.

461
00:16:25,200 --> 00:16:27,680
SPFX was originally designed for SharePoint pages

462
00:16:27,680 --> 00:16:29,920
and it was the framework you used to build web parts

463
00:16:29,920 --> 00:16:32,080
or custom interfaces that lived on your internet sites.

464
00:16:32,080 --> 00:16:33,280
That was the use case.

465
00:16:33,280 --> 00:16:34,160
That was the domain.

466
00:16:34,160 --> 00:16:36,720
You used it to extend the page layer of SharePoint.

467
00:16:36,720 --> 00:16:38,960
But now, SPFX is the primary way

468
00:16:38,960 --> 00:16:41,360
to build what Microsoft calls "Egentic UX".

469
00:16:41,360 --> 00:16:43,920
It is the mechanism for putting interactive components

470
00:16:43,920 --> 00:16:46,160
directly into the co-pilot orchestration layer.

471
00:16:46,160 --> 00:16:48,480
This isn't just an expansion of what SPFX can do.

472
00:16:48,480 --> 00:16:51,600
It's a fundamental shift in what the framework is actually for.

473
00:16:51,600 --> 00:16:54,480
But here's the problem with calling it just another version release.

474
00:16:54,480 --> 00:16:56,400
Version 1.24 is the inflection point

475
00:16:56,400 --> 00:16:59,600
because it includes a full suite of dependency modernizations

476
00:16:59,600 --> 00:17:01,600
that go way beyond incremental updates.

477
00:17:01,600 --> 00:17:04,080
You're getting updated NPM packages across the board

478
00:17:04,080 --> 00:17:05,840
which finally reduces the technical debt

479
00:17:05,840 --> 00:17:07,840
you've been carrying from earlier versions.

480
00:17:07,840 --> 00:17:09,600
You're getting React 18 support

481
00:17:09,600 --> 00:17:11,920
and that finally aligns SPFX development

482
00:17:11,920 --> 00:17:13,840
with the mainstream JavaScript ecosystem

483
00:17:13,840 --> 00:17:17,040
instead of keeping you tethered to older, slower patterns.

484
00:17:17,040 --> 00:17:18,880
You're also getting navigation customizers

485
00:17:18,880 --> 00:17:22,560
that let you override how navigation itself works inside SharePoint.

486
00:17:22,560 --> 00:17:23,920
Each of these changes was designed

487
00:17:23,920 --> 00:17:26,320
to remove the friction of building modern components.

488
00:17:26,320 --> 00:17:27,600
So why does that matter?

489
00:17:27,600 --> 00:17:30,720
It matters because if you already have a mature SPFX estate

490
00:17:30,720 --> 00:17:32,640
and you've spent years building webpots

491
00:17:32,640 --> 00:17:34,640
and custom interfaces for your internet,

492
00:17:34,640 --> 00:17:37,680
you can now surface those exact components inside co-pilot

493
00:17:37,680 --> 00:17:39,520
without rebuilding them from scratch.

494
00:17:39,520 --> 00:17:41,120
The components you already built,

495
00:17:41,120 --> 00:17:42,560
the patterns you already established,

496
00:17:42,560 --> 00:17:44,640
the teams that already know how to maintain them,

497
00:17:44,640 --> 00:17:46,080
you aren't starting over.

498
00:17:46,080 --> 00:17:47,840
You're extending.

499
00:17:47,840 --> 00:17:50,560
That is the reuse story that makes this actually achievable

500
00:17:50,560 --> 00:17:51,440
for a business.

501
00:17:51,440 --> 00:17:56,080
If SPFX 1.24 required you to rewrite every existing component,

502
00:17:56,080 --> 00:17:58,800
adoption would be slow and it would be expensive.

503
00:17:58,800 --> 00:18:00,240
Instead, the process is additive.

504
00:18:00,240 --> 00:18:01,680
You take what you've already built,

505
00:18:01,680 --> 00:18:04,160
you apply the 1.24 modernizations

506
00:18:04,160 --> 00:18:06,000
and then you expose it in co-pilot.

507
00:18:06,000 --> 00:18:08,160
The investment you've already made doesn't become obsolete,

508
00:18:08,160 --> 00:18:09,760
it actually becomes more valuable.

509
00:18:09,760 --> 00:18:11,120
And from a governance perspective,

510
00:18:11,120 --> 00:18:14,160
this is where the security stack inheritance really matters.

511
00:18:14,160 --> 00:18:16,160
SPFX runs inside your tenant boundary.

512
00:18:16,160 --> 00:18:18,880
It doesn't crawl out to external servers for logic or data,

513
00:18:18,880 --> 00:18:22,000
so it inherits the full Microsoft 365 security

514
00:18:22,000 --> 00:18:23,760
and governance stack directly.

515
00:18:23,760 --> 00:18:25,520
EntraID handles your identity,

516
00:18:25,520 --> 00:18:27,360
SharePoint enforces your permissions.

517
00:18:27,360 --> 00:18:31,120
Sensitivity labels flow through automatically

518
00:18:31,120 --> 00:18:33,200
and DLP policies apply without you having

519
00:18:33,200 --> 00:18:34,880
to do any additional configuration.

520
00:18:34,880 --> 00:18:36,880
The compliance controls you've already implemented

521
00:18:36,880 --> 00:18:38,640
for regular SharePoint don't need to be redone

522
00:18:38,640 --> 00:18:41,120
for co-pilot components, they're just automatic.

523
00:18:41,120 --> 00:18:43,040
This is a fundamentally different security model

524
00:18:43,040 --> 00:18:44,400
than building custom integrations

525
00:18:44,400 --> 00:18:45,920
that sit outside your tenant boundary.

526
00:18:45,920 --> 00:18:47,280
There is no credential management

527
00:18:47,280 --> 00:18:48,640
across different boundaries.

528
00:18:48,640 --> 00:18:51,040
There are no external API keys to rotate.

529
00:18:51,040 --> 00:18:52,720
There isn't a separate audit trail

530
00:18:52,720 --> 00:18:54,320
that you have to manually correlate

531
00:18:54,320 --> 00:18:55,680
with your internal logging.

532
00:18:55,680 --> 00:18:57,120
The governance model is unified

533
00:18:57,120 --> 00:18:59,280
because the execution model is unified.

534
00:18:59,280 --> 00:19:02,080
The licensing alignment reinforces this even further.

535
00:19:02,080 --> 00:19:04,080
SPFX co-pilot apps are licensed

536
00:19:04,080 --> 00:19:06,880
through the same Microsoft 365 co-pilot seat

537
00:19:06,880 --> 00:19:08,000
you're already paying for.

538
00:19:08,000 --> 00:19:09,760
You aren't buying a separate skew for this.

539
00:19:09,760 --> 00:19:11,840
You aren't dealing with consumption-based billing,

540
00:19:11,840 --> 00:19:13,520
where every component interaction

541
00:19:13,520 --> 00:19:15,200
gets metered and charged per action.

542
00:19:15,200 --> 00:19:16,720
You make one licensing decision

543
00:19:16,720 --> 00:19:19,040
who gets the $30 per month co-pilot seat

544
00:19:19,040 --> 00:19:22,400
and that decision automatically covers your SPFX co-pilot apps.

545
00:19:22,400 --> 00:19:24,640
It's simple, it's predictable, it's governable.

546
00:19:24,640 --> 00:19:27,440
For developers, this completely reframes

547
00:19:27,440 --> 00:19:29,440
what your existing expertise is worth.

548
00:19:29,440 --> 00:19:31,120
Your SharePoint framework skills,

549
00:19:31,120 --> 00:19:33,680
the things you learned for page-level customization

550
00:19:33,680 --> 00:19:36,560
are now your primary asset for running enterprise intelligence.

551
00:19:36,560 --> 00:19:38,240
You aren't becoming an AI developer,

552
00:19:38,240 --> 00:19:40,080
you're becoming an orchestration developer,

553
00:19:40,080 --> 00:19:42,320
and the interface for that orchestration

554
00:19:42,320 --> 00:19:44,480
is the exact skill set you already have.

555
00:19:44,480 --> 00:19:46,800
This is why 1.24 is the inflection point.

556
00:19:46,800 --> 00:19:48,480
It's not because of one single feature.

557
00:19:48,480 --> 00:19:50,000
It's because all of these elements,

558
00:19:50,000 --> 00:19:52,240
the dependencies, the reusable components,

559
00:19:52,240 --> 00:19:53,920
the governance, the licensing,

560
00:19:53,920 --> 00:19:57,200
and the developer relevance all converge at the same moment.

561
00:19:57,200 --> 00:19:59,120
And that convergence is exactly when

562
00:19:59,120 --> 00:20:01,520
the choice between different architectural parts

563
00:20:01,520 --> 00:20:04,560
becomes unavoidable because SPFX isn't your only option.

564
00:20:04,560 --> 00:20:06,000
There is another path entirely,

565
00:20:06,000 --> 00:20:07,520
MCP apps, the open path,

566
00:20:07,520 --> 00:20:08,720
that other paths is MCP,

567
00:20:08,720 --> 00:20:10,000
and understanding what it is

568
00:20:10,000 --> 00:20:11,520
and why it's fundamentally different

569
00:20:11,520 --> 00:20:13,200
from the SPFX approach,

570
00:20:13,200 --> 00:20:16,000
clarifies the entire governance trade-off you're making

571
00:20:16,000 --> 00:20:18,640
when you choose how to build your agent fabric.

572
00:20:18,640 --> 00:20:21,200
MCP stands for Model Context Protocol.

573
00:20:21,200 --> 00:20:23,840
It's a vendor neutral standard created to define

574
00:20:23,840 --> 00:20:27,680
how AI agents discover, call, and interact with tools.

575
00:20:27,680 --> 00:20:29,200
You can think of it as a contract language

576
00:20:29,200 --> 00:20:31,840
between an AI system and external capabilities.

577
00:20:31,840 --> 00:20:33,680
You define what your system can do,

578
00:20:33,680 --> 00:20:35,440
you list the tools it exposes,

579
00:20:35,440 --> 00:20:37,920
and you set the format for the data it returns.

580
00:20:37,920 --> 00:20:39,280
You publish that definition,

581
00:20:39,280 --> 00:20:41,760
and then any AI system that understands MCP

582
00:20:41,760 --> 00:20:43,840
can call those tools, and that is the core appeal,

583
00:20:43,840 --> 00:20:45,040
vendor neutrality.

584
00:20:45,040 --> 00:20:49,200
The same MCP server you build can work with Microsoft 365 Copilot,

585
00:20:49,200 --> 00:20:50,720
but it can also work with Claude,

586
00:20:50,720 --> 00:20:52,800
ChapGPT, or GitHub Copilot.

587
00:20:52,800 --> 00:20:54,480
You write the integration once,

588
00:20:54,480 --> 00:20:57,040
and then you can reuse it across multiple AI platforms.

589
00:20:57,040 --> 00:20:59,280
That's powerful when you think about your investment.

590
00:20:59,280 --> 00:21:02,720
You aren't locking your work into a single AI vendor's ecosystem.

591
00:21:02,720 --> 00:21:04,400
MCP apps take this a step further.

592
00:21:04,400 --> 00:21:07,040
They let your MCP server return interactive UI widgets

593
00:21:07,040 --> 00:21:08,240
alongside the data.

594
00:21:08,240 --> 00:21:09,280
So instead of Copilot,

595
00:21:09,280 --> 00:21:12,080
just giving you a text response about an order status,

596
00:21:12,080 --> 00:21:14,240
your MCP server returns the status data

597
00:21:14,240 --> 00:21:15,520
and a visual component.

598
00:21:15,520 --> 00:21:17,840
That component lets the user update the status,

599
00:21:17,840 --> 00:21:20,080
track the shipping, or start a refund right there.

600
00:21:20,080 --> 00:21:22,640
The widget renders inline in the Copilot canvas.

601
00:21:22,640 --> 00:21:23,840
The user interacts with it.

602
00:21:23,840 --> 00:21:26,080
The data gets updated back through your system.

603
00:21:26,080 --> 00:21:27,360
Here is how it actually works.

604
00:21:27,360 --> 00:21:29,600
You host an MCP server somewhere,

605
00:21:29,600 --> 00:21:31,200
like on-premises, in Azure,

606
00:21:31,200 --> 00:21:33,120
or in any cloud provider you choose.

607
00:21:33,120 --> 00:21:36,000
You write the server in whatever language fits your architecture,

608
00:21:36,000 --> 00:21:37,920
whether that's node, Python, or .NET.

609
00:21:37,920 --> 00:21:39,840
That server defines the tools it exposes

610
00:21:39,840 --> 00:21:41,040
and what those tools do.

611
00:21:41,040 --> 00:21:43,280
When Copilot needs to interact with your system,

612
00:21:43,280 --> 00:21:44,880
it calls your MCP server

613
00:21:44,880 --> 00:21:46,880
and then your server processes the request.

614
00:21:46,880 --> 00:21:49,920
It returns the structured data and the UI metadata.

615
00:21:49,920 --> 00:21:51,360
Copilot renders the response,

616
00:21:51,360 --> 00:21:52,560
the user interacts with it,

617
00:21:52,560 --> 00:21:53,760
and the loop closes.

618
00:21:53,760 --> 00:21:54,960
That sounds straightforward.

619
00:21:54,960 --> 00:22:00,080
But the friction points reveal why this is a different governance category entirely.

620
00:22:00,080 --> 00:22:01,280
To make this work securely,

621
00:22:01,280 --> 00:22:03,440
you need OAuth 2 properly configured.

622
00:22:03,440 --> 00:22:04,640
You need Mutual TLS,

623
00:22:04,640 --> 00:22:07,760
which means both sides of the connection have to authenticate each other.

624
00:22:07,760 --> 00:22:09,760
You need federated credentials in Entra

625
00:22:09,760 --> 00:22:11,920
so that Copilot can authenticate your MCP server

626
00:22:11,920 --> 00:22:14,160
without your server storing credentials in a database.

627
00:22:14,160 --> 00:22:16,160
If you want custom connectors in Power Apps

628
00:22:16,160 --> 00:22:17,680
to call your MCP server,

629
00:22:17,680 --> 00:22:19,120
you have to register those two.

630
00:22:19,120 --> 00:22:20,480
If you want to log what's happening,

631
00:22:20,480 --> 00:22:22,400
you have to instrument your own server.

632
00:22:22,400 --> 00:22:24,320
Each of these steps is very precise.

633
00:22:24,320 --> 00:22:25,680
One misconfigured redirect,

634
00:22:25,680 --> 00:22:27,360
URI breaks the entire flow.

635
00:22:27,360 --> 00:22:29,520
One certificate issue stops everything.

636
00:22:29,520 --> 00:22:31,680
The real governance cost is that your MCP server

637
00:22:31,680 --> 00:22:32,880
is external to your tenant.

638
00:22:32,880 --> 00:22:34,160
That isn't inherently bad,

639
00:22:34,160 --> 00:22:36,160
and sometimes that's exactly what you need.

640
00:22:36,160 --> 00:22:38,800
But it means you are managing identity across a boundary.

641
00:22:38,800 --> 00:22:40,480
You're securing a new integration point.

642
00:22:40,480 --> 00:22:42,160
You're responsible for secret rotation.

643
00:22:42,160 --> 00:22:44,480
You're maintaining audit logs that span your tenant

644
00:22:44,480 --> 00:22:45,680
and an external server.

645
00:22:45,680 --> 00:22:46,560
If something goes wrong,

646
00:22:46,560 --> 00:22:49,760
the forensics require you to correlate data across two different systems.

647
00:22:49,760 --> 00:22:51,920
This is the right choice in specific scenarios.

648
00:22:51,920 --> 00:22:53,360
If your data is scattered,

649
00:22:53,360 --> 00:22:55,120
some in dynamics, some in Salesforce,

650
00:22:55,120 --> 00:22:56,320
some in a custom ERP,

651
00:22:56,320 --> 00:22:57,920
and some in a data warehouse,

652
00:22:57,920 --> 00:23:00,160
then you need something that can orchestrate across all of it.

653
00:23:00,160 --> 00:23:03,120
You can't build every one of those integrations into your tenant.

654
00:23:03,120 --> 00:23:03,920
In that case,

655
00:23:03,920 --> 00:23:06,480
an MCP server becomes the translation layer.

656
00:23:06,480 --> 00:23:08,240
You build ones, you call from co-pilot,

657
00:23:08,240 --> 00:23:10,160
you get vendor agnostic tool reuse.

658
00:23:10,160 --> 00:23:12,000
But you have to notice what you're trading away.

659
00:23:12,000 --> 00:23:13,600
You gain flexibility and portability

660
00:23:13,600 --> 00:23:15,120
across different platforms.

661
00:23:15,120 --> 00:23:16,880
But you lose the unified governance

662
00:23:16,880 --> 00:23:19,200
that comes from staying inside your tenant boundary.

663
00:23:19,200 --> 00:23:21,760
You gain the ability to integrate anything you want.

664
00:23:21,760 --> 00:23:23,920
But you lose the automatic security inheritance

665
00:23:23,920 --> 00:23:26,960
that comes from running on Microsoft 365 infrastructure.

666
00:23:26,960 --> 00:23:28,720
That trade-off is the entire question,

667
00:23:28,720 --> 00:23:30,960
and how you answer it determines which architecture

668
00:23:30,960 --> 00:23:32,400
you are actually building.

669
00:23:32,400 --> 00:23:34,640
SPFX co-pilot apps, the fortified path.

670
00:23:34,640 --> 00:23:37,360
SPFX co-pilot apps operate on a completely different premise.

671
00:23:37,360 --> 00:23:39,840
Instead of building an external MCP server

672
00:23:39,840 --> 00:23:42,080
and figuring out how to integrate it,

673
00:23:42,080 --> 00:23:45,280
you're taking components you've already built inside SharePoint

674
00:23:45,280 --> 00:23:48,240
and exposing them directly into the co-pilot canvas.

675
00:23:48,240 --> 00:23:50,400
The component you created for your internet page

676
00:23:50,400 --> 00:23:52,960
becomes a tool that co-pilot surfaces in line.

677
00:23:52,960 --> 00:23:55,920
No external servers, no authentication bridge,

678
00:23:55,920 --> 00:23:57,600
no integration complexity.

679
00:23:57,600 --> 00:23:58,880
Here's the technical model.

680
00:23:58,880 --> 00:24:02,000
You build a web part or extension using SharePoint framework,

681
00:24:02,000 --> 00:24:04,240
which is the same way you've been doing it for years.

682
00:24:04,240 --> 00:24:07,760
You package it, you deploy it to the SharePoint app catalog.

683
00:24:07,760 --> 00:24:10,560
When co-pilot needs to surface interactive capabilities,

684
00:24:10,560 --> 00:24:13,280
it pulls that component and renders it in the chat canvas.

685
00:24:13,280 --> 00:24:15,120
The user interacts with the component

686
00:24:15,120 --> 00:24:18,560
and the data flows directly through your SharePoint infrastructure.

687
00:24:18,560 --> 00:24:19,840
Everything stays inside.

688
00:24:19,840 --> 00:24:20,960
This different sounds minor.

689
00:24:20,960 --> 00:24:22,160
It's actually fundamental.

690
00:24:22,160 --> 00:24:24,800
The governance advantage is where this becomes concrete.

691
00:24:24,800 --> 00:24:26,960
Everything runs inside your tenant boundary,

692
00:24:26,960 --> 00:24:29,120
so there is no external server to secure

693
00:24:29,120 --> 00:24:32,320
and no authentication handshake across a network boundary.

694
00:24:32,320 --> 00:24:34,240
Identity is handled by Enter directly.

695
00:24:34,240 --> 00:24:36,160
The component runs with the user's credentials

696
00:24:36,160 --> 00:24:37,440
in the user's context.

697
00:24:37,440 --> 00:24:40,400
Permissions are enforced through your existing SharePoint permission model.

698
00:24:40,400 --> 00:24:41,680
If you don't have access to a list,

699
00:24:41,680 --> 00:24:43,520
the component won't fetch data from it.

700
00:24:43,520 --> 00:24:46,080
If you can't modify something, the button will be disabled.

701
00:24:46,080 --> 00:24:48,240
That's not a separate security layer

702
00:24:48,240 --> 00:24:51,120
that's your existing permission model being applied automatically.

703
00:24:51,120 --> 00:24:52,400
Audit logging is built in.

704
00:24:52,400 --> 00:24:56,160
Every interaction with an SPFX component in co-pilot gets logged

705
00:24:56,160 --> 00:24:59,040
to purview the same way any other SharePoint action does.

706
00:24:59,040 --> 00:25:00,640
You don't need to instrument custom logging.

707
00:25:00,640 --> 00:25:02,720
You don't need to correlate logs across systems.

708
00:25:02,720 --> 00:25:05,840
The audit trail is unified because the execution is unified.

709
00:25:05,840 --> 00:25:09,120
The reuse story is what makes this actually practical at scale.

710
00:25:09,120 --> 00:25:12,000
If you spent the last five years building SPFX webpots

711
00:25:12,000 --> 00:25:14,400
for your internet like a dashboard for project status

712
00:25:14,400 --> 00:25:16,160
or a form for incident reporting,

713
00:25:16,160 --> 00:25:17,280
you don't throw those away.

714
00:25:17,280 --> 00:25:18,640
You surface them in co-pilot.

715
00:25:18,640 --> 00:25:20,240
The component code doesn't need to change

716
00:25:20,240 --> 00:25:22,080
because you aren't rewriting from scratch.

717
00:25:22,080 --> 00:25:23,840
You're exposing what you already have.

718
00:25:23,840 --> 00:25:25,600
That's a massive practical advantage.

719
00:25:25,600 --> 00:25:27,520
You inherit five years of refinement,

720
00:25:27,520 --> 00:25:29,440
five years of performance optimization,

721
00:25:29,440 --> 00:25:31,520
and five years of user feedback baked in.

722
00:25:31,520 --> 00:25:33,520
You're not starting a new technical project.

723
00:25:33,520 --> 00:25:35,760
You're using an existing asset in a new context.

724
00:25:35,760 --> 00:25:38,560
The licensing alignment reinforces the simplicity.

725
00:25:38,560 --> 00:25:40,400
SPFX co-pilot apps are licensed

726
00:25:40,400 --> 00:25:43,120
through the standard M365 co-pilot seat.

727
00:25:43,120 --> 00:25:44,320
There's no additional SKU.

728
00:25:44,320 --> 00:25:45,680
There's no consumption-based billing

729
00:25:45,680 --> 00:25:47,680
where component interactions get metered.

730
00:25:47,680 --> 00:25:50,880
You made the decision about who gets the $30 per month license

731
00:25:50,880 --> 00:25:54,080
and that decision automatically extends to SPFX co-pilot apps.

732
00:25:54,080 --> 00:25:56,000
Every person with a co-pilot license can interact

733
00:25:56,000 --> 00:25:57,440
with every SPFX component.

734
00:25:57,440 --> 00:25:59,440
The licensing model is clear and predictable.

735
00:25:59,440 --> 00:26:01,120
But there's a constraint you need to acknowledge.

736
00:26:01,120 --> 00:26:04,320
SPFX is fundamentally locked into the Microsoft 365 ecosystem.

737
00:26:04,320 --> 00:26:05,600
It doesn't work with Claude.

738
00:26:05,600 --> 00:26:06,880
It doesn't work with ChatGPT.

739
00:26:06,880 --> 00:26:08,480
It doesn't work with any AI platform

740
00:26:08,480 --> 00:26:09,920
that doesn't understand SPFX.

741
00:26:09,920 --> 00:26:12,320
If you're building for maximum vendor portability

742
00:26:12,320 --> 00:26:14,560
or if you're planning to use the same integration logic

743
00:26:14,560 --> 00:26:17,680
across multiple AI systems, SPFX constrains you.

744
00:26:17,680 --> 00:26:18,480
That's not a bug.

745
00:26:18,480 --> 00:26:19,360
It's a trade-off.

746
00:26:19,360 --> 00:26:21,440
The use case fit is where you see this play out.

747
00:26:21,440 --> 00:26:24,720
SPFX co-pilot apps excel at internet orchestration,

748
00:26:24,720 --> 00:26:28,000
which means surfacing company news, organizational information

749
00:26:28,000 --> 00:26:30,160
and employee resources directly in Chat.

750
00:26:30,160 --> 00:26:31,600
They excel at knowledge management

751
00:26:31,600 --> 00:26:33,680
by bringing documentation, FAQs,

752
00:26:33,680 --> 00:26:36,000
and procedural guides into the flow of work.

753
00:26:36,000 --> 00:26:37,840
They excel at list-driven workflows

754
00:26:37,840 --> 00:26:40,080
like approvals, requests, and status updates

755
00:26:40,080 --> 00:26:42,160
where the data lives in SharePoint lists.

756
00:26:42,160 --> 00:26:44,000
They excel at document-centric actions,

757
00:26:44,000 --> 00:26:46,800
allowing someone to search, preview, and modify documents

758
00:26:46,800 --> 00:26:48,080
without leaving the conversation.

759
00:26:48,080 --> 00:26:50,160
Anywhere SharePoint is already the system of record.

760
00:26:50,160 --> 00:26:52,000
SPFX is the natural path.

761
00:26:52,000 --> 00:26:54,480
Where they don't fit is scenarios where your data

762
00:26:54,480 --> 00:26:56,800
is scattered across multiple platforms

763
00:26:56,800 --> 00:26:59,520
and you need a single integration layer that works everywhere.

764
00:26:59,520 --> 00:27:00,800
That's the MCP scenario.

765
00:27:00,800 --> 00:27:03,600
That's where you need the flexibility of an external server

766
00:27:03,600 --> 00:27:06,080
and the portability of a vendor neutral standard.

767
00:27:06,080 --> 00:27:08,080
So when you're standing at the fork in the road,

768
00:27:08,080 --> 00:27:10,800
deciding whether to build MCP or build SPFX,

769
00:27:10,800 --> 00:27:14,480
you're not actually choosing between two equally flexible options.

770
00:27:14,480 --> 00:27:18,160
You're choosing between two completely different governance philosophies.

771
00:27:18,160 --> 00:27:19,440
The governance trade-off.

772
00:27:19,440 --> 00:27:22,640
So here's where we get concrete about the decision you're actually making.

773
00:27:22,640 --> 00:27:25,200
There's attention sitting underneath this entire choice

774
00:27:25,200 --> 00:27:27,120
and it determines everything that comes after

775
00:27:27,120 --> 00:27:28,960
MCP offers flexibility.

776
00:27:28,960 --> 00:27:30,880
SPFX offers assurance.

777
00:27:30,880 --> 00:27:32,960
Those two things point in opposite directions

778
00:27:32,960 --> 00:27:35,840
and where you land on that spectrum depends entirely on

779
00:27:35,840 --> 00:27:38,480
what your organization can actually afford to govern.

780
00:27:38,480 --> 00:27:41,200
That's unpack what governance actually means in each scenario.

781
00:27:41,200 --> 00:27:43,840
With MCP, you're managing a new integration boundary.

782
00:27:43,840 --> 00:27:46,000
Your server sits somewhere, whether it's in Azure,

783
00:27:46,000 --> 00:27:48,400
your own data center, or managed by a vendor.

784
00:27:48,400 --> 00:27:49,600
The moment you deploy it,

785
00:27:49,600 --> 00:27:53,200
you've created a new place where secrets need to be stored and rotated.

786
00:27:53,200 --> 00:27:57,120
O-auth credentials, API keys, certificates for mutual TLS.

787
00:27:57,120 --> 00:27:58,800
All of that is your responsibility now.

788
00:27:58,800 --> 00:28:00,640
You can't delegate that to Microsoft.

789
00:28:00,640 --> 00:28:02,480
You can't inherit it from the platform.

790
00:28:02,480 --> 00:28:03,440
You have to own it.

791
00:28:03,440 --> 00:28:05,600
Identity propagation becomes your problem too.

792
00:28:05,600 --> 00:28:07,440
When co-pilot calls your MCP server,

793
00:28:07,440 --> 00:28:09,440
it needs to pass along the user's identity

794
00:28:09,440 --> 00:28:12,720
so that your server can enforce the right permissions on the right data.

795
00:28:12,720 --> 00:28:14,560
That handoff has to be set up correctly.

796
00:28:14,560 --> 00:28:17,120
A misconfiguration means users see data they shouldn't,

797
00:28:17,120 --> 00:28:18,800
or legitimate requests get blocked.

798
00:28:19,440 --> 00:28:21,280
Audit logging spans two systems now.

799
00:28:21,280 --> 00:28:22,640
Co-pilot logs what it did.

800
00:28:22,640 --> 00:28:24,480
Your MCP server logs what it did.

801
00:28:24,480 --> 00:28:25,440
But those logs are separate.

802
00:28:25,440 --> 00:28:27,520
If you need a complete forensic trail of what happened,

803
00:28:27,520 --> 00:28:29,840
you're correlating logs from two different places.

804
00:28:29,840 --> 00:28:32,480
And you need to make sure that correlation is actually possible,

805
00:28:32,480 --> 00:28:35,040
ensuring that timestamps align and user identities match

806
00:28:35,040 --> 00:28:36,320
so the story is coherent.

807
00:28:36,320 --> 00:28:39,120
If your MCP server calls external APIs,

808
00:28:39,120 --> 00:28:41,920
like pulling data from Salesforce or an ERP system,

809
00:28:41,920 --> 00:28:44,320
you need to implement DLP at the API level.

810
00:28:44,320 --> 00:28:45,920
You need custom logic that says,

811
00:28:45,920 --> 00:28:47,760
don't return this field because it's sensitive.

812
00:28:47,760 --> 00:28:50,000
Or don't allow this combination of data flows

813
00:28:50,000 --> 00:28:51,440
because it violates compliance.

814
00:28:51,440 --> 00:28:53,440
That's not something Microsoft can do for you.

815
00:28:53,440 --> 00:28:54,640
That's code you write.

816
00:28:54,640 --> 00:28:57,520
All of this requires security engineering expertise.

817
00:28:57,520 --> 00:28:59,920
Not I know how to configure Azure AD.

818
00:28:59,920 --> 00:29:03,200
Not I understand how to manage SharePoint permissions.

819
00:29:03,200 --> 00:29:06,000
This is I know how to build secure API integrations

820
00:29:06,000 --> 00:29:08,480
with proper credential rotation and audit trails.

821
00:29:08,480 --> 00:29:09,760
That's a different skill set.

822
00:29:09,760 --> 00:29:12,000
SPFX has a different governance surface.

823
00:29:12,000 --> 00:29:13,840
You're not managing a separate security boundary

824
00:29:13,840 --> 00:29:15,520
because there is no separate boundary.

825
00:29:15,520 --> 00:29:17,520
Your components run inside your tenant.

826
00:29:17,520 --> 00:29:20,720
Identity is handled by Android permissions flow from SharePoint.

827
00:29:20,720 --> 00:29:23,680
DLP policies that you've already set up apply automatically.

828
00:29:23,680 --> 00:29:24,560
Audit is built in.

829
00:29:24,560 --> 00:29:25,760
You're not solving new problems.

830
00:29:25,760 --> 00:29:27,840
Your extending governance that already exists.

831
00:29:27,840 --> 00:29:29,280
Your governance requirements are different.

832
00:29:29,280 --> 00:29:31,840
You need to control who can deploy to the app catalog.

833
00:29:31,840 --> 00:29:33,680
You need SharePoint governance discipline,

834
00:29:33,680 --> 00:29:36,640
which means making sure permissions are structured correctly,

835
00:29:36,640 --> 00:29:37,600
data is classified,

836
00:29:37,600 --> 00:29:40,000
and your sensitivity labeling is consistent.

837
00:29:40,000 --> 00:29:42,400
You need to enforce your existing policies rigorously

838
00:29:42,400 --> 00:29:44,160
because the component will inherit them.

839
00:29:44,160 --> 00:29:46,160
But you're not inventing new governance layers.

840
00:29:46,160 --> 00:29:49,680
This requires SharePoint expertise and governance discipline.

841
00:29:49,680 --> 00:29:51,600
Not I know how to write OAuth flows.

842
00:29:51,600 --> 00:29:53,920
This is I understand how SharePoint permissions work

843
00:29:53,920 --> 00:29:55,600
and how to structure a site hierarchy

844
00:29:55,600 --> 00:29:57,360
that actually matches your compliance requirements.

845
00:29:57,360 --> 00:29:59,840
Here's where organizations get stuck.

846
00:29:59,840 --> 00:30:01,360
Someone MCP's flexibility,

847
00:30:01,360 --> 00:30:03,200
but can't afford the security overhead.

848
00:30:03,200 --> 00:30:04,480
They don't have the infrastructure,

849
00:30:04,480 --> 00:30:05,200
the expertise,

850
00:30:05,200 --> 00:30:06,560
or the governance maturity

851
00:30:06,560 --> 00:30:08,800
to manage external integration securely.

852
00:30:08,800 --> 00:30:10,160
So they look at MCP and realize

853
00:30:10,160 --> 00:30:11,760
it's not actually an option for them.

854
00:30:11,760 --> 00:30:13,600
Others want SPFX's assurance

855
00:30:13,600 --> 00:30:15,920
but lack the SharePoint governance foundation.

856
00:30:15,920 --> 00:30:17,280
Their sites are overshared,

857
00:30:17,280 --> 00:30:18,800
their data is unclassified,

858
00:30:18,800 --> 00:30:19,920
their permissions are flat,

859
00:30:19,920 --> 00:30:21,680
they look at SPFX and realize

860
00:30:21,680 --> 00:30:24,080
they can't safely expose their components in co-pilot

861
00:30:24,080 --> 00:30:26,240
because the governance underneath is too weak.

862
00:30:26,240 --> 00:30:27,840
The decision framework is simple.

863
00:30:27,840 --> 00:30:30,400
If your data lives in SharePoint, use SPFX.

864
00:30:30,400 --> 00:30:31,840
Get your governance house in order.

865
00:30:31,840 --> 00:30:34,880
The investment pays itself back in operational simplicity.

866
00:30:34,880 --> 00:30:37,840
If your data is scattered across systems, use MCP.

867
00:30:37,840 --> 00:30:40,320
But budget for the security investment is not optional.

868
00:30:40,320 --> 00:30:42,000
Some organizations do both.

869
00:30:42,000 --> 00:30:44,480
They use SPFX for SharePoint centric workflows

870
00:30:44,480 --> 00:30:46,480
and MCP for cross-system orchestration.

871
00:30:46,480 --> 00:30:48,560
But that requires dual governance models.

872
00:30:48,560 --> 00:30:50,720
Two security patterns, two audit frameworks.

873
00:30:50,720 --> 00:30:51,760
That's only sustainable

874
00:30:51,760 --> 00:30:53,840
if you have the organizational maturity to manage it.

875
00:30:53,840 --> 00:30:55,040
The core insight is this.

876
00:30:55,040 --> 00:30:56,560
The agent fabric isn't one solution.

877
00:30:56,560 --> 00:30:58,320
It's a framework that chooses based

878
00:30:58,320 --> 00:30:59,760
on your governance constraints.

879
00:30:59,760 --> 00:31:01,360
And understanding those constraints right now

880
00:31:01,360 --> 00:31:03,360
determines whether you're building something sustainable

881
00:31:03,360 --> 00:31:05,680
or something you'll have to remediate later.

882
00:31:05,680 --> 00:31:07,840
The death of TeamsFX and the consolidation.

883
00:31:07,840 --> 00:31:10,240
There is a deprecation notice sitting in the documentation

884
00:31:10,240 --> 00:31:12,320
that most organizations haven't even registered yet.

885
00:31:12,320 --> 00:31:14,400
The TeamsFX SDK is going away.

886
00:31:14,400 --> 00:31:16,960
It will be fully retired by July 2026.

887
00:31:16,960 --> 00:31:19,680
If you have TeamsFX solutions running in production right now,

888
00:31:19,680 --> 00:31:21,520
you need to understand exactly what that means

889
00:31:21,520 --> 00:31:23,520
and why Microsoft is making this move.

890
00:31:23,520 --> 00:31:25,280
TeamsFX was originally positioned

891
00:31:25,280 --> 00:31:27,520
as the primary way to build Teams apps.

892
00:31:27,520 --> 00:31:29,920
It was an attempt to create a simplified developer experience

893
00:31:29,920 --> 00:31:31,280
for building custom applications

894
00:31:31,280 --> 00:31:33,600
that lived specifically inside the Teams client.

895
00:31:33,600 --> 00:31:36,720
Instead of dealing with the full complexity of the SharePoint framework,

896
00:31:36,720 --> 00:31:38,800
you could use TeamsFX to get templates

897
00:31:38,800 --> 00:31:40,400
and a much lighter toolkit.

898
00:31:40,400 --> 00:31:41,360
It made sense at the time

899
00:31:41,360 --> 00:31:42,480
because Teams was exploding

900
00:31:42,480 --> 00:31:45,360
and every organization wanted to build custom experiences

901
00:31:45,360 --> 00:31:46,320
for their channels.

902
00:31:46,320 --> 00:31:48,320
TeamsFX was supposed to make that easy,

903
00:31:48,320 --> 00:31:50,240
but the enterprise moved in a different direction.

904
00:31:50,240 --> 00:31:52,160
And that movement is what is killing TeamsFX.

905
00:31:52,160 --> 00:31:53,600
The shift is fundamental.

906
00:31:53,600 --> 00:31:55,920
Organizations stopped thinking about Teams apps

907
00:31:55,920 --> 00:31:56,800
as a distinct category

908
00:31:56,800 --> 00:31:58,800
and started thinking about co-pilot apps instead.

909
00:31:58,800 --> 00:32:00,160
These are experiences that operate

910
00:32:00,160 --> 00:32:01,920
through the AI orchestration layer

911
00:32:01,920 --> 00:32:04,480
rather than through a specific surface like a Teams tab.

912
00:32:04,480 --> 00:32:06,320
That is a different architecture entirely.

913
00:32:06,320 --> 00:32:07,680
The moment that shift happened,

914
00:32:07,680 --> 00:32:09,200
maintaining two separate frameworks

915
00:32:09,200 --> 00:32:12,160
like SPFX and TeamsFX became unnecessary overhead.

916
00:32:12,160 --> 00:32:13,360
Here is what it means practically.

917
00:32:13,360 --> 00:32:16,000
If you built a request approval app in TeamsFX,

918
00:32:16,000 --> 00:32:18,800
that app lived inside a specific Teams channel.

919
00:32:18,800 --> 00:32:20,480
Users had to navigate to the channel,

920
00:32:20,480 --> 00:32:22,240
open the app and fill out a form

921
00:32:22,240 --> 00:32:23,520
for the request to go through.

922
00:32:23,520 --> 00:32:25,440
It worked, but it only worked inside Teams.

923
00:32:25,440 --> 00:32:27,280
It was not discoverable through co-pilot,

924
00:32:27,280 --> 00:32:29,200
it was not accessible through SharePoint

925
00:32:29,200 --> 00:32:30,240
and it did not participate

926
00:32:30,240 --> 00:32:31,760
in the broader orchestration layer.

927
00:32:31,760 --> 00:32:33,280
It was a single surface solution.

928
00:32:33,280 --> 00:32:35,600
SPFX co-pilot apps changed that equation.

929
00:32:35,600 --> 00:32:36,880
The same approval experience

930
00:32:36,880 --> 00:32:38,720
can now surface inside co-pilot,

931
00:32:38,720 --> 00:32:39,760
inside SharePoint,

932
00:32:39,760 --> 00:32:42,400
or inside the Microsoft 365 app.

933
00:32:42,400 --> 00:32:43,760
You build the logic once

934
00:32:43,760 --> 00:32:46,400
and surface it everywhere the organization needs it.

935
00:32:46,400 --> 00:32:48,320
That is not just a marginal improvement.

936
00:32:48,320 --> 00:32:50,560
It is a different value proposition entirely.

937
00:32:50,560 --> 00:32:51,600
From that perspective,

938
00:32:51,600 --> 00:32:53,520
maintaining TeamsFX as a separate framework

939
00:32:53,520 --> 00:32:54,560
no longer makes sense.

940
00:32:54,560 --> 00:32:56,080
The framework that can do everything

941
00:32:56,080 --> 00:32:57,760
is the one you want to standardize on.

942
00:32:57,760 --> 00:33:00,000
So TeamsFX is being deprecated.

943
00:33:00,000 --> 00:33:02,000
If you have it in production, you have two paths.

944
00:33:02,000 --> 00:33:04,960
You can rewrite for SPFX 1.24

945
00:33:04,960 --> 00:33:07,600
to gain all that multi-surface capability.

946
00:33:07,600 --> 00:33:09,440
Or you can migrate to Power Apps.

947
00:33:09,440 --> 00:33:11,440
If your solution is heavy on business logic

948
00:33:11,440 --> 00:33:12,960
and light on custom UI,

949
00:33:12,960 --> 00:33:14,400
Power Apps is getting much better

950
00:33:14,400 --> 00:33:16,000
at building structured applications

951
00:33:16,000 --> 00:33:17,200
and it integrates directly

952
00:33:17,200 --> 00:33:19,040
with co-pilot studio for orchestration.

953
00:33:19,040 --> 00:33:20,800
The timing creates real pressure.

954
00:33:20,800 --> 00:33:23,200
July 2026 is the hard deadline

955
00:33:23,200 --> 00:33:25,680
and that is not as far away as it sounds.

956
00:33:25,680 --> 00:33:28,080
If you have a production TeamsFX application right now,

957
00:33:28,080 --> 00:33:30,000
you have roughly a year to decide on a path

958
00:33:30,000 --> 00:33:31,280
and execute the migration.

959
00:33:31,280 --> 00:33:32,480
Delaying does not make sense

960
00:33:32,480 --> 00:33:34,560
because the work won't get easier if you wait.

961
00:33:34,560 --> 00:33:35,440
The sooner you move,

962
00:33:35,440 --> 00:33:37,520
the sooner you can take advantage of the capabilities

963
00:33:37,520 --> 00:33:38,800
that come with the new architecture.

964
00:33:38,800 --> 00:33:40,480
But here is what actually matters about this.

965
00:33:40,480 --> 00:33:43,440
The TeamsFX deprecation is not just a technology problem.

966
00:33:43,440 --> 00:33:45,840
It is an opportunity because the forced migration

967
00:33:45,840 --> 00:33:47,760
is exactly the moment to re-architect

968
00:33:47,760 --> 00:33:49,360
how you think about these solutions.

969
00:33:49,360 --> 00:33:51,200
Instead of just patching your existing app

970
00:33:51,200 --> 00:33:52,400
and moving it to SPFX,

971
00:33:52,400 --> 00:33:53,520
you can step back and ask

972
00:33:53,520 --> 00:33:55,200
what the application is actually trying to do.

973
00:33:55,200 --> 00:33:57,920
Is it better modeled as an SPFX component exposed

974
00:33:57,920 --> 00:33:59,040
through co-pilot?

975
00:33:59,040 --> 00:34:00,400
Is it actually a business process

976
00:34:00,400 --> 00:34:01,920
that belongs in Power Apps

977
00:34:01,920 --> 00:34:03,680
with governance-driven automation?

978
00:34:03,680 --> 00:34:05,520
Does it need to orchestrate across systems?

979
00:34:05,520 --> 00:34:07,760
Which might mean building an MCP server instead?

980
00:34:07,760 --> 00:34:09,920
The people writing TeamsFX code right now

981
00:34:09,920 --> 00:34:12,480
are about to make a career inflection point decision.

982
00:34:12,480 --> 00:34:14,080
You can upskill to SPFX

983
00:34:14,080 --> 00:34:15,920
and become an agentex UX developer

984
00:34:15,920 --> 00:34:17,600
who builds the interactive components

985
00:34:17,600 --> 00:34:19,920
that operationalize enterprise intelligence.

986
00:34:19,920 --> 00:34:22,320
That is a growing market where all the investment is going.

987
00:34:22,320 --> 00:34:24,080
Or you can pivot toward Power Apps

988
00:34:24,080 --> 00:34:25,840
and become a business process architect.

989
00:34:25,840 --> 00:34:27,600
That is also a massive growth area

990
00:34:27,600 --> 00:34:29,120
but you cannot stay in TeamsFX

991
00:34:29,120 --> 00:34:30,240
that door is closing.

992
00:34:30,240 --> 00:34:31,760
And that closure is a signal

993
00:34:31,760 --> 00:34:33,520
about the bigger structural shift.

994
00:34:33,520 --> 00:34:36,240
Microsoft is consolidating its extensibility stack.

995
00:34:36,240 --> 00:34:39,360
The future is not multiple frameworks for multiple surfaces.

996
00:34:39,360 --> 00:34:42,320
It is unified orchestration through the agent fabric

997
00:34:42,320 --> 00:34:44,720
with SPFX as the primary mechanism

998
00:34:44,720 --> 00:34:46,800
for interactive components and Power Apps

999
00:34:46,800 --> 00:34:49,200
as the primary mechanism for business logic.

1000
00:34:49,200 --> 00:34:50,960
That consolidation makes sense.

1001
00:34:50,960 --> 00:34:52,640
It reduces complexity

1002
00:34:52,640 --> 00:34:55,200
and aligns everything around a coherent architecture.

1003
00:34:55,200 --> 00:34:57,120
It reveals what the next generation

1004
00:34:57,120 --> 00:34:59,520
of enterprise development actually looks like.

1005
00:34:59,520 --> 00:35:00,720
The security hardening,

1006
00:35:00,720 --> 00:35:02,720
CSP enforcement and beyond.

1007
00:35:02,720 --> 00:35:04,080
There is another date on the calendar

1008
00:35:04,080 --> 00:35:06,560
that matters just as much as the TeamsFX deadline.

1009
00:35:06,560 --> 00:35:08,400
And it is going to break a lot of assumptions

1010
00:35:08,400 --> 00:35:11,200
about how you have been building SPFX solutions.

1011
00:35:11,200 --> 00:35:13,200
On March 1st, 2026,

1012
00:35:13,200 --> 00:35:15,280
Content Security Policy Enforcement moves

1013
00:35:15,280 --> 00:35:18,560
from report-only mode to enforced mode in SharePoint Online.

1014
00:35:18,560 --> 00:35:19,680
What does that actually mean?

1015
00:35:19,680 --> 00:35:23,280
Right now, if an SPFX solution loads a script from a CDN

1016
00:35:23,280 --> 00:35:24,800
that is not on the approved list,

1017
00:35:24,800 --> 00:35:26,240
SharePoint logs the event.

1018
00:35:26,240 --> 00:35:28,080
It reports it but it does not block it.

1019
00:35:28,080 --> 00:35:30,800
The script still runs and the solution still works.

1020
00:35:30,800 --> 00:35:32,160
You might get a warning in the console

1021
00:35:32,160 --> 00:35:34,240
but nothing actually breaks for the end user.

1022
00:35:34,240 --> 00:35:36,080
Starting March 1st, that changes.

1023
00:35:36,080 --> 00:35:38,160
Inline scripts will be blocked outright.

1024
00:35:38,160 --> 00:35:40,240
External scripts will have to be explicitly registered

1025
00:35:40,240 --> 00:35:41,840
as trusted script sources

1026
00:35:41,840 --> 00:35:43,280
in the SharePoint Admin Center.

1027
00:35:43,280 --> 00:35:45,040
If a script is not on that approved list,

1028
00:35:45,040 --> 00:35:47,200
the browser will simply refuse to execute it.

1029
00:35:47,200 --> 00:35:49,280
The violation will get logged in per view audit

1030
00:35:49,280 --> 00:35:50,800
so you can see what was attempted

1031
00:35:50,800 --> 00:35:52,640
but the code itself will not run.

1032
00:35:52,640 --> 00:35:53,840
This matters for SPFX

1033
00:35:53,840 --> 00:35:56,480
because many existing solutions rely on loading libraries

1034
00:35:56,480 --> 00:35:58,240
from external CDNs like JQuery

1035
00:35:58,240 --> 00:35:59,840
or specialized charting helpers.

1036
00:35:59,840 --> 00:36:02,560
If those sources are not pre-registered as trusted,

1037
00:36:02,560 --> 00:36:04,720
they will stop working and the solution will break.

1038
00:36:04,720 --> 00:36:07,680
Users will see incomplete functionality or errors on the page.

1039
00:36:07,680 --> 00:36:09,920
It is not just a security issue at that point.

1040
00:36:09,920 --> 00:36:11,840
It is a total loss of capability.

1041
00:36:11,840 --> 00:36:13,920
If you have SPFX solutions in production right now,

1042
00:36:13,920 --> 00:36:15,920
you need to audit your dependencies immediately.

1043
00:36:15,920 --> 00:36:18,400
You need to know what external scripts you are loading

1044
00:36:18,400 --> 00:36:19,840
and where they are hosted.

1045
00:36:19,840 --> 00:36:22,720
This is the work that must happen between now and March 1st.

1046
00:36:22,720 --> 00:36:25,520
If you discover a dependency that is not trusted,

1047
00:36:25,520 --> 00:36:28,800
you can register the source, move the code to a trusted host

1048
00:36:28,800 --> 00:36:32,240
or refactor the solution to eliminate the dependency entirely.

1049
00:36:32,240 --> 00:36:34,800
But you have to know about it before the enforcement date hits.

1050
00:36:34,800 --> 00:36:37,440
The governance implication is what makes this architectural.

1051
00:36:37,440 --> 00:36:39,280
CSP is becoming a central control

1052
00:36:39,280 --> 00:36:41,040
for what code can execute in your tenant.

1053
00:36:41,040 --> 00:36:43,280
Microsoft is not just blocking random scripts.

1054
00:36:43,280 --> 00:36:45,600
They are enforcing a white list of approved sources.

1055
00:36:45,600 --> 00:36:48,000
That is a governance model that applies uniformly

1056
00:36:48,000 --> 00:36:49,520
across the entire tenant.

1057
00:36:49,520 --> 00:36:52,960
Here is where the SPFX security model is actually quite elegant.

1058
00:36:52,960 --> 00:36:56,080
SPFX solutions do not run with elevated privileges.

1059
00:36:56,080 --> 00:36:58,560
They run with the user's identity and permissions.

1060
00:36:58,560 --> 00:37:02,960
When a component executes, it can only do what that specific user is allowed to do manually.

1061
00:37:02,960 --> 00:37:05,040
The security boundary is the user's permissions,

1062
00:37:05,040 --> 00:37:06,480
not the code's privileges.

1063
00:37:06,480 --> 00:37:09,760
That is different from systems where code runs with service account privileges,

1064
00:37:09,760 --> 00:37:11,040
which would be much riskier.

1065
00:37:11,040 --> 00:37:13,440
SPFX is delegation based by design.

1066
00:37:13,440 --> 00:37:15,920
The code inherits the user's permission context.

1067
00:37:15,920 --> 00:37:17,280
But here is the part that matters.

1068
00:37:17,280 --> 00:37:19,120
CSP controls whether code runs at all,

1069
00:37:19,120 --> 00:37:22,480
while DLP controls what that code can do with data once it is running.

1070
00:37:22,480 --> 00:37:25,840
You can build an SPFX component that is perfectly CSP compliant

1071
00:37:25,840 --> 00:37:28,000
where every script comes from a trusted source.

1072
00:37:28,000 --> 00:37:30,880
But that component could still send data to an external API

1073
00:37:30,880 --> 00:37:32,160
if the browser can reach it,

1074
00:37:32,160 --> 00:37:34,880
and your DLP policy does not block the traffic.

1075
00:37:34,880 --> 00:37:37,200
CSP does not prevent data exfiltration.

1076
00:37:37,200 --> 00:37:39,200
It only controls code execution.

1077
00:37:39,200 --> 00:37:40,880
Those are two different layers of the stack.

1078
00:37:40,880 --> 00:37:45,040
So the real security question is not just whether your solution is compliant with CSP.

1079
00:37:45,040 --> 00:37:47,040
The real question is where that code can send data

1080
00:37:47,040 --> 00:37:49,440
and whether you have restricted those flows with DLP.

1081
00:37:49,440 --> 00:37:51,520
The mitigation layers are very specific.

1082
00:37:51,520 --> 00:37:54,080
First, you must classify your data systematically

1083
00:37:54,080 --> 00:37:56,560
because you cannot protect what you haven't identified.

1084
00:37:56,560 --> 00:37:58,560
Apply sensitivity labels to high-risk content

1085
00:37:58,560 --> 00:38:01,760
and configure DLP policies that are scoped to co-pilot interactions.

1086
00:38:01,760 --> 00:38:05,040
If you have a policy that says not to share data with external systems,

1087
00:38:05,040 --> 00:38:07,520
make sure it applies when data flows through co-pilot.

1088
00:38:07,520 --> 00:38:10,240
Monitor external API calls from your SPFX components.

1089
00:38:10,240 --> 00:38:11,920
If you see requests going to domains,

1090
00:38:11,920 --> 00:38:14,320
you do not recognize you need to investigate them.

1091
00:38:14,320 --> 00:38:17,360
This is where security becomes a first-class design concern

1092
00:38:17,360 --> 00:38:18,800
rather than an afterthought.

1093
00:38:18,800 --> 00:38:21,280
You are no longer just asking if a component works.

1094
00:38:21,280 --> 00:38:23,360
You are asking where that component sends data

1095
00:38:23,360 --> 00:38:24,960
and if that flow is authorized.

1096
00:38:24,960 --> 00:38:27,440
The CSP Enforcement Deadline is a forcing function.

1097
00:38:27,440 --> 00:38:30,720
It makes you audit your scripts, discover your dependencies

1098
00:38:30,720 --> 00:38:32,320
and register what is trusted.

1099
00:38:32,320 --> 00:38:34,720
By doing that, you build the governance discipline you need

1100
00:38:34,720 --> 00:38:37,040
for the agent fabric to work safely at scale.

1101
00:38:37,040 --> 00:38:39,360
Governance first, the permission audit.

1102
00:38:39,360 --> 00:38:41,920
You've decided to move forward with the agent fabric.

1103
00:38:41,920 --> 00:38:45,760
You've picked your architecture, SPFX, MCP, or a mix of both.

1104
00:38:45,760 --> 00:38:47,280
You've mapped out the licensing.

1105
00:38:47,280 --> 00:38:48,800
You've hardened your CSP.

1106
00:38:48,800 --> 00:38:51,520
Now comes the part most organizations try to ignore

1107
00:38:51,520 --> 00:38:54,080
because it isn't flashy or technically elegant.

1108
00:38:54,080 --> 00:38:56,000
Before you turn on co-pilot for everyone,

1109
00:38:56,000 --> 00:38:58,640
you have to know what your SharePoint actually looks like.

1110
00:38:58,640 --> 00:39:00,560
Not the clean version you have in your head,

1111
00:39:00,560 --> 00:39:02,560
but the messy version that exists in reality,

1112
00:39:02,560 --> 00:39:03,760
this is the audit phase.

1113
00:39:03,760 --> 00:39:05,040
And it is not optional.

1114
00:39:05,040 --> 00:39:06,720
You start in the SharePoint Admin Center

1115
00:39:06,720 --> 00:39:08,480
with Data Access Governance Reports.

1116
00:39:08,480 --> 00:39:10,720
You aren't looking for tiny individual errors here.

1117
00:39:10,720 --> 00:39:12,400
You're looking for structural patterns.

1118
00:39:12,400 --> 00:39:13,680
When you run that DAG report,

1119
00:39:13,680 --> 00:39:15,920
look closely at the distribution of access.

1120
00:39:15,920 --> 00:39:18,720
You'll see exactly which sites are shared with too many people,

1121
00:39:18,720 --> 00:39:20,160
where inheritance is broken

1122
00:39:20,160 --> 00:39:22,000
and where external sharing is wide open.

1123
00:39:22,000 --> 00:39:25,040
What you're hunting for are sites that are broadly shared for no reason.

1124
00:39:25,040 --> 00:39:28,000
Maybe it's a project site shared with everyone in the organization

1125
00:39:28,000 --> 00:39:30,320
because a consultant needed a file four years ago.

1126
00:39:30,320 --> 00:39:32,400
Maybe it's a finance folder left open to everyone

1127
00:39:32,400 --> 00:39:34,480
because managing groups felt too slow.

1128
00:39:34,480 --> 00:39:37,120
Maybe it's a classified library sitting inside a research site

1129
00:39:37,120 --> 00:39:39,680
with default permissions that let anyone wander in.

1130
00:39:39,680 --> 00:39:42,480
These aren't security breaches in the traditional sense.

1131
00:39:42,480 --> 00:39:43,520
They're permission drift.

1132
00:39:43,520 --> 00:39:46,480
It's a slow accumulation of access that stays invisible

1133
00:39:46,480 --> 00:39:48,080
until something forces you to look at it.

1134
00:39:48,080 --> 00:39:49,920
Co-pilot forces you to look immediately.

1135
00:39:49,920 --> 00:39:51,520
Once you find these overshared sites,

1136
00:39:51,520 --> 00:39:53,760
you have to follow a specific sequence to fix them.

1137
00:39:53,760 --> 00:39:55,920
First, you kill the broad sharing.

1138
00:39:55,920 --> 00:39:57,680
Everyone becomes a specific group

1139
00:39:57,680 --> 00:40:01,600
and anyone with the link becomes people I explicitly approved.

1140
00:40:01,600 --> 00:40:03,200
You aren't changing the content itself.

1141
00:40:03,200 --> 00:40:05,360
You're just fixing the boundary of who can see it.

1142
00:40:05,360 --> 00:40:08,000
Second, you layer in restricted access control

1143
00:40:08,000 --> 00:40:09,520
for your most sensitive sites.

1144
00:40:09,520 --> 00:40:11,200
Think of RAC as a fortress mode,

1145
00:40:11,200 --> 00:40:14,080
where you explicitly state that only specific groups can enter

1146
00:40:14,080 --> 00:40:16,640
and no one else can be added without a major escalation.

1147
00:40:16,640 --> 00:40:18,480
You use this for the high-risk stuff.

1148
00:40:18,480 --> 00:40:21,680
Mergers executive strategy or sensitive financial data

1149
00:40:21,680 --> 00:40:23,600
where you need absolute certainty.

1150
00:40:23,600 --> 00:40:25,600
Third, you use restricted content discovery

1151
00:40:25,600 --> 00:40:27,840
to hide certain sites from co-pilot entirely.

1152
00:40:27,840 --> 00:40:29,280
If a site is already locked down,

1153
00:40:29,280 --> 00:40:30,640
but you want an extra layer of safety,

1154
00:40:30,640 --> 00:40:32,800
you tell co-pilot not to index it at all.

1155
00:40:32,800 --> 00:40:35,440
Users can still find those files through a normal search,

1156
00:40:35,440 --> 00:40:38,240
but co-pilot will never use them as a source for an answer.

1157
00:40:38,240 --> 00:40:39,520
Then comes the labeling.

1158
00:40:39,520 --> 00:40:41,600
This is where you define what your data actually is.

1159
00:40:41,600 --> 00:40:43,360
You deploy sensitivity labels,

1160
00:40:43,360 --> 00:40:45,120
like confidential, internal, or public,

1161
00:40:45,120 --> 00:40:46,480
and you make the mandatory.

1162
00:40:46,480 --> 00:40:48,480
New documents can't be saved without a label,

1163
00:40:48,480 --> 00:40:50,880
and existing files get classified through automation

1164
00:40:50,880 --> 00:40:51,920
or manual review.

1165
00:40:51,920 --> 00:40:54,400
For the highest risk data, you apply encryption.

1166
00:40:54,400 --> 00:40:57,120
If a document is labeled confidential and encrypted,

1167
00:40:57,120 --> 00:40:59,360
only specific users can actually read it.

1168
00:40:59,360 --> 00:41:01,920
Co-pilot can still index the file for search,

1169
00:41:01,920 --> 00:41:03,680
but the actual content stays protected

1170
00:41:03,680 --> 00:41:05,200
behind that encryption layer.

1171
00:41:05,200 --> 00:41:06,800
Your DLP strategy sits on top of this.

1172
00:41:06,800 --> 00:41:09,760
You create policies specifically for co-pilot interactions,

1173
00:41:09,760 --> 00:41:11,680
like a rule that blocks the AI

1174
00:41:11,680 --> 00:41:14,720
if it tries to touch a document containing social security numbers.

1175
00:41:14,720 --> 00:41:17,840
You start an audit mode to watch the patterns without breaking anything.

1176
00:41:17,840 --> 00:41:19,920
And after a few weeks of monitoring the logs,

1177
00:41:19,920 --> 00:41:21,040
you move to active blocking.

1178
00:41:21,040 --> 00:41:22,560
This isn't a one-time project.

1179
00:41:22,560 --> 00:41:24,000
It's a baseline you have to maintain.

1180
00:41:24,000 --> 00:41:25,840
You should be running DAG reports every quarter

1181
00:41:25,840 --> 00:41:28,160
and checking your DLP match rates constantly.

1182
00:41:28,160 --> 00:41:30,720
If you see a spike in violations for a specific team,

1183
00:41:30,720 --> 00:41:32,560
you investigate and tighten the screws.

1184
00:41:32,560 --> 00:41:34,640
The timeline is the most important part here.

1185
00:41:34,640 --> 00:41:36,880
You need this foundation solid before co-pilot goes wide,

1186
00:41:36,880 --> 00:41:38,640
because once the AI is out there,

1187
00:41:38,640 --> 00:41:40,960
trying to retrofit governance is almost impossible.

1188
00:41:40,960 --> 00:41:44,400
The agent fabric, what it actually means.

1189
00:41:44,400 --> 00:41:46,320
Now we need to name what we're actually building,

1190
00:41:46,320 --> 00:41:48,000
because the licensing, the architecture,

1191
00:41:48,000 --> 00:41:51,600
and the permission audits all lead to one place, the agent fabric.

1192
00:41:51,600 --> 00:41:54,240
People use that term a lot and usually it's pretty vague.

1193
00:41:54,240 --> 00:41:56,800
So let's be concrete about what it is, how it works,

1194
00:41:56,800 --> 00:41:58,640
and why your governance foundation matters

1195
00:41:58,640 --> 00:42:00,080
to every single layer of it.

1196
00:42:00,080 --> 00:42:01,840
The agent fabric is the infrastructure

1197
00:42:01,840 --> 00:42:03,920
that lets AI agents work across your business

1198
00:42:03,920 --> 00:42:05,360
while respecting your boundaries.

1199
00:42:05,360 --> 00:42:07,760
It isn't a way for AI to bypass your security.

1200
00:42:07,760 --> 00:42:10,320
It's the system that forces AI to operate inside of it.

1201
00:42:10,320 --> 00:42:11,760
The components are very specific.

1202
00:42:11,760 --> 00:42:12,960
Identity is the floor.

1203
00:42:12,960 --> 00:42:15,520
Entra ID, that's where you verify who the user is.

1204
00:42:15,520 --> 00:42:17,040
Authorization is the next layer.

1205
00:42:17,040 --> 00:42:18,720
This isn't just checking a group membership.

1206
00:42:18,720 --> 00:42:20,160
It's checking SharePoint permissions,

1207
00:42:20,160 --> 00:42:22,960
sensitivity labels, and DLP policies.

1208
00:42:22,960 --> 00:42:26,320
Every time an agent touches data, the system checks if it's allowed to.

1209
00:42:26,320 --> 00:42:27,200
Ordered is the memory.

1210
00:42:27,200 --> 00:42:29,440
Microsoft Perview logs every tool call

1211
00:42:29,440 --> 00:42:31,120
and every action the agent takes.

1212
00:42:31,120 --> 00:42:32,720
This isn't for compliance theatre.

1213
00:42:32,720 --> 00:42:36,400
It's so you actually understand what the system did and why it did it.

1214
00:42:36,400 --> 00:42:37,920
Orchestration is the engine.

1215
00:42:37,920 --> 00:42:40,880
This is co-pilot, power automate, or co-pilot studio.

1216
00:42:40,880 --> 00:42:43,360
These platforms are the interface between what the human needs

1217
00:42:43,360 --> 00:42:45,360
and what the tool actually executes.

1218
00:42:45,360 --> 00:42:47,120
But here's the reality most people miss.

1219
00:42:47,120 --> 00:42:48,960
An agent doesn't think of itself as an agent.

1220
00:42:48,960 --> 00:42:50,720
It isn't a separate autonomous entity.

1221
00:42:50,720 --> 00:42:53,120
It's just a co-pilot instance with access to a toolbox.

1222
00:42:53,120 --> 00:42:56,000
Those tools might be SPFX components in your tenant,

1223
00:42:56,000 --> 00:42:58,720
MCP server sitting outside, or power automate flows.

1224
00:42:58,720 --> 00:43:00,880
But to the agent, they're just functions it can call.

1225
00:43:00,880 --> 00:43:01,760
You ask a question.

1226
00:43:01,760 --> 00:43:02,880
The agent reasons through it.

1227
00:43:02,880 --> 00:43:05,520
It decides it needs a specific tool to answer you.

1228
00:43:05,520 --> 00:43:06,560
It calls that tool.

1229
00:43:06,560 --> 00:43:08,960
The tool sends back data or an interactive card

1230
00:43:08,960 --> 00:43:10,000
and the agent shows it to you.

1231
00:43:10,000 --> 00:43:11,920
You click a button, the result flows back,

1232
00:43:11,920 --> 00:43:13,680
and the agent finishes its thought.

1233
00:43:13,680 --> 00:43:15,680
That cycle is the agent fabric in action.

1234
00:43:15,680 --> 00:43:19,200
The governance model is the only thing that makes this safe for a real company.

1235
00:43:19,200 --> 00:43:21,760
Every action is logged, every call is audited,

1236
00:43:21,760 --> 00:43:23,840
and every piece of data is permission trimmed.

1237
00:43:23,840 --> 00:43:26,240
If the agent tries to grab a file you aren't allowed to see,

1238
00:43:26,240 --> 00:43:27,920
the permission check fails instantly.

1239
00:43:27,920 --> 00:43:29,360
The tool returns nothing,

1240
00:43:29,360 --> 00:43:31,280
and the agent can't show you the secret.

1241
00:43:31,280 --> 00:43:33,040
And none of this happens without you.

1242
00:43:33,040 --> 00:43:36,000
If an agent is supposed to update a list or modify a document,

1243
00:43:36,000 --> 00:43:37,120
there are checkpoints.

1244
00:43:37,120 --> 00:43:38,320
You build in approval steps

1245
00:43:38,320 --> 00:43:41,200
so the agent can't act unilaterally on your behalf.

1246
00:43:41,200 --> 00:43:42,240
Why does this matter?

1247
00:43:42,240 --> 00:43:44,960
Because this is the shift from chat to orchestration.

1248
00:43:44,960 --> 00:43:46,240
The old model was simple.

1249
00:43:46,240 --> 00:43:48,320
You type a question, get some text back,

1250
00:43:48,320 --> 00:43:50,320
and then you go do the work yourself.

1251
00:43:50,320 --> 00:43:51,760
The interface was conversational,

1252
00:43:51,760 --> 00:43:53,760
but the actual execution was manual.

1253
00:43:53,760 --> 00:43:55,840
You had to leave the chat to get anything done.

1254
00:43:55,840 --> 00:43:57,280
The agent fabric changes that.

1255
00:43:57,280 --> 00:43:58,640
You're still talking to an agent,

1256
00:43:58,640 --> 00:44:00,880
but now the agent can actually move the gears.

1257
00:44:00,880 --> 00:44:03,120
It surfaces interactive components right in the chat

1258
00:44:03,120 --> 00:44:05,520
so you can finish a task without switching tabs.

1259
00:44:05,520 --> 00:44:07,520
The distance between "I need to do this"

1260
00:44:07,520 --> 00:44:08,640
and "this is done"

1261
00:44:08,640 --> 00:44:09,920
drops from hours to seconds.

1262
00:44:09,920 --> 00:44:12,160
The business outcome is obvious.

1263
00:44:12,160 --> 00:44:13,760
Workflows that used to take half a day

1264
00:44:13,760 --> 00:44:14,720
now take five minutes.

1265
00:44:14,720 --> 00:44:16,640
Data lookups that require digging through folders

1266
00:44:16,640 --> 00:44:17,680
now just appear.

1267
00:44:17,680 --> 00:44:19,520
Status updates that used to mean opening

1268
00:44:19,520 --> 00:44:21,840
three different systems now happen in one click.

1269
00:44:21,840 --> 00:44:22,800
But there is a catch.

1270
00:44:22,800 --> 00:44:24,000
If your governance is weak,

1271
00:44:24,000 --> 00:44:25,520
the agent fabric won't fix it.

1272
00:44:25,520 --> 00:44:26,640
It will amplify it.

1273
00:44:26,640 --> 00:44:29,200
Bad permissions become visible the second you turn this on.

1274
00:44:29,200 --> 00:44:31,600
Poor data classification becomes a total blocker.

1275
00:44:31,600 --> 00:44:34,240
Missing audits become a massive liability.

1276
00:44:34,240 --> 00:44:35,840
That's why governance has to come first.

1277
00:44:35,840 --> 00:44:37,600
The agent fabric is a powerful engine,

1278
00:44:37,600 --> 00:44:40,240
but it only works if the tracks are laid down correctly.

1279
00:44:40,240 --> 00:44:42,160
If this shift from chat to orchestration

1280
00:44:42,160 --> 00:44:43,760
changed how you think about AI.

1281
00:44:43,760 --> 00:44:45,600
Follow me, Mucopeter's on LinkedIn,

1282
00:44:45,600 --> 00:44:47,040
and if you want more of this,

1283
00:44:47,040 --> 00:44:47,840
leave a review.

1284
00:44:47,840 --> 00:44:49,760
It helps more people find the show.

1285
00:44:49,760 --> 00:44:51,040
Share this with your team,

1286
00:44:51,040 --> 00:44:53,440
especially if you're dealing with these permission issues right now.

1287
00:44:53,440 --> 00:44:56,080
Why governance must precede architecture?

1288
00:44:56,080 --> 00:44:58,720
The entire framework breaks if you get the sequence wrong.

1289
00:44:58,720 --> 00:45:01,040
Most organizations make this mistake when they start.

1290
00:45:01,040 --> 00:45:02,000
It looks like this.

1291
00:45:02,000 --> 00:45:04,320
You get budget approval for co-pilot licenses.

1292
00:45:04,320 --> 00:45:06,320
You're excited about the productivity gains.

1293
00:45:06,320 --> 00:45:07,200
You buy the seats.

1294
00:45:07,200 --> 00:45:08,160
You enable the feature.

1295
00:45:08,160 --> 00:45:09,440
You train a few teams.

1296
00:45:09,440 --> 00:45:11,520
And then you wait for the ROI to show up,

1297
00:45:11,520 --> 00:45:12,320
but it doesn't.

1298
00:45:12,320 --> 00:45:14,800
Teams use co-pilot for a few weeks and the novelty wears off.

1299
00:45:14,800 --> 00:45:15,680
Adoption plateaus.

1300
00:45:15,680 --> 00:45:18,480
You're paying for licenses that people aren't actually using.

1301
00:45:18,480 --> 00:45:20,320
The ROI story just evaporates.

1302
00:45:20,320 --> 00:45:21,600
The reason this happens

1303
00:45:21,600 --> 00:45:23,280
isn't because co-pilot doesn't work.

1304
00:45:23,280 --> 00:45:24,960
It's because you skipped the prerequisite.

1305
00:45:24,960 --> 00:45:26,560
You tried to build the architecture

1306
00:45:26,560 --> 00:45:28,560
before the governance foundation was in place.

1307
00:45:28,560 --> 00:45:29,840
And without that foundation,

1308
00:45:29,840 --> 00:45:32,640
the architecture becomes a liability instead of an asset.

1309
00:45:32,640 --> 00:45:34,160
When I say governance foundation,

1310
00:45:34,160 --> 00:45:36,160
I'm not talking about a compliance checkbox.

1311
00:45:36,160 --> 00:45:38,800
So I'm not talking about a policy document that sits on a shelf.

1312
00:45:38,800 --> 00:45:40,640
So I'm talking about an operational reality.

1313
00:45:40,640 --> 00:45:42,400
It means your permissions are actually clear.

1314
00:45:42,400 --> 00:45:44,880
You can look at a site and know exactly who should have access

1315
00:45:44,880 --> 00:45:45,680
and who shouldn't.

1316
00:45:45,680 --> 00:45:47,760
It means your sensitive data is classified

1317
00:45:47,760 --> 00:45:49,360
so you know what needs protection.

1318
00:45:49,360 --> 00:45:52,800
It means you have DLP policies that actually prevent violations

1319
00:45:52,800 --> 00:45:54,480
instead of just logging them after the fact.

1320
00:45:54,480 --> 00:45:56,720
That means your audit trail is complete and trustworthy

1321
00:45:56,720 --> 00:45:57,920
when you have that foundation.

1322
00:45:57,920 --> 00:46:00,320
You can build the agent fabric on top of it with confidence.

1323
00:46:00,320 --> 00:46:02,240
When you don't, you're building on sand.

1324
00:46:02,240 --> 00:46:04,000
The sequence is non-negotiable.

1325
00:46:04,000 --> 00:46:05,760
Governance first, then architecture,

1326
00:46:05,760 --> 00:46:07,680
then implementation, skip governance,

1327
00:46:07,680 --> 00:46:09,360
and everything else becomes fragile.

1328
00:46:09,360 --> 00:46:12,000
There is a structural problem that makes this harder than it sounds.

1329
00:46:12,000 --> 00:46:13,760
Most organizations built their sharepoint

1330
00:46:13,760 --> 00:46:16,080
around a permission model that made sense 10 years ago.

1331
00:46:16,080 --> 00:46:16,720
It's flat.

1332
00:46:16,720 --> 00:46:18,080
The default is broad access.

1333
00:46:18,080 --> 00:46:20,880
Everyone in the organization gets access to most sites.

1334
00:46:20,880 --> 00:46:23,200
That model works fine when people are navigating manually

1335
00:46:23,200 --> 00:46:24,480
and searching for content.

1336
00:46:24,480 --> 00:46:26,960
But it breaks immediately when you introduce an AI system

1337
00:46:26,960 --> 00:46:29,280
that can surface any content to any user

1338
00:46:29,280 --> 00:46:30,240
with a single prompt.

1339
00:46:30,240 --> 00:46:33,360
At the same time, compliance requirements have gotten more sophisticated.

1340
00:46:33,360 --> 00:46:36,560
You have regulations that say certain data can only be accessed by certain people.

1341
00:46:36,560 --> 00:46:40,240
You have internal policies that say executive strategy documents

1342
00:46:40,240 --> 00:46:42,000
shouldn't be visible to operational staff.

1343
00:46:42,000 --> 00:46:43,520
So you have a structural mismatch.

1344
00:46:43,520 --> 00:46:44,880
Your permission model is flat.

1345
00:46:44,880 --> 00:46:46,720
Your compliance requirements are hierarchical.

1346
00:46:46,720 --> 00:46:48,880
For years, people could work around that gap

1347
00:46:48,880 --> 00:46:50,560
because navigation was manual.

1348
00:46:50,560 --> 00:46:53,440
You'd search for something, find some documents, and move on.

1349
00:46:53,440 --> 00:46:55,600
If you stumbled onto something you shouldn't see,

1350
00:46:55,600 --> 00:46:57,040
it wasn't a systemic problem.

1351
00:46:57,040 --> 00:46:59,200
Copilot makes that gap visible immediately.

1352
00:46:59,200 --> 00:47:01,440
Suddenly, data that was technically accessible

1353
00:47:01,440 --> 00:47:03,760
but practically hidden is one prompt away.

1354
00:47:03,760 --> 00:47:05,360
The friction of navigation and search,

1355
00:47:05,360 --> 00:47:07,360
the thing that was actually protecting compliance,

1356
00:47:07,360 --> 00:47:08,320
disappears.

1357
00:47:08,320 --> 00:47:09,760
The fix requires months of work.

1358
00:47:09,760 --> 00:47:12,320
You implement restricted access control on sensitive sites,

1359
00:47:12,320 --> 00:47:14,160
so access is explicit and limited.

1360
00:47:14,160 --> 00:47:16,080
You apply sensitivity labels to data

1361
00:47:16,080 --> 00:47:17,680
so you know what needs protection.

1362
00:47:17,680 --> 00:47:19,120
You use restricted content discovery

1363
00:47:19,120 --> 00:47:22,400
so certain categories of data aren't indexed by copilot at all.

1364
00:47:22,400 --> 00:47:23,760
This work can't be rushed.

1365
00:47:23,760 --> 00:47:26,480
It requires IT to understand the permission structure.

1366
00:47:26,480 --> 00:47:29,920
It requires security to understand the compliance requirements.

1367
00:47:29,920 --> 00:47:32,720
It requires business to weigh in on which data is sensitive.

1368
00:47:32,720 --> 00:47:34,000
It's not a technical project.

1369
00:47:34,000 --> 00:47:35,520
It's an organizational alignment project.

1370
00:47:35,520 --> 00:47:36,640
The cost is real.

1371
00:47:36,640 --> 00:47:37,280
It's budget.

1372
00:47:37,280 --> 00:47:37,760
It's time.

1373
00:47:37,760 --> 00:47:38,960
It's cross-functional meetings.

1374
00:47:38,960 --> 00:47:40,400
It's decisions made and remade.

1375
00:47:40,400 --> 00:47:41,520
And here's the hard part.

1376
00:47:41,520 --> 00:47:43,440
The July 1st licensing deadline

1377
00:47:43,440 --> 00:47:45,760
doesn't care whether your governance foundation is ready.

1378
00:47:45,760 --> 00:47:47,200
The deadline is coming regardless.

1379
00:47:47,200 --> 00:47:48,080
So you face a choice.

1380
00:47:48,080 --> 00:47:49,760
You can invest in governance now,

1381
00:47:49,760 --> 00:47:51,840
which means delaying your copilot rollout

1382
00:47:51,840 --> 00:47:52,640
by several months

1383
00:47:52,640 --> 00:47:54,640
but setting yourself up for real value.

1384
00:47:54,640 --> 00:47:57,680
Or you can ignore governance and rollout copilot broadly today

1385
00:47:57,680 --> 00:47:59,600
knowing that you'll either get minimal adoption

1386
00:47:59,600 --> 00:48:00,400
or worse.

1387
00:48:00,400 --> 00:48:01,840
You'll discover compliance problems

1388
00:48:01,840 --> 00:48:03,520
that force expensive remediation.

1389
00:48:03,520 --> 00:48:04,800
That's the decision point.

1390
00:48:04,800 --> 00:48:07,840
And it has to be made consciously, not accidentally.

1391
00:48:07,840 --> 00:48:09,600
The developer career inflection.

1392
00:48:09,600 --> 00:48:11,600
For a decade, the job title was clear.

1393
00:48:11,600 --> 00:48:13,360
You were a SharePoint developer.

1394
00:48:13,360 --> 00:48:14,640
Or maybe a team's developer.

1395
00:48:14,640 --> 00:48:16,480
Your work was about building interfaces.

1396
00:48:16,480 --> 00:48:17,600
You took business requirements

1397
00:48:17,600 --> 00:48:18,960
for what the page should look like.

1398
00:48:18,960 --> 00:48:20,320
The flow the user should follow

1399
00:48:20,320 --> 00:48:21,840
and the data that should display.

1400
00:48:21,840 --> 00:48:23,040
You build React components.

1401
00:48:23,040 --> 00:48:24,160
You called APIs.

1402
00:48:24,160 --> 00:48:26,000
You deployed to the app catalog.

1403
00:48:26,000 --> 00:48:28,640
Your success was measured by whether the interface worked

1404
00:48:28,640 --> 00:48:30,000
and whether people used it.

1405
00:48:30,000 --> 00:48:31,520
That role is about to become something

1406
00:48:31,520 --> 00:48:32,720
fundamentally different.

1407
00:48:32,720 --> 00:48:34,400
Not because the technology changed,

1408
00:48:34,400 --> 00:48:36,320
but because what the organization needs

1409
00:48:36,320 --> 00:48:37,680
from developers changed.

1410
00:48:37,680 --> 00:48:40,000
Building an SPFX component for a SharePoint page

1411
00:48:40,000 --> 00:48:41,120
is about UX.

1412
00:48:41,120 --> 00:48:42,880
How does the user navigate this interface?

1413
00:48:42,880 --> 00:48:44,640
How is the data organized visually?

1414
00:48:44,640 --> 00:48:46,560
Those are legitimate technical questions

1415
00:48:46,560 --> 00:48:47,760
and answering them well matters.

1416
00:48:47,760 --> 00:48:49,200
But they're bounded questions.

1417
00:48:49,200 --> 00:48:50,960
The component lives in a specific place.

1418
00:48:50,960 --> 00:48:52,320
It serves a specific purpose.

1419
00:48:52,320 --> 00:48:55,360
Building an SPFX component for the agent fabric

1420
00:48:55,360 --> 00:48:57,200
is about something else entirely.

1421
00:48:57,200 --> 00:48:59,760
You're not designing an interface for human navigation.

1422
00:48:59,760 --> 00:49:01,280
You're designing an orchestration point

1423
00:49:01,280 --> 00:49:02,720
where an agent can call your code

1424
00:49:02,720 --> 00:49:04,160
and execute business logic.

1425
00:49:04,160 --> 00:49:06,160
That changes every decision you make.

1426
00:49:06,160 --> 00:49:07,520
Consider a simple example.

1427
00:49:07,520 --> 00:49:10,560
You built a web part that displays a list of pending approvals.

1428
00:49:10,560 --> 00:49:12,960
The user sees a nice grid with filters and sorting.

1429
00:49:12,960 --> 00:49:14,640
They click "Approve" or "Reject".

1430
00:49:14,640 --> 00:49:15,840
The action gets recorded.

1431
00:49:15,840 --> 00:49:18,560
That's a well-designed SPFX component for a page.

1432
00:49:18,560 --> 00:49:20,640
Now expose that same component in co-pilot.

1433
00:49:20,640 --> 00:49:21,920
The agent is calling it.

1434
00:49:21,920 --> 00:49:23,600
The user asks co-pilot a question.

1435
00:49:23,600 --> 00:49:25,520
The agent reason that showing pending approvals

1436
00:49:25,520 --> 00:49:26,960
would help answer that question.

1437
00:49:26,960 --> 00:49:30,000
Now your component is rendering inside a conversational interface.

1438
00:49:30,000 --> 00:49:32,320
The user can still click to approve or reject.

1439
00:49:32,320 --> 00:49:33,600
But the context is different.

1440
00:49:33,600 --> 00:49:35,920
The agent is going to interpret the user's decision.

1441
00:49:35,920 --> 00:49:37,920
The agent is going to decide what to show next.

1442
00:49:37,920 --> 00:49:40,640
Your component is now part of a larger orchestration flow.

1443
00:49:40,640 --> 00:49:42,320
That requires different thinking.

1444
00:49:42,320 --> 00:49:45,440
You need to understand what data the agent might pass to your component.

1445
00:49:45,440 --> 00:49:47,920
You need to handle edge cases where the agent's reasoning

1446
00:49:47,920 --> 00:49:50,720
led to your component being surfaced in an unexpected context.

1447
00:49:50,720 --> 00:49:53,680
You need to think about how your component reports back to the agent.

1448
00:49:53,680 --> 00:49:55,840
Not just the user clicked "Approve",

1449
00:49:55,840 --> 00:49:59,280
but what does that approval mean in the context of the larger workflow?

1450
00:49:59,280 --> 00:50:01,920
More importantly, you need to understand governance.

1451
00:50:01,920 --> 00:50:05,200
When your component executes, whose permissions is it running under?

1452
00:50:05,200 --> 00:50:06,720
What data is it allowed to access?

1453
00:50:06,720 --> 00:50:08,240
If the component tries to fetch data,

1454
00:50:08,240 --> 00:50:09,840
the user shouldn't see what happens.

1455
00:50:09,840 --> 00:50:11,120
That's not a UX question.

1456
00:50:11,120 --> 00:50:12,480
That's an authorization question.

1457
00:50:12,480 --> 00:50:13,920
And it's now your responsibility.

1458
00:50:13,920 --> 00:50:16,320
Most SPFX developers today understand React.

1459
00:50:16,320 --> 00:50:18,480
They understand the SharePoint Rest API.

1460
00:50:18,480 --> 00:50:20,560
Fewer understand identity propagation.

1461
00:50:20,560 --> 00:50:24,560
How to verify that the user running the component is actually the user they claim to be.

1462
00:50:24,560 --> 00:50:26,640
Fewer understand DLP policies

1463
00:50:26,640 --> 00:50:28,960
and how to design a component that respects them.

1464
00:50:28,960 --> 00:50:31,760
Fewer understand audit logging and how to instrument their code

1465
00:50:31,760 --> 00:50:33,600
so governance teams can see what it did.

1466
00:50:33,600 --> 00:50:35,120
Those aren't optional skills anymore.

1467
00:50:35,120 --> 00:50:37,600
They're table stakes for building in the agent fabric.

1468
00:50:37,600 --> 00:50:38,640
That's the skill gap.

1469
00:50:38,640 --> 00:50:39,600
And it's a real one.

1470
00:50:39,600 --> 00:50:41,040
But it's also an opportunity.

1471
00:50:41,040 --> 00:50:44,000
Because organizations desperately need developers who can bridge that gap.

1472
00:50:44,000 --> 00:50:46,640
They need people who understand both the technical side.

1473
00:50:46,640 --> 00:50:49,040
How to build React components and the governance side.

1474
00:50:49,040 --> 00:50:51,920
How to make sure those components operate safely within compliance boundaries.

1475
00:50:51,920 --> 00:50:53,440
The market signal is clear.

1476
00:50:53,440 --> 00:50:58,160
Demand for co-pilot app developers or agent architects is growing faster than the supply of people

1477
00:50:58,160 --> 00:50:59,840
who actually have those skills.

1478
00:50:59,840 --> 00:51:01,520
This is a career inflection point.

1479
00:51:01,520 --> 00:51:03,200
You can train yourself now

1480
00:51:03,200 --> 00:51:07,760
and you'll be significantly more valuable to your organization in 18 months than you are today.

1481
00:51:07,760 --> 00:51:10,720
Or you can stay focused on page level SPFX components

1482
00:51:10,720 --> 00:51:12,480
and watch the market move past you.

1483
00:51:12,480 --> 00:51:14,160
The training path is straightforward.

1484
00:51:14,160 --> 00:51:16,320
Start with SPFX 1.24.

1485
00:51:16,320 --> 00:51:18,800
Understand how components render and co-pilot.

1486
00:51:18,800 --> 00:51:21,920
Move to MCP and understand when to use it versus SPFX.

1487
00:51:21,920 --> 00:51:23,120
Study governance patterns.

1488
00:51:23,120 --> 00:51:25,600
Learn how authorization and audit actually work.

1489
00:51:25,600 --> 00:51:29,840
Build a component in a test environment that respects permissions and logs its actions.

1490
00:51:29,840 --> 00:51:32,480
That foundation prepares you for the work that's coming.

1491
00:51:32,480 --> 00:51:34,720
Because the agent fabric doesn't need page developers.

1492
00:51:34,720 --> 00:51:36,480
It needs orchestration developers.

1493
00:51:36,480 --> 00:51:37,840
The licensing paradox.

1494
00:51:37,840 --> 00:51:40,720
Every CFO has the same question on their spreadsheet right now.

1495
00:51:40,720 --> 00:51:44,080
Is $30 per user every single month actually worth it?

1496
00:51:44,080 --> 00:51:47,280
They want to know what the organization gets for that investment.

1497
00:51:47,280 --> 00:51:49,040
But asking that is asking the wrong question.

1498
00:51:49,040 --> 00:51:51,200
The real question is both economic and strategic.

1499
00:51:51,200 --> 00:51:52,560
What happens if you don't pay it?

1500
00:51:52,560 --> 00:51:55,840
Let's look at the math for a thousand person organization.

1501
00:51:55,840 --> 00:51:59,040
If you move 30% of your stuff onto co-pilot licenses,

1502
00:51:59,040 --> 00:52:00,800
you are looking at 300 people.

1503
00:52:00,800 --> 00:52:04,000
At $30 a month that is $9,000 monthly

1504
00:52:04,000 --> 00:52:05,840
or $108,000 every year.

1505
00:52:05,840 --> 00:52:08,320
For a mid-market company that is a significant line item

1506
00:52:08,320 --> 00:52:10,720
that requires real justification and budget approval.

1507
00:52:10,720 --> 00:52:12,880
But this is where the analysis usually stops.

1508
00:52:12,880 --> 00:52:15,760
Finance asks if the return justifies the spend.

1509
00:52:15,760 --> 00:52:19,200
Without a clear way to measure it, the answer is usually we don't know.

1510
00:52:19,200 --> 00:52:21,280
So the license gets treated like a cost center.

1511
00:52:21,280 --> 00:52:23,680
And in every business, cost centers get minimized.

1512
00:52:23,680 --> 00:52:25,680
The deeper math changes the entire conversation.

1513
00:52:25,680 --> 00:52:27,920
If those 300 people are the ones who make decisions

1514
00:52:27,920 --> 00:52:29,200
and move workflows forward,

1515
00:52:29,200 --> 00:52:32,000
their time has a multiplier effect on the whole company.

1516
00:52:32,000 --> 00:52:35,920
The ROI calculation isn't about how much faster one person works.

1517
00:52:35,920 --> 00:52:37,680
It's about how much value you unlock

1518
00:52:37,680 --> 00:52:40,960
when a decision maker cuts their cycle time by 50%.

1519
00:52:40,960 --> 00:52:44,560
Think about an operations manager who currently spends four hours every week

1520
00:52:44,560 --> 00:52:46,560
on status updates and data lookups.

1521
00:52:46,560 --> 00:52:48,960
Through the agent fabric, that work drops to two hours.

1522
00:52:48,960 --> 00:52:51,440
That is two hours of brain power freed up every week,

1523
00:52:51,440 --> 00:52:54,720
allowing that person to focus on strategy instead of tactical overhead.

1524
00:52:54,720 --> 00:52:57,360
Over a year, you have recovered 100 hours of capacity.

1525
00:52:57,360 --> 00:52:59,680
If that role costs the company $100 per hour,

1526
00:52:59,680 --> 00:53:02,800
you just save $10,000 in productivity for a single person.

1527
00:53:02,800 --> 00:53:04,480
When 30% of your staff has a license

1528
00:53:04,480 --> 00:53:08,080
and the average recovered productivity is between 5,000 and 15,000 per person,

1529
00:53:08,080 --> 00:53:10,880
your return on investment is 10 to 30 times the cost.

1530
00:53:10,880 --> 00:53:12,800
Suddenly, the license looks incredibly cheap.

1531
00:53:12,800 --> 00:53:13,920
But here is the problem.

1532
00:53:13,920 --> 00:53:16,960
That ROI only happens if the licenses go to the right people.

1533
00:53:16,960 --> 00:53:19,040
If you hand them out randomly or give them to people

1534
00:53:19,040 --> 00:53:21,440
whose roles don't have that decision making power,

1535
00:53:21,440 --> 00:53:22,640
the ROI collapses.

1536
00:53:22,640 --> 00:53:24,960
You are paying for tools that aren't generating value.

1537
00:53:24,960 --> 00:53:26,160
That is the paradox.

1538
00:53:26,160 --> 00:53:28,640
The strategic decision isn't whether you license everyone.

1539
00:53:28,640 --> 00:53:30,320
You can't. The budget won't allow it.

1540
00:53:30,320 --> 00:53:32,080
And most people don't actually need it yet.

1541
00:53:32,080 --> 00:53:34,400
The real decision is figuring out who needs it most

1542
00:53:34,400 --> 00:53:36,320
and what value you unlock when they have it.

1543
00:53:36,320 --> 00:53:37,600
You have to be specific.

1544
00:53:37,600 --> 00:53:40,320
Start with roles that make high-frequency decisions.

1545
00:53:40,320 --> 00:53:42,160
Operations teams managing resources,

1546
00:53:42,160 --> 00:53:44,560
project managers coordinating across departments,

1547
00:53:44,560 --> 00:53:46,880
customer service leaders, handling escalations.

1548
00:53:46,880 --> 00:53:48,560
Finance teams managing approvals.

1549
00:53:48,560 --> 00:53:50,800
These are the spots where AI-driven decisions create

1550
00:53:50,800 --> 00:53:52,480
compounding value for the business.

1551
00:53:52,480 --> 00:53:54,880
License those roles first and then measure what happens.

1552
00:53:54,880 --> 00:53:57,440
Did the time it takes to make a decision actually go down?

1553
00:53:57,440 --> 00:53:59,280
Did the quality of those decisions improve?

1554
00:53:59,280 --> 00:54:01,040
Did you see fewer compliance violations?

1555
00:54:01,040 --> 00:54:03,120
You need to know if people are actually using the tools

1556
00:54:03,120 --> 00:54:04,880
or just treating them like a new toy.

1557
00:54:04,880 --> 00:54:07,920
Once you have the data, you expand to the next tier of roles.

1558
00:54:07,920 --> 00:54:10,000
You show the organization what became possible

1559
00:54:10,000 --> 00:54:12,000
and look for where else that patent fits.

1560
00:54:12,000 --> 00:54:13,920
You grow the license based methodically,

1561
00:54:13,920 --> 00:54:16,800
based on real measurement rather than just hoping for the best.

1562
00:54:16,800 --> 00:54:18,640
Timing makes this even more urgent.

1563
00:54:18,640 --> 00:54:20,800
On July 1, Microsoft is changing the rules.

1564
00:54:20,800 --> 00:54:23,360
Copilot features inside Office Apps will be restricted

1565
00:54:23,360 --> 00:54:25,840
to paid licenses and prices are going up.

1566
00:54:25,840 --> 00:54:28,240
If you wait, you aren't just delaying the benefits.

1567
00:54:28,240 --> 00:54:31,120
You are going to pay more per seat when you finally move forward.

1568
00:54:31,120 --> 00:54:33,440
The cost of waiting is compounding every month.

1569
00:54:33,440 --> 00:54:34,960
The work of building your foundation

1570
00:54:34,960 --> 00:54:38,320
and identifying the right roles needs to happen in the next few months.

1571
00:54:38,320 --> 00:54:39,120
Not next year.

1572
00:54:39,120 --> 00:54:40,160
That is the paradox.

1573
00:54:40,160 --> 00:54:41,600
The license isn't cheap.

1574
00:54:41,600 --> 00:54:43,760
But the cost of doing nothing is much worse.

1575
00:54:43,760 --> 00:54:45,120
The measurement problem.

1576
00:54:45,120 --> 00:54:46,800
How do you know it's working?

1577
00:54:46,800 --> 00:54:48,000
You have made the investment,

1578
00:54:48,000 --> 00:54:50,320
you built the architecture and deployed the components.

1579
00:54:50,320 --> 00:54:51,840
The agent fabric is finally running.

1580
00:54:51,840 --> 00:54:53,520
Now comes the question nobody wants to ask

1581
00:54:53,520 --> 00:54:54,880
because the answer is difficult.

1582
00:54:54,880 --> 00:54:56,320
Is this actually working?

1583
00:54:56,320 --> 00:54:58,720
Most people reach for the metrics they already know.

1584
00:54:58,720 --> 00:55:01,120
They look at engagement rates, daily active users,

1585
00:55:01,120 --> 00:55:02,800
or how long a session lasts.

1586
00:55:02,800 --> 00:55:04,720
These are the numbers that work for social media

1587
00:55:04,720 --> 00:55:05,600
or consumer apps.

1588
00:55:05,600 --> 00:55:07,200
They tell you if people are showing up.

1589
00:55:07,200 --> 00:55:09,920
But they tell you nothing about whether the agent fabric

1590
00:55:09,920 --> 00:55:11,200
is actually delivering.

1591
00:55:11,200 --> 00:55:13,600
The agent fabric isn't there to entertain your employees.

1592
00:55:13,600 --> 00:55:15,280
It is there to move work forward.

1593
00:55:15,280 --> 00:55:18,720
The metric that matters isn't how long someone stayed inside co-pilot.

1594
00:55:18,720 --> 00:55:21,760
It's how much faster they finished the task they were trying to do.

1595
00:55:21,760 --> 00:55:24,560
A traditional productivity metrics miss the point entirely.

1596
00:55:24,560 --> 00:55:27,200
You can have high engagement where people spend hours in co-pilot

1597
00:55:27,200 --> 00:55:28,320
and still be wasting time.

1598
00:55:28,320 --> 00:55:30,880
The interface might feel smooth and the chat might feel natural.

1599
00:55:30,880 --> 00:55:33,600
But if nothing gets done faster, it is just elegant friction.

1600
00:55:33,600 --> 00:55:34,400
It isn't progress.

1601
00:55:34,400 --> 00:55:37,600
The measurements that actually matter are operational.

1602
00:55:37,600 --> 00:55:39,280
Take time to decision.

1603
00:55:39,840 --> 00:55:43,440
How long does it take from the moment a request arrives until it is approved?

1604
00:55:43,440 --> 00:55:45,840
In the old model, that might take two hours.

1605
00:55:45,840 --> 00:55:48,160
You get an email, you navigate to a system,

1606
00:55:48,160 --> 00:55:50,400
you find the request, you review it,

1607
00:55:50,400 --> 00:55:51,600
and then you click approve.

1608
00:55:51,600 --> 00:55:55,200
The time is measured in hours because navigation and context switching

1609
00:55:55,200 --> 00:55:56,720
are built into the process.

1610
00:55:56,720 --> 00:55:59,600
In the agent fabric, you just ask co-pilot for pending approvals.

1611
00:55:59,600 --> 00:56:01,040
The component appears right there.

1612
00:56:01,040 --> 00:56:02,720
You click approve and you're done.

1613
00:56:02,720 --> 00:56:05,120
The time to decision is now measured in seconds.

1614
00:56:05,120 --> 00:56:07,680
That compressed timeline adds up across the whole company.

1615
00:56:07,680 --> 00:56:09,600
If 50 approvals happen every day,

1616
00:56:09,600 --> 00:56:11,920
and each one saves 90 minutes of clicking around,

1617
00:56:11,920 --> 00:56:15,040
you just freed up 75 hours of capacity in a single day.

1618
00:56:15,040 --> 00:56:17,040
Over a year, that is 1,500 hours.

1619
00:56:17,040 --> 00:56:18,720
That is how value becomes concrete.

1620
00:56:18,720 --> 00:56:20,960
You also need to look at the task completion rate.

1621
00:56:20,960 --> 00:56:23,280
How many tasks start in the agent fabric

1622
00:56:23,280 --> 00:56:25,760
and actually finish without the user leaving the screen?

1623
00:56:25,760 --> 00:56:28,800
In the old way of working, a task involves three different systems.

1624
00:56:28,800 --> 00:56:31,280
You check a status here, update a list there,

1625
00:56:31,280 --> 00:56:33,040
and send a notification somewhere else.

1626
00:56:33,040 --> 00:56:36,640
Users often quit halfway through because the friction is too high.

1627
00:56:36,640 --> 00:56:39,760
In the agent fabric, the component handles all those systems at once.

1628
00:56:39,760 --> 00:56:41,840
The task finishes right in front of the user

1629
00:56:41,840 --> 00:56:43,600
and your completion rates go up.

1630
00:56:43,600 --> 00:56:46,720
Error reduction is another huge factor that people overlook.

1631
00:56:46,720 --> 00:56:49,680
When users have to jump between systems, they make mistakes.

1632
00:56:49,680 --> 00:56:52,080
They update the wrong line because they lost their place

1633
00:56:52,080 --> 00:56:53,600
or they approve something they shouldn't

1634
00:56:53,600 --> 00:56:55,520
because they didn't have the full picture.

1635
00:56:55,520 --> 00:56:58,000
The agent fabric solves this by showing exactly

1636
00:56:58,000 --> 00:56:59,680
what is needed to make the right call.

1637
00:56:59,680 --> 00:57:01,920
It flags risks and highlights missing info.

1638
00:57:01,920 --> 00:57:05,280
When errors go down, your operational and compliance value goes up,

1639
00:57:05,280 --> 00:57:07,040
then you have the governance metrics.

1640
00:57:07,040 --> 00:57:08,400
Are all the actions being logged?

1641
00:57:08,400 --> 00:57:09,920
Can you trace exactly who did what?

1642
00:57:09,920 --> 00:57:11,600
Are the permissions being respected?

1643
00:57:11,600 --> 00:57:13,520
If someone tries to see data they shouldn't,

1644
00:57:13,520 --> 00:57:15,200
does the system actually stop them?

1645
00:57:15,200 --> 00:57:16,720
You need to know if there are audit gaps

1646
00:57:16,720 --> 00:57:19,040
where actions are happening outside the lines.

1647
00:57:19,040 --> 00:57:21,760
These questions determine if your system is controlled

1648
00:57:21,760 --> 00:57:24,000
or just a faster way to break the rules.

1649
00:57:24,000 --> 00:57:27,200
Risk metrics show you if your governance is actually holding firm.

1650
00:57:27,200 --> 00:57:30,080
You need to track how many unauthorized access attempts were blocked

1651
00:57:30,080 --> 00:57:31,680
and how many data leaks were prevented.

1652
00:57:31,680 --> 00:57:34,240
You need to see if permissions are creeping upward over time

1653
00:57:34,240 --> 00:57:35,360
or staying tight.

1654
00:57:35,360 --> 00:57:38,160
These numbers tell you if your foundation is preventing bad outcomes

1655
00:57:38,160 --> 00:57:40,080
or just recording them after they happen.

1656
00:57:40,080 --> 00:57:41,760
The framework for this measurement has to start

1657
00:57:41,760 --> 00:57:42,960
before you turn anything on.

1658
00:57:42,960 --> 00:57:44,800
You need to establish your baselines now.

1659
00:57:44,800 --> 00:57:47,440
Document how long a typical decision takes today.

1660
00:57:47,440 --> 00:57:49,440
Record how many tasks never get finished

1661
00:57:49,440 --> 00:57:51,600
and what your current error rate looks like.

1662
00:57:51,600 --> 00:57:53,680
Six months after the agent fabric is live,

1663
00:57:53,680 --> 00:57:55,120
run those same tests again.

1664
00:57:55,120 --> 00:57:57,840
The difference between those numbers tells you what changed.

1665
00:57:57,840 --> 00:58:00,880
More importantly, it tells you if those changes match your goals.

1666
00:58:00,880 --> 00:58:02,480
If your decision time dropped by half

1667
00:58:02,480 --> 00:58:04,240
but your error rate stayed the same,

1668
00:58:04,240 --> 00:58:05,680
you have speed without safety.

1669
00:58:05,680 --> 00:58:06,960
You need to investigate why.

1670
00:58:06,960 --> 00:58:08,720
Maybe the governance controls missed something

1671
00:58:08,720 --> 00:58:11,040
or the component is showing incomplete data.

1672
00:58:11,040 --> 00:58:12,720
If people are finishing tasks faster

1673
00:58:12,720 --> 00:58:14,720
but compliance violations are spiking,

1674
00:58:14,720 --> 00:58:16,160
you are moving in the wrong direction.

1675
00:58:16,160 --> 00:58:18,720
You have to recalibrate, tighten your data protections

1676
00:58:18,720 --> 00:58:20,000
and add more checkpoints.

1677
00:58:20,000 --> 00:58:22,880
You might even need to slow down to make sure you are moving safely.

1678
00:58:22,880 --> 00:58:24,560
Measurement is what reveals the truth.

1679
00:58:24,560 --> 00:58:27,360
It cuts through the hype and shows you the structural reality

1680
00:58:27,360 --> 00:58:28,320
of your business.

1681
00:58:28,320 --> 00:58:30,480
That is where real improvement actually starts.

1682
00:58:31,440 --> 00:58:33,360
The organizations that will struggle.

1683
00:58:33,360 --> 00:58:36,880
A clear pattern is emerging in organizations piloting co-pilot right now.

1684
00:58:36,880 --> 00:58:40,000
It is worth naming because you might be seeing it in your own office.

1685
00:58:40,000 --> 00:58:42,720
The companies struggling the hardest are not failing

1686
00:58:42,720 --> 00:58:44,400
because the technology is broken.

1687
00:58:44,400 --> 00:58:47,680
They are struggling because their governance foundation is fractured.

1688
00:58:47,680 --> 00:58:50,640
Weak governance is easy to spot once you know what to look for.

1689
00:58:50,640 --> 00:58:53,280
It looks like overshared sites where access was never tightened

1690
00:58:53,280 --> 00:58:54,560
after the first deployment.

1691
00:58:54,560 --> 00:58:58,400
It looks like unclassified data sitting inconsistently across the tenant

1692
00:58:58,400 --> 00:59:00,560
where some folders have labels but most do not.

1693
00:59:00,560 --> 00:59:04,800
You see it in DLP policies that only exist as templates nobody ever configured.

1694
00:59:04,800 --> 00:59:07,680
Permission models vary wildly from one side to the next

1695
00:59:07,680 --> 00:59:09,520
because there is no central standard.

1696
00:59:09,520 --> 00:59:11,680
Audit practices log events into a black hole

1697
00:59:11,680 --> 00:59:14,400
because nobody defined what actually matters to monitor.

1698
00:59:14,400 --> 00:59:17,040
This mess is invisible when people navigate manually.

1699
00:59:17,040 --> 00:59:20,160
A user searches for a document, finds it and moves on.

1700
00:59:20,160 --> 00:59:22,400
If they stumble into something they should not see,

1701
00:59:22,400 --> 00:59:24,400
it is just an isolated incident.

1702
00:59:24,400 --> 00:59:27,040
Nobody traces it back to a systemic permission problem.

1703
00:59:27,040 --> 00:59:30,160
The friction of discovery actually provides a layer of protection.

1704
00:59:30,160 --> 00:59:32,800
You have to actively look to find overshared content

1705
00:59:32,800 --> 00:59:34,800
and most people simply do not bother.

1706
00:59:34,800 --> 00:59:37,040
Co-pilot changes that equation instantly.

1707
00:59:37,040 --> 00:59:40,320
The moment you enable co-pilot in an organization with weak governance,

1708
00:59:40,320 --> 00:59:43,440
you have created a discovery engine that operates at machine speed.

1709
00:59:43,440 --> 00:59:46,000
A user asks co-pilot for sales forecasts

1710
00:59:46,000 --> 00:59:48,640
and the engine searches across the entire tenant to find them.

1711
00:59:48,640 --> 00:59:51,040
It finds them in the main sales site which is appropriate

1712
00:59:51,040 --> 00:59:53,360
but it also finds them in the shared CEO folder

1713
00:59:53,360 --> 00:59:55,760
because that site inherits permissions from its parent.

1714
00:59:55,760 --> 00:59:57,920
It finds them in a departmental sharepoint site

1715
00:59:57,920 --> 01:00:00,080
that was supposed to be restricted but never was.

1716
01:00:00,080 --> 01:00:02,400
It even finds them in a years old archive site

1717
01:00:02,400 --> 01:00:04,800
that still has default company-wide access.

1718
01:00:04,800 --> 01:00:07,520
Data that was technically accessible but practically hidden

1719
01:00:07,520 --> 01:00:09,200
is now surfaced in seconds.

1720
01:00:09,200 --> 01:00:11,680
The security and compliance teams notice this immediately.

1721
01:00:11,680 --> 01:00:14,240
They see the data flow, they see the risk, and they panic.

1722
01:00:14,240 --> 01:00:16,720
The response is predictable.

1723
01:00:16,720 --> 01:00:19,280
They block co-pilot access to sensitive sites.

1724
01:00:19,280 --> 01:00:22,000
They refuse to index entire categories of data.

1725
01:00:22,000 --> 01:00:24,640
They restrict co-pilot to a tiny white list of approved sites

1726
01:00:24,640 --> 01:00:26,160
instead of letting it search broadly.

1727
01:00:26,160 --> 01:00:29,440
In some cases, organizations simply refuse to enable co-pilot at all

1728
01:00:29,440 --> 01:00:31,040
because the risk feels too high.

1729
01:00:31,040 --> 01:00:32,880
The result is organizational paralysis.

1730
01:00:32,880 --> 01:00:35,280
You have bought the licenses, you have trained the teams,

1731
01:00:35,280 --> 01:00:36,880
you have announced the deployment.

1732
01:00:36,880 --> 01:00:38,960
Now you are telling those teams they cannot use it

1733
01:00:38,960 --> 01:00:42,000
or they can only use it in ways that eliminate most of its value.

1734
01:00:42,000 --> 01:00:43,600
The initiative becomes a liability.

1735
01:00:43,600 --> 01:00:45,280
It costs money and delivers nothing.

1736
01:00:45,280 --> 01:00:48,320
Adoption flatlines and the investment becomes a sunk cost.

1737
01:00:48,320 --> 01:00:50,480
This creates a 12 to 18 month lag

1738
01:00:50,480 --> 01:00:52,320
where the organization is paying for co-pilot

1739
01:00:52,320 --> 01:00:54,000
while the technology sits idle.

1740
01:00:54,000 --> 01:00:56,640
The licenses keep renewing and the budget stays active

1741
01:00:56,640 --> 01:00:58,480
but nothing meaningful is happening.

1742
01:00:58,480 --> 01:01:01,120
Security feels vindicated because they prevented a breach.

1743
01:01:01,120 --> 01:01:03,600
Business feels frustrated because they were promised capability

1744
01:01:03,600 --> 01:01:05,280
and got a sandbox instead.

1745
01:01:05,280 --> 01:01:07,520
It is caught in the middle trying to find a compromise

1746
01:01:07,520 --> 01:01:09,200
that satisfies both sides.

1747
01:01:09,200 --> 01:01:10,720
The cost compounds over time.

1748
01:01:10,720 --> 01:01:13,440
During those 18 months, your competitors are moving forward.

1749
01:01:13,440 --> 01:01:15,040
They invested in governance first

1750
01:01:15,040 --> 01:01:18,240
so their co-pilot deployment actually accelerates their decision making.

1751
01:01:18,240 --> 01:01:19,680
Their operations get faster.

1752
01:01:19,680 --> 01:01:21,280
They capture efficiency gains.

1753
01:01:21,280 --> 01:01:23,680
Meanwhile, your organization is stuck explaining

1754
01:01:23,680 --> 01:01:26,480
why you have licenses that nobody can use.

1755
01:01:26,480 --> 01:01:27,920
The exit from this trap exists

1756
01:01:27,920 --> 01:01:29,360
but only if you start now.

1757
01:01:29,360 --> 01:01:31,680
Do not wait for co-pilot to force the issue.

1758
01:01:31,680 --> 01:01:33,440
Start the governance work immediately.

1759
01:01:33,440 --> 01:01:35,760
Run the permission audits, classify the data,

1760
01:01:35,760 --> 01:01:38,720
implement the DLP policies, build the controls.

1761
01:01:38,720 --> 01:01:40,080
It is slower in the short term

1762
01:01:40,080 --> 01:01:42,480
and it requires everyone to get on the same page.

1763
01:01:42,480 --> 01:01:43,440
It takes months.

1764
01:01:43,440 --> 01:01:46,640
But by the time SPFX 1.24 reaches general availability

1765
01:01:46,640 --> 01:01:48,480
and adoption accelerates, you will be ready.

1766
01:01:48,480 --> 01:01:50,960
You will move from concept to production at speed.

1767
01:01:50,960 --> 01:01:52,880
You will capture the gains while competitors

1768
01:01:52,880 --> 01:01:54,720
are still arguing about permissions.

1769
01:01:54,720 --> 01:01:56,080
The choice is clear.

1770
01:01:56,080 --> 01:01:57,840
Govern now or struggle later.

1771
01:01:57,840 --> 01:02:01,200
The organizations that will win.

1772
01:02:01,200 --> 01:02:02,720
Contrast that with the organizations

1773
01:02:02,720 --> 01:02:04,480
making different decisions right now.

1774
01:02:04,480 --> 01:02:05,520
They are not waiting.

1775
01:02:05,520 --> 01:02:08,480
They are not stuck in permission audits and compliance debates.

1776
01:02:08,480 --> 01:02:10,560
They are already moving through that work methodically

1777
01:02:10,560 --> 01:02:12,400
because they treat it as a prerequisite.

1778
01:02:12,400 --> 01:02:14,080
What is different about their approach?

1779
01:02:14,080 --> 01:02:17,840
They have accepted that governance is not a friction point to minimize.

1780
01:02:17,840 --> 01:02:20,400
It is the foundation that makes everything else possible.

1781
01:02:20,400 --> 01:02:21,840
They are building it deliberately.

1782
01:02:21,840 --> 01:02:24,000
They run data access governance reports

1783
01:02:24,000 --> 01:02:27,760
as an operational baseline rather than a one-time exercise.

1784
01:02:27,760 --> 01:02:29,760
They classify their data because they understand

1785
01:02:29,760 --> 01:02:31,760
that classification enables automation.

1786
01:02:31,760 --> 01:02:33,200
They implement DLP policies

1787
01:02:33,200 --> 01:02:35,680
because they know those policies will eventually govern

1788
01:02:35,680 --> 01:02:36,960
how the agent fabric operates.

1789
01:02:36,960 --> 01:02:39,360
They build discipline across IT security and business

1790
01:02:39,360 --> 01:02:41,520
because they know this is not a technical project

1791
01:02:41,520 --> 01:02:43,280
for security to own an isolation.

1792
01:02:43,280 --> 01:02:46,000
That cross-functional alignment is what separates them

1793
01:02:46,000 --> 01:02:47,760
from the organizations that struggle.

1794
01:02:47,760 --> 01:02:49,840
When IT proposes a governance control,

1795
01:02:49,840 --> 01:02:52,000
security understands why it matters.

1796
01:02:52,000 --> 01:02:54,560
When compliance asks for audit trails, business accepts the cost

1797
01:02:54,560 --> 01:02:56,080
because they understand the value.

1798
01:02:56,080 --> 01:02:57,600
When business wants to move fast,

1799
01:02:57,600 --> 01:02:59,680
IT and security have frameworks in place

1800
01:02:59,680 --> 01:03:01,120
that let them move safely.

1801
01:03:01,120 --> 01:03:02,320
There is a shared language.

1802
01:03:02,320 --> 01:03:05,840
There is alignment on what secure actually means in their context.

1803
01:03:05,840 --> 01:03:07,440
That alignment creates momentum.

1804
01:03:07,440 --> 01:03:09,120
It is a different pace entirely.

1805
01:03:09,120 --> 01:03:13,120
They are not waiting for SPF X1.24 to go live in autumn of 2026

1806
01:03:13,120 --> 01:03:14,560
before they start preparing.

1807
01:03:14,560 --> 01:03:17,920
They are using the preview period between July and late 2026

1808
01:03:17,920 --> 01:03:21,120
to test components and understand how co-pilot surfaces them.

1809
01:03:21,120 --> 01:03:23,840
They are training developers on the new model right now.

1810
01:03:23,840 --> 01:03:26,720
By the time general availability arrives, they are not learning.

1811
01:03:26,720 --> 01:03:27,840
They are scaling.

1812
01:03:27,840 --> 01:03:29,680
That timing advantage is measurable.

1813
01:03:29,680 --> 01:03:32,880
While struggling organizations are still debating if co-pilot is safe,

1814
01:03:32,880 --> 01:03:35,600
these organizations are moving from pilot to production.

1815
01:03:35,600 --> 01:03:38,400
They are not dealing with proof of concept friction.

1816
01:03:38,400 --> 01:03:39,920
They are dealing with scale challenges

1817
01:03:39,920 --> 01:03:41,840
which are fundamentally different problems.

1818
01:03:41,840 --> 01:03:44,560
Scale is about infrastructure and monitoring,

1819
01:03:44,560 --> 01:03:45,760
which are solvable.

1820
01:03:45,760 --> 01:03:48,640
Proof of concept friction is about misaligned governance and fear,

1821
01:03:48,640 --> 01:03:50,320
which is much harder to fix.

1822
01:03:50,320 --> 01:03:53,040
The competitive consequence becomes visible within months.

1823
01:03:53,040 --> 01:03:55,280
These organizations start capturing efficiency gains

1824
01:03:55,280 --> 01:03:57,280
that competitors are not even attempting yet.

1825
01:03:57,280 --> 01:03:59,360
Their operations teams make decisions faster

1826
01:03:59,360 --> 01:04:02,080
because the data surfaces exactly where they need it.

1827
01:04:02,080 --> 01:04:04,400
Their project managers coordinate work in half the time

1828
01:04:04,400 --> 01:04:07,200
because the agent fabric handles the communication and approvals.

1829
01:04:07,200 --> 01:04:10,160
Their customer service teams resolve escalations with better information

1830
01:04:10,160 --> 01:04:13,040
because co-pilot synthesizes context from multiple sources.

1831
01:04:13,040 --> 01:04:14,880
Meanwhile, the organizations that delayed

1832
01:04:14,880 --> 01:04:17,200
are still stuck in the governance debate phase

1833
01:04:17,200 --> 01:04:18,960
that efficiency gap compounds.

1834
01:04:18,960 --> 01:04:21,840
By the end of 2026, the speed difference is obvious.

1835
01:04:21,840 --> 01:04:23,920
By mid-2027, it is undeniable.

1836
01:04:23,920 --> 01:04:26,400
These organizations have built organizational muscle

1837
01:04:26,400 --> 01:04:27,760
around the agent fabric.

1838
01:04:27,760 --> 01:04:29,200
Their teams know how to work with it.

1839
01:04:29,200 --> 01:04:31,280
Their governance controls are running routinely,

1840
01:04:31,280 --> 01:04:32,640
not as special projects.

1841
01:04:32,640 --> 01:04:35,040
Their data is classified, their permissions are tight,

1842
01:04:35,040 --> 01:04:36,960
and their audit trails are complete.

1843
01:04:36,960 --> 01:04:38,400
They are operating in the new model,

1844
01:04:38,400 --> 01:04:40,640
while competitors are still planning to transition.

1845
01:04:40,640 --> 01:04:42,560
The talent dynamics shifts too.

1846
01:04:42,560 --> 01:04:46,080
These organizations become known as places where the technology actually works.

1847
01:04:46,080 --> 01:04:48,240
You can build something and actually use it in production

1848
01:04:48,240 --> 01:04:49,680
without fighting restrictions.

1849
01:04:49,680 --> 01:04:52,080
That reputation attracts developers and architects

1850
01:04:52,080 --> 01:04:54,080
who want to work on modern infrastructure.

1851
01:04:54,080 --> 01:04:57,360
They want to build a GEN-TIC UX instead of old-page components.

1852
01:04:57,360 --> 01:04:58,720
They want to solve governance problems

1853
01:04:58,720 --> 01:05:00,480
instead of fighting compliance blocks.

1854
01:05:00,480 --> 01:05:03,200
The talent advantage becomes self-reinforcing,

1855
01:05:03,200 --> 01:05:04,880
better talent builds better systems

1856
01:05:04,880 --> 01:05:06,800
and better systems attract more talent.

1857
01:05:06,800 --> 01:05:08,560
The business outcome is measurable

1858
01:05:08,560 --> 01:05:10,400
in ways that go beyond simple metrics.

1859
01:05:10,400 --> 01:05:12,560
These organizations improve their compliance posture

1860
01:05:12,560 --> 01:05:14,640
because their controls are tight and well integrated.

1861
01:05:14,640 --> 01:05:17,360
They achieve real ROI on their co-pilot investment

1862
01:05:17,360 --> 01:05:19,200
because they are actually using it productively.

1863
01:05:19,200 --> 01:05:20,480
They reduce operational risk

1864
01:05:20,480 --> 01:05:22,160
because decisions happen with better data

1865
01:05:22,160 --> 01:05:23,920
and complete audit trails.

1866
01:05:23,920 --> 01:05:26,480
They build institutional knowledge about how to operate

1867
01:05:26,480 --> 01:05:28,880
at the intersection of innovation and control.

1868
01:05:28,880 --> 01:05:31,200
By 2028, when the market has fully caught up

1869
01:05:31,200 --> 01:05:32,480
to the architectural shift,

1870
01:05:32,480 --> 01:05:34,560
the gap will be visible in every metric.

1871
01:05:34,560 --> 01:05:35,760
It will not be theoretical.

1872
01:05:35,760 --> 01:05:37,680
It will be measurable in decision cycle time

1873
01:05:37,680 --> 01:05:40,640
in project completion rates and in ROI per license.

1874
01:05:40,640 --> 01:05:42,640
The organizations that prepared now are ahead,

1875
01:05:42,640 --> 01:05:44,720
the organizations that delayed are playing catch-up.

1876
01:05:44,720 --> 01:05:47,120
This reckoning clarifies what is actually at stake

1877
01:05:47,120 --> 01:05:49,040
in the decisions you make right now.

1878
01:05:49,040 --> 01:05:50,480
The structural inevitability.

1879
01:05:50,480 --> 01:05:52,320
The question isn't whether this shift happens,

1880
01:05:52,320 --> 01:05:54,560
it's whether you're ahead of it or behind it when it does.

1881
01:05:54,560 --> 01:05:56,480
The forces pushing us toward the agent fabric

1882
01:05:56,480 --> 01:05:58,480
aren't just trends, they're structural.

1883
01:05:58,480 --> 01:06:01,440
For years, text has been the bottleneck for complex work.

1884
01:06:01,440 --> 01:06:03,680
You type a question, you get back a wall of text,

1885
01:06:03,680 --> 01:06:05,120
then you have to leave that interface

1886
01:06:05,120 --> 01:06:07,360
just to actually do something with the information

1887
01:06:07,360 --> 01:06:09,200
that workflow works for simple things,

1888
01:06:09,200 --> 01:06:11,120
like asking what time a meeting starts.

1889
01:06:11,120 --> 01:06:13,440
But it breaks the moment you need to make a decision

1890
01:06:13,440 --> 01:06:15,360
or finish a multi-step task.

1891
01:06:15,360 --> 01:06:17,280
The technology to fix this isn't a dream.

1892
01:06:17,280 --> 01:06:18,240
It exists right now.

1893
01:06:18,240 --> 01:06:21,200
We have interactive components living inside the co-pilot canvas.

1894
01:06:21,200 --> 01:06:24,080
We have SPFX rendering directly inside agents.

1895
01:06:24,080 --> 01:06:26,960
We have MCP servers that can expose tools and UI

1896
01:06:26,960 --> 01:06:28,400
at the exact same time.

1897
01:06:28,400 --> 01:06:29,920
These aren't ideas for the future.

1898
01:06:29,920 --> 01:06:31,280
They're in preview today.

1899
01:06:31,280 --> 01:06:33,600
And they'll be everywhere within the next six months.

1900
01:06:33,600 --> 01:06:35,280
When you have the tech to remove friction,

1901
01:06:35,280 --> 01:06:36,480
economics takes over.

1902
01:06:36,480 --> 01:06:38,800
Organizations using these tools move faster.

1903
01:06:38,800 --> 01:06:41,520
They make better decisions because their data is actually useful.

1904
01:06:41,520 --> 01:06:42,880
They get more done in less time.

1905
01:06:42,880 --> 01:06:44,880
They also lower their risk because their governance

1906
01:06:44,880 --> 01:06:46,640
is built in and easy to audit.

1907
01:06:46,640 --> 01:06:50,000
In a competitive market, that speed becomes a massive advantage.

1908
01:06:50,000 --> 01:06:51,360
Some companies will grab it early.

1909
01:06:51,360 --> 01:06:54,160
The rest will be forced to play catch-up just to stay alive.

1910
01:06:54,160 --> 01:06:55,440
The timeline is already set.

1911
01:06:55,440 --> 01:06:59,120
In July of 2026, licensing changes will turn embedded co-pilot

1912
01:06:59,120 --> 01:07:00,880
in office into a paid feature.

1913
01:07:00,880 --> 01:07:05,680
By late 2026, SPFX 1.24 and SharePoint co-pilot apps

1914
01:07:05,680 --> 01:07:07,760
will be fully available to everyone.

1915
01:07:07,760 --> 01:07:11,280
By early 2027, the companies that invested in their architecture

1916
01:07:11,280 --> 01:07:12,560
won't be testing anymore.

1917
01:07:12,560 --> 01:07:13,600
They'll be operating.

1918
01:07:13,600 --> 01:07:15,920
They'll be running real workflows through the agent fabric.

1919
01:07:15,920 --> 01:07:17,440
They'll be making decisions in minutes

1920
01:07:17,440 --> 01:07:19,280
that used to take your team hours.

1921
01:07:19,280 --> 01:07:21,920
This shift changes what we consider normal.

1922
01:07:21,920 --> 01:07:23,680
New companies entering the market

1923
01:07:23,680 --> 01:07:25,200
won't have to learn this model.

1924
01:07:25,200 --> 01:07:27,600
They'll just adopt it as the standard way of doing business.

1925
01:07:27,600 --> 01:07:30,000
The pioneers won't just have a head start on speed.

1926
01:07:30,000 --> 01:07:32,080
They'll be the ones who wrote the rules on governance

1927
01:07:32,080 --> 01:07:34,240
and architecture that everyone else has to copy.

1928
01:07:34,240 --> 01:07:36,880
The impact ripples through every role in the company.

1929
01:07:36,880 --> 01:07:40,080
Jobs built around just finding data are going away.

1930
01:07:40,080 --> 01:07:42,240
Jobs that require real-time decision making

1931
01:07:42,240 --> 01:07:44,320
are becoming the most important roles you have.

1932
01:07:44,320 --> 01:07:46,320
The developer market is shifting from building pages

1933
01:07:46,320 --> 01:07:47,920
to architecting orchestration.

1934
01:07:47,920 --> 01:07:49,600
IT is moving from watching platforms

1935
01:07:49,600 --> 01:07:50,800
to engineering governance.

1936
01:07:50,800 --> 01:07:52,160
These aren't small tweaks.

1937
01:07:52,160 --> 01:07:54,160
This is role extinction and role creation

1938
01:07:54,160 --> 01:07:55,520
happening at the same time.

1939
01:07:55,520 --> 01:07:57,680
The governance problem is where this hits the hardest.

1940
01:07:57,680 --> 01:07:59,040
If you don't invest now,

1941
01:07:59,040 --> 01:08:01,200
you'll face a brutal choice in 18 months.

1942
01:08:01,200 --> 01:08:03,920
You can spend months doing expensive governance work then,

1943
01:08:03,920 --> 01:08:05,680
or you can pay for massive remediation

1944
01:08:05,680 --> 01:08:07,520
under pressure when things inevitably break.

1945
01:08:07,520 --> 01:08:09,520
The cost of waiting isn't just a slow rollout.

1946
01:08:09,520 --> 01:08:11,760
It's the compounding price of fixing a broken system

1947
01:08:11,760 --> 01:08:13,040
after an operational failure.

1948
01:08:13,040 --> 01:08:14,480
But here's what actually matters.

1949
01:08:14,480 --> 01:08:16,560
The first move will set the standard for what works.

1950
01:08:16,560 --> 01:08:20,000
By the time SPFX 1.24 is the default way to build apps,

1951
01:08:20,000 --> 01:08:22,240
the earlier adopters will have months of proven patterns

1952
01:08:22,240 --> 01:08:23,840
already baked into their culture.

1953
01:08:23,840 --> 01:08:25,360
They'll know exactly what works.

1954
01:08:25,360 --> 01:08:27,760
Competitors who wait will just be copying old home work.

1955
01:08:27,760 --> 01:08:28,800
They won't be innovating.

1956
01:08:28,800 --> 01:08:29,680
They'll just be following.

1957
01:08:29,680 --> 01:08:31,280
The business reality is simple.

1958
01:08:31,280 --> 01:08:33,520
At the turning point in late 2026,

1959
01:08:33,520 --> 01:08:36,480
the market stops asking if the agent fabric is possible.

1960
01:08:36,480 --> 01:08:38,240
It starts assuming it's the standard.

1961
01:08:38,240 --> 01:08:40,160
Organizations caught in the middle will lose.

1962
01:08:40,160 --> 01:08:41,600
They'll be paying for new technology

1963
01:08:41,600 --> 01:08:43,360
without the governance to use it safely.

1964
01:08:43,360 --> 01:08:44,560
They'll be stuck in old processes

1965
01:08:44,560 --> 01:08:46,160
while everyone else races past them.

1966
01:08:46,160 --> 01:08:49,600
Your position in 2028 is being decided by what you do right now.

1967
01:08:49,600 --> 01:08:50,720
It's not about the tech.

1968
01:08:50,720 --> 01:08:51,600
The tech is solved.

1969
01:08:51,600 --> 01:08:52,880
It's about your governance.

1970
01:08:52,880 --> 01:08:54,800
It's about whether you build the foundation

1971
01:08:54,800 --> 01:08:56,560
that makes this whole architecture possible.

1972
01:08:56,560 --> 01:08:58,480
The path forward.

1973
01:08:58,480 --> 01:08:59,760
The choice is actually simple.

1974
01:08:59,760 --> 01:09:01,200
You can invest in governance now.

1975
01:09:01,200 --> 01:09:02,720
Or you can accept a tiny return

1976
01:09:02,720 --> 01:09:05,200
on your co-pilot investment while your competitors pull away.

1977
01:09:05,200 --> 01:09:06,400
The window is closing fast.

1978
01:09:06,400 --> 01:09:07,840
We have the July 1st pricing.

1979
01:09:07,840 --> 01:09:09,840
We have the July 2026 preview.

1980
01:09:09,840 --> 01:09:12,480
We have the general release in the autumn of 2026

1981
01:09:12,480 --> 01:09:14,960
by the time you're hearing this month's have already slipped by.

1982
01:09:14,960 --> 01:09:16,000
So start here.

1983
01:09:16,000 --> 01:09:17,200
Run a governance audit.

1984
01:09:17,200 --> 01:09:18,320
Classify your data.

1985
01:09:18,320 --> 01:09:19,840
Set up your DLP policies.

1986
01:09:19,840 --> 01:09:22,640
Get your IT security and business teams on the same page.

1987
01:09:22,640 --> 01:09:25,520
Then build your agent fabric on top of that foundation.

1988
01:09:25,520 --> 01:09:28,160
By 2027, you'll be running the new model

1989
01:09:28,160 --> 01:09:30,400
while your competitors are still fighting with the old one.

1990
01:09:30,400 --> 01:09:31,680
That isn't just a small win.

1991
01:09:31,680 --> 01:09:33,840
It's a total shift in how your enterprise operates.

1992
01:09:33,840 --> 01:09:35,280
The technology is just the tool.

1993
01:09:35,280 --> 01:09:36,560
The change is structural.

1994
01:09:36,560 --> 01:09:37,920
Subscribe for the next episode

1995
01:09:37,920 --> 01:09:41,760
where we'll look at the specific governance patterns that actually scale.

1996
01:09:41,760 --> 01:09:43,760
And if you're dealing with these challenges right now,

1997
01:09:43,760 --> 01:09:44,960
connect with me, Mirko Peters.

1998
01:09:44,960 --> 01:09:46,960
On LinkedIn, let's figure this out together.