Independent installation guide

Deploy and operate Copilot Agent Kit

A source-backed guide to prerequisites, installation, setup, governance, testing, and CI/CD for the current Microsoft Power CAT toolkit.

Scope and ownership: This site is maintained independently from Microsoft. It summarizes official Microsoft Learn and GitHub sources and is not a Microsoft product page or statement of support.

Version checkpoint

Latest verified release

Verified 2026-08-28

Copilot Agent Kit August 2026 Update 1 – Agent Review Tool Setup Fix

Tag
CopilotStudioAccelerator-August2026.1
Published
Managed asset
CopilotAgentKit_20260817.1_managed.zip

Asset selection

For this release, install CopilotAgentKit_20260817.1_managed.zip. The release also provides AgentReviewPipeline_20260817.1_managed.zip, AgentReviewPipeline.zip, Conversation.KPIs.zip, and CopilotAgentKit.zip.

For a later release, open the latest release page and select the managed Copilot Agent Kit solution attached there. Treat the dated filename above as exact for August 2026 Update 1, not as a permanent naming rule.

Product naming

Microsoft identified July 2026 as the first phase of the rename from Copilot Studio Kit to Copilot Agent Kit. The official GitHub repository retains its historical name, and official role guidance currently drifts between CSK and CAK prefixes. Use the roles present in the imported solution and verify them against the current source instructions.

August 2026 Update 1

Release highlights

  • Agent Change TrackerTrack supported changes for selected agents in the current environment with a versioned timeline, maker details, before-and-after values, summaries, and YAML details.
  • Agent LibraryBrowse a gallery of ready-to-deploy MCP Apps alongside reusable agent resources.
  • Agent Review ToolReview GitHub Copilot harness-based agents with Skill Evaluator, Agent Map, instruction coverage, and cost and efficiency insights.
  • Skills and automationsReview agent skills, Microsoft Scout automations, and automation installers for quality, safety, readiness, and compatibility.
  • Agent InventoryUse inventory settings, bulk quarantine or unquarantine and reassignment, multilingual extraction, and richer governance metadata.
  • Debugger, value, and testsDebug harness-based agents, filter by channel, read improved durations, reduce Agent Value Summary scan consumption, and use adaptive cards as test responses.
Shipped does not mean generally available

A feature can ship in the August solution while still being labeled Preview. The Microsoft-owned repository currently labels Agent Change Tracker, Agent Library, and Component Library as Preview. MCP Apps and Skills/Automations are confirmed by the August release notes but remain documentation-light.

Agent Change Tracker currently supports tracked agents in the current environment. Tracking all agents available in Agent Inventory across environments is planned for a future release, not shipped.

Plan the deployment

Capability map

The base solution supports a broad feature family. Most feature-specific configuration is optional, but every connector packaged in the solution still has to be allowed by data policies and populated during import.

Install and core

Platform foundation

Dataverse stores configuration and test data. The Setup Wizard checks prerequisites, maps core connection references and environment variables, and activates selected cloud flows.

Testing and quality

Evaluation toolchain

Test Automation supports test sets and rubrics. Agent Review Tool, Agent Debugger, Rubrics Refinement, and adaptive-card responses extend quality review and diagnostics.

Governance

Inventory and controls

Compliance Hub, Agent Inventory, Power Shield, and Agent Change Tracker support discovery, risk controls, DLP workflows, administrative actions, and change visibility.

Analytics

Performance and value

Agent Insights Hub, Conversation KPIs, Conversation Analyzer, and Agent Value bring telemetry, outcomes, qualitative analysis, and value classification into operational review.

Maker productivity

Build and reuse

Agent Library, SharePoint synchronization, Prompt Advisor, Webchat Playground, Adaptive Cards Gallery, and MCP Apps shorten common maker workflows.

Advanced CI/CD

Automated deployment gates

Automated testing with Power Platform Pipelines and the standalone Agent Review Pipeline can apply quality checks before a deployment proceeds.

Before import

Preflight checklist

  1. Dataverse environment: select a Power Platform environment with Dataverse.
  2. Installer permissions: use an account with the System Administrator security role in the target environment.
  3. Code components: enable Power Apps code component framework for canvas apps.
  4. Code Apps: enable Power Apps Code Apps in the environment.
  5. Licensing: confirm licensing that permits model-driven apps and premium cloud flows.
  6. Creator Kit: install the Power Platform Creator Kit before importing Copilot Agent Kit.
  7. Data policies: make sure every applicable DLP policy allows all 12 packaged connectors.
  8. Connections: prepare an authorized connection for every connector and populate each request during import, even when its feature is optional.
Complete connector matrix from Microsoft Learn
Connector Used by Import requirement
Microsoft DataverseCore features, Power Shield, Agent Review ToolAllow and populate
Power Platform for AdminsAgent InventoryAllow and populate
Power Platform for Admins V2Agent Inventory, Compliance HubAllow and populate
Microsoft TeamsCompliance HubAllow and populate
Office 365 GroupsCompliance HubAllow and populate
Office 365 UsersCompliance HubAllow and populate
Office 365 OutlookCompliance HubAllow and populate
ApprovalsCompliance HubAllow and populate
SharePoint OnlineSharePoint synchronizationAllow and populate
Power Apps for MakersSetup Wizard, Power ShieldAllow and populate
HTTP with Microsoft Entra ID (preauthorized)Power Shield, usage metricsAllow and populate
Microsoft Copilot StudioTest Automation, pipelineAllow and populate
DLP is a deployment prerequisite, not a feature toggle

If any packaged connector is blocked or left unpopulated, import or runtime operations can fail even when you do not intend to configure that connector's feature immediately.

Optional capacity and telemetry

Plan AI Builder/Copilot credits for AI-backed features such as generative-answer evaluation, Conversation Analyzer, Prompt Advisor, Agent Review Tool, Agent Value Summary, and Rubrics Refinement. Configure Application Insights only when you need its additional telemetry. Microsoft does not publish one universal consumption estimate for every workload, so size credits from your own test volume.

Two supported paths

Install and upgrade

Method A

Microsoft Marketplace

Use the current Marketplace listing to deploy the package into a selected environment, then complete the documented post-deployment repair.

Method B

GitHub managed solution

Download the managed solution from the latest official release and import it through Power Apps. This is also the path used for a managed upgrade.

Method A: Marketplace deployment

  1. Complete the preflight checklist, including Creator Kit, environment settings, licensing, DLP, and connections.
  2. Open the current Marketplace listing, select Get it now, and sign in if requested.
  3. Select the target environment, review the terms and statements, and start the installation.
  4. After deployment, open Power Apps, then Solutions and Default Solution.
  5. Open Connection references, repair Copilot Agent Kit - Dataverse, create or select a valid Dataverse connection, and save.
  6. Continue with the Setup Wizard and the post-deployment checks in this guide.

Method B: GitHub managed import

  1. Open the latest release. For the verified August release, download CopilotAgentKit_20260817.1_managed.zip.
  2. Sign in to Power Apps, select the target environment, open Solutions, and select Import solution.
  3. Select the downloaded managed ZIP. Review the solution information and create or select every requested connection.
  4. Leave the Conversation KPI environment-variable values unchanged during the initial import; configure them later only if you deploy the KPI report.
  5. Start the import. After it reports completion, open the Setup Wizard and complete the verification checklist.
Current asset name versus documentation examples

The latest release page is authoritative for the exact assets it ships. Parts of Microsoft Learn retain an earlier or generic managed-solution filename. Use CopilotAgentKit_20260817.1_managed.zip for the verified release; for a future release, choose its managed Agent Kit asset rather than reusing this dated name.

Upgrade an existing managed installation

  1. Back up or otherwise protect environment configuration according to your organization's change process.
  2. Download the newer managed Agent Kit solution from the latest release.
  3. In the target environment, import the managed ZIP and choose the default Upgrade action.
  4. Review connection mappings, initially leave Conversation KPI values unchanged, and complete the upgrade.
  5. Run the Setup Wizard again, confirm the intended flows, and repeat post-deployment verification.
Upgrade versus Update

Upgrade removes components that exist in the older managed solution but are absent from the newer solution. Update does not remove those components.

Known cat_copilottestrunid upgrade issue Solution 'Power CAT Copilot Agent Kit' failed to import: ImportAsHolding failed with exception: Cannot delete attribute: cat_copilottestrunid from Entity: cat_CopilotTestRun since the attribute is not a custom field.

If this known error occurs, choose Stage for Upgrade, complete the import, and then select Apply Solution Upgrade. Follow the official upgrade a solution procedure.

Post-deployment

Setup Wizard coverage and boundaries

Open the Setup Wizard from the Copilot Agent Kit home page. It covers the core path but is not an exhaustive setup surface for every connector or optional feature.

Covered by the wizard

  • Check required dependencies and environment settings.
  • Set core connection references.
  • Set core environment variables.
  • Review and activate the cloud flows selected for use.

Completed outside the wizard

  • Publish the Conversation KPI Power BI report and schedule refresh.
  • Enable Agent Inventory usage metrics.
  • Create app registrations for test automation authentication and Application Insights.
  • Complete feature-specific Compliance Hub and secret configuration.

Core configuration decisions

Agent Inventory mode

Both One Inventory and standard modes require Copilot Agent Kit - Dataverse for detailed agent data. Full visibility requires that connection's account to have System Administrator access in every relevant environment. Microsoft recommends Enable One Inventory = Yes; One Inventory additionally uses Copilot Agent Kit - Power Platform for Admins V2. Usage metrics still require their separate procedure.

Feature variables and secrets

Configure Compliance Hub variables through its feature guidance. Use Azure Key Vault-backed secret environment variables where the feature stores secrets; do not place production secrets in ordinary text values.

Flow activation

Turn on only the flows for features you intend to use, after their related connection references and variables are valid. Revisit this step when enabling another feature.

Connector completeness

The wizard's core connection-reference list does not replace the import requirement: all 12 packaged connectors must be allowed and populated.

Before handoff

Verify, assign access, and share

  1. Confirm the managed Copilot Agent Kit solution appears in the intended environment and the import or update completed without errors.
  2. Run the Setup Wizard and resolve failed prerequisite, connection-reference, environment-variable, or intended-flow checks.
  3. Open Power CAT Copilot Agent Kit and confirm the home experience loads for an administrator.
  4. Validate the features you enabled: run a representative test, confirm the intended inventory scope, and inspect related flow run history where applicable.
  5. Assign the current security roles through Microsoft Entra group teams where possible, then test with representative administrator and maker accounts.
  6. Share the Code app with the intended users or teams. Do not share the model-driven app as the user entry point.
Official role-name drift

Microsoft Learn currently documents CSK - Administrator and CSK - Maker, while the Microsoft-owned repository security-role matrix and current feature instructions use CAK - Administrator and CAK - Maker. This is unresolved official naming drift during the product rename; do not treat either prefix as universally authoritative.

Assign the current administrator or maker roles present in the imported solution, then verify their names and permissions against the current Microsoft Learn role matrix and repository feature instructions.

Administrator and maker role mapping during the rename
Role Use Assignment guidance
Administrator
Learn: CSK - Administrator
Repository: CAK - Administrator
Full administrative access for solution administrators who configure, manage, and maintain the kit. Prefer a Microsoft Entra group team for the administrator population.
Maker
Learn: CSK - Maker
Repository: CAK - Maker
Limited access for developers and testers who build and validate agents and primarily work with their own records. Prefer a separate Microsoft Entra group team for makers.
Legacy roles are deprecated

Do not assign deprecated legacy roles. Migrate users to the current administrator or maker roles present in the imported solution, and verify feature-level access against the current Microsoft Learn role matrix and repository instructions.

Enable deliberately

Feature-specific next steps

What to configure after the core wizard
Feature family Next step Important boundary
Agent Inventory Configure Copilot Agent Kit - Dataverse for detailed data in either mode; for full visibility, give its account System Administrator access in each relevant environment. For One Inventory, also set Enable One Inventory = Yes and use Admins V2. One Inventory additionally uses the Admins V2 connection reference. Usage metrics are configured outside the Setup Wizard.
Compliance Hub Complete its feature-specific variables, groups, connectors, and flows after inventory is configured. Review every governance action and secret location before production use.
Test Automation and rubrics Configure agents, test cases, test sets, and reusable rubrics; add authentication registrations only when needed. AI-backed evaluation consumes AI Builder/Copilot credits. Adaptive cards can be test responses.
Application Insights and Agent Insights Hub Create the required registration and telemetry configuration, then validate ingestion with a controlled test. Application Insights is optional and its registration is not created by the wizard.
Conversation KPIs Use Conversation.KPIs.zip, publish the supplied report, set its identifiers, and schedule refresh. Publishing and scheduling remain manual.
SharePoint synchronization Configure SharePoint and Dataverse settings before activating its flows. Do not activate the feature flows with incomplete references.
Agent Review Tool and Agent Debugger Confirm required capacity and data access, then review a representative agent and inspect its report or conversation trace. The August release expands both tools for GitHub Copilot harness-based agents.
Agent Change Tracker Track selected agents in the current environment and establish how your governance team reviews the version timeline. Preview. Broader tracking of all agents available in Agent Inventory across environments is planned for a future release, not shipped.
Maker tools Evaluate Agent Library, MCP Apps, Prompt Advisor, Webchat Playground, Adaptive Cards Gallery, and SharePoint sync for the maker scenarios you support. Enable only the related flows and configuration that your organization has approved.

Operate with evidence

Governance and testing operating guide

Govern connectors as one package

Review every environment-level data policy before import and whenever policies change. An AppForbidden error is a prompt to verify the full 12-connector matrix, not only the connector named in the most recent feature change.

Separate administrative and maker access

Use the administrator and maker roles present in the imported solution, with Microsoft Entra group teams where possible, to make assignment reviewable and maintainable. Keep privileged service and administrator identities limited to their operational purpose.

Combine deterministic and AI testing

Use response, attachment, topic, multi-turn, rubric-based generative-answer, and adaptive-card tests as applicable. Treat AI scoring as one quality signal alongside deterministic assertions and human review.

Keep an auditable change loop

Use inventory metadata, review findings, test history, and Agent Change Tracker timelines to understand what changed before applying quarantine, reassignment, release, or remediation decisions.

Protect secrets

Store supported secrets in Azure Key Vault-backed environment variables. Never place production tokens or client secrets in documentation, ordinary configuration text, or broadly readable workflow output.

Re-verify each release

Review the latest release page for asset names and changes, stage managed upgrades when required, then repeat wizard, smoke-test, inventory, and access checks before wider use.

Advanced CI/CD

Agent Review Pipeline quality gate

The Agent Review Pipeline is a standalone automated gate for deployments through Power Platform Pipelines. The full Copilot Agent Kit solution is not required.

  1. Pipeline trigger
    A required pre-deployment step starts in a pipeline that uses a custom host.
  2. Host flow
    The managed pipeline solution dispatches a GitHub Actions workflow and waits for its callback.
  3. Evaluation
    The action downloads the solution, runs deterministic and AI checks, calculates a score, and creates a PDF.
  4. Gate result
    The callback approves or rejects the stage against the configured threshold.

Required components

  • A Power Platform Pipeline with a custom pipeline host; platform-hosted and personal pipelines cannot be extended for this gate.
  • The managed pipeline solution. For the verified release, use AgentReviewPipeline_20260817.1_managed.zip.
  • A GitHub repository containing the supplied action and workflow.
  • A Microsoft Entra app registration and Dataverse application user for the pipeline host. Assign that application user the Agent Review Pipeline Service security role; Service Reader is a broader alternative.
  • Copilot Studio credits/messages per evaluation run.
Evaluation stages
Stage Method Purpose
Parse and detectDeterministicChecks structural issues such as missing names or descriptions, variable naming, and excessive tool counts.
Design patternsAIReviews topic design, knowledge configuration, conversation flow, and error handling.
Instruction complianceAIChecks whether authored topics follow the agent's own system instructions.

Decision and evidence

The shipped workflow's default passing threshold is 60. Each run uploads a PDF report as a GitHub Actions artifact so reviewers can inspect the score and findings.

Production credential handling

Microsoft Learn notes that the imported solution can store a GitHub personal access token as plaintext. For production, use a secret environment variable backed by Azure Key Vault. Scope repository credentials narrowly and never grant broad permissions by convenience.

Pipeline asset naming note

Microsoft Learn uses the generic example AgentReviewPipeline_managed.zip. The verified release ships AgentReviewPipeline_20260817.1_managed.zip and the unmanaged AgentReviewPipeline.zip. Use the versioned managed asset for this release.

Diagnose by boundary

Troubleshooting

Expand an issue for the source-backed first checks. Use flow run history and official feature guidance for deeper diagnosis.

Review every data policy applied to the environment. Confirm all 12 connectors in the matrix are allowed and their connections were populated during import. Do not limit the review to features already enabled.

First-party directory

Official sources

Current product claims in this guide are limited to Microsoft Learn and the official Microsoft Power CAT repository and release.