Product
Product12 min readBy The Data Workers Team

You're on Microsoft Copilot Studio: Add Data Workers as an MCP Tool So Every Agent Answers From Governed Data

Your makers build agents in Copilot Studio. Add Data Workers as an MCP tool so those agents answer from governed context and fix data through approvals and receipts.

Your makers are busy in Copilot Studio. Procurement built a Spend Assistant, sales ops built a pipeline agent, HR built an onboarding agent, and each one is published to the Teams and Microsoft Copilot channel so people ask it where they already work. Generative orchestration picks the right tool for each question. Knowledge comes from SharePoint, files and connectors, and the Power Platform admin center decides through data policies which connectors sit in the Business group and which are Blocked. Copilot Studio is where your makers build agents. Data Workers is the agentic data platform those agents call over MCP: it answers from one governed context graph and does the real data work (fix, rerun, verify) behind a named approver and a receipt.

Every maker-built agent that touches a number inherits whatever is true, or broken, in the data underneath. One governed layer under all of them is the difference between twenty agents giving twenty answers and twenty agents giving one.

Key takeaways

  • •Copilot Studio keeps its job. Environments, data policies, channels, admin approval and your maker community stay as they are. Data Workers is one more MCP server your makers add through the MCP onboarding wizard.
  • •Every agent answers from governed context. Through the Data Workers tool, an agent reads metric definitions, lineage, owners, freshness and open incidents from one context graph, so the Spend Assistant and the finance agent give the same number.
  • •Fixes pass two locks. In Copilot Studio, a write tool runs only after a maker turns it on. In Data Workers, each change goes to a named approver in Spellbook with its blast radius, stays reversible and leaves a receipt.
  • •Your data policies cover it from day one. MCP servers in Copilot Studio ride on Power Platform connectors, so the data policies you already run govern the Data Workers server and its tools.
  • •Setup is a short maker task. Add a tool, New tool, Model Context Protocol, the server URL and OAuth 2.0. Turn off Allow all, enable read tools first, and add write tools one domain at a time.
  • •Start with a pilot. Read-only on one agent, then one write class in one domain, on the autonomy ladder from L0 manual to L4 autonomous.

Copilot Studio is where makers build agents. Data Workers is the data crew those agents call.

Copilot Studio made agent building a department-level activity. Fabric data agents add another strong question-answering surface: Microsoft Fabric's What's new page lists the Fabric Data Agent integration with Copilot Studio as generally available in August 2026, adding a data agent "as a Fabric IQ Data MCP tool while retaining source permissions" (checked Oct 2, 2026). That raises the stakes on the data underneath. When a model in Databricks drops rows, every agent that reads it repeats the wrong number with confidence.

Here is what that looks like on a Friday morning with Data Workers connected. This is an illustration, not a customer case.

TimeSystemWhat happens
Thu 18:00SAP S/4HANAFinance adds company code 4100 for a newly acquired subsidiary
01:00Azure Data FactoryThe nightly copy lands the new entity's invoices in ADLS
02:00Databricks + dbtThe job succeeds; fct_vendor_spend filters company codes through a seed file, so 4100's invoices drop out
02:20Data WorkersA row-count check against the source finds 1,240 invoices missing; Data Workers traces the gap through lineage to the seed and opens an incident
08:30Copilot Studio agent (Teams)A procurement director asks the Spend Assistant why logistics spend fell 22% this quarter
08:31Data WorkersThe orchestrator calls the Data Workers tool. The answer comes from governed context: spend is flat; one entity's invoices are missing since 02:00; here is the incident, the definition used and the model owner
08:34Copilot Studio agentThe director asks for the fix; the agent shows Data Workers' proposal and she confirms it in chat
08:35Data WorkersData Workers proposes a dbt diff adding 4100 to the seed, with its blast radius: two models, one Power BI semantic model and three reports
09:00SpellbookThe analytics engineer who owns the model reviews the diff and approves; dbt CI passes
09:20DatabricksData Workers reruns the job for the affected partitions; totals match SAP to the invoice
09:25Power BIThe spend report refreshes before the 10:00 review; the agent's next answer links the receipt
Incident timeline across the stack: what Copilot Studio, your team and Data Workers each do, step by step

The Spend Assistant did its job: it answered from the data it was given, and that data really did show a drop. What changed is that Data Workers was already on the break at 02:20, and the fix went through the same Teams chat the question came from, with one confirmation, one approval and one receipt.

JobWhat Copilot Studio doesWhat Data Workers does
The agentLets a maker build, test and publish it to Teams and Microsoft 365 CopilotGives it one governed data tool instead of a connector per system
The questionOrchestrates which topic, knowledge source or tool answers itSupplies the governed definition, lineage, owner and freshness behind the answer
The contextGrounds answers in SharePoint, files, connectors and Fabric data agentsKeeps one context graph across every platform current, with provenance
The breakRepeats what the data saysDetects the break and traces the cause across SAP, Data Factory, dbt and Databricks
The fixRuns only the tools a maker turned on, inside your data policiesProposes the change with its blast radius, routes it to a named approver, applies it reversibly
The proofAnalytics on agent performance and session outcomesVerifies downstream with checks and baselines on the changed tables and writes a receipt for the change
The guardrailsEnforces data policies on every connector and MCP serverSets autonomy per data domain on the ladder from L0 to L4

Why doesn't Copilot Studio just do this itself?

Because Microsoft built Copilot Studio for makers in every department, and it made sensible choices for that job. Copilot Studio is the builder and the client. The systems an agent calls belong to other vendors and to your data team, and Microsoft's documentation says so directly: when you connect to an external MCP server, "you're responsible for the tools and resources you access from within Copilot Studio."

That is the right design for a low-code product used by procurement, HR, sales and IT alike. Microsoft supplies the gates: data policies with Business, Non-business and Blocked groups, endpoint filtering, OAuth 2.0 so each person signs in as themselves, per-tool toggles on every MCP server, and admin approval before an agent reaches the whole organization. Writing to production data across Databricks, dbt, Data Factory and an SAP-fed pipeline is a different product category. It needs blast-radius scoping across systems Copilot Studio doesn't run, approvals routed to the people who own each model, rollback for every change class, receipts that tie a change to its cause, and liability for what happens inside tools Microsoft doesn't own.

Focus matters too. A maker who builds a spend agent shouldn't need to know which dbt seed filters company codes. Data Workers carries that knowledge, the change control and the evidence, so each maker stays a maker.

Every tool owns a slice. Data Workers covers the whole lifecycle

Copilot Studio owns one slice of the data lifecycle, and it owns it well: building agents that answer people where they work, inside a governed Power Platform. Each point tool adds another console, another contract and another handoff. Data Workers covers the whole lifecycle with one context, one approval flow and one audit trail, and builds on Copilot Studio where your makers already work.

Spider chart of ten jobs a data team does: Data Workers covers the whole list, Copilot Studio goes deep on its own area
StageData WorkersCopilot StudioWhy we scored it this way
Catalog & Context94Agents ground answers in knowledge sources (SharePoint, files, websites, connectors) and Fabric data agents. Data Workers keeps one governed context graph across warehouses, dbt, orchestration and BI.
Analytics & Insights88.5Copilot Studio's home stage: makers build agents that answer in Teams and Microsoft 365 Copilot, and Fabric data agents plug in as an MCP tool (listed GA in Fabric's August 2026 notes). Data Workers answers from governed definitions with lineage behind every number.
Data Quality82An agent can call a tool that runs a check if a maker wires one in. Data Workers writes, runs and repairs checks and dbt tests across the estate.
Observability & Incidents8.52.5Copilot Studio analytics track agent performance and session outcomes. Data Workers detects data breaks, traces them across systems, fixes and verifies them.
Pipelines & Ingestion8.53.5Workflows, agent flows and prebuilt or custom connectors automate business steps. Data Workers builds, reruns and backfills data pipelines behind approvals and verifies the output.
Schema & Migration82Copilot Studio reads the inputs and outputs a tool declares. Data Workers detects upstream schema changes, assesses blast radius and plans migrations in parity-checked waves.
Governance & Access8.56Strong over its own agents: end-user or maker credentials per tool, sharing, admin approval to publish org-wide. Data Workers proposes and applies least-privilege grants on your data platforms.
Security & Privacy88.5A second home stage: Power Platform data policies (Business, Non-business, Blocked), endpoint filtering and Entra authentication govern every connector and MCP server in real time. Data Workers leaves a receipt on every data change.
Cost / FinOps82.5Copilot Studio administration includes cost management for agents. Data Workers traces Snowflake credits to the dbt model behind them and drafts the fix for its owner.
MLOps & Models7.53Evaluations validate agent quality with test sets and graders before and after publishing. Data Workers keeps the data under your own models healthy and connects to MLflow and W&B.

How Copilot Studio and Data Workers work together

Copilot Studio stays on top, where makers build and where people ask and confirm in Teams and Microsoft 365 Copilot. Spellbook Data Catalog (in preview) is where the data team looks: each proposed change, who approved it, what it touched and how to roll it back. Between them, Data Context Wizard keeps one governed context graph, the Data-Agents Swarm does the work with more than 20 specialist agents, the Autonomous Data-Conductor runs each fix end to end (detect, diagnose, fix, review, verify, remember), and per-domain guardrails hold approvals, receipts and rollback.

How Data Workers fits with Copilot Studio: your coding agent on top, Data Workers in the middle, your estate underneath

Setup in Copilot Studio. Every Data Workers agent is an MCP server, and the same tools are served over Streamable HTTP for remote clients. That is the transport Copilot Studio supports (it stopped accepting SSE for MCP after August 2025), and the agent needs generative orchestration turned on. The maker steps, using the labels in Microsoft Learn this month:

  • •Open the agent, go to the Tools page and select Add a tool, then New tool, then Model Context Protocol. The MCP onboarding wizard opens.
  • •Fill in Server name, Server description and Server URL. Write the description carefully: the orchestrator reads it to decide when to call Data Workers.
  • •Choose OAuth 2.0 (Dynamic discovery if your identity provider supports dynamic client registration, otherwise Dynamic or Manual) or API key. Select Create, then Create a new connection, then Add to agent.
  • •On the server's settings page, turn off Allow all and enable only the read tools for now. With Allow all off, any new tool Data Workers adds stays off until a maker turns it on.
  • •Copilot Studio's tool settings also document an Ask the end user before running option (No by default). Where it appears for your MCP server, set it to Yes before enabling a write tool.
  • •Publish, then add the Teams and Microsoft Copilot channel. For an org-wide agent, submit it for admin approval.
Example: Data Workers in the Copilot Studio MCP onboarding wizard
Server name:         Data Workers
Server description:  Governed data context (definitions, lineage, owners,
                     freshness, incidents) and approved data fixes with receipts
Server URL:          https://<your-data-workers-host>/mcp   (Streamable HTTP)
Authentication:      OAuth 2.0 (Dynamic discovery or Manual, your Entra app)
Tools:               Allow all off; read tools on; one write class per domain later

For admins, nothing new to learn. The MCP server rides on a Power Platform connector, so the environment's data policy governs it: put the Data Workers connector in the Business group, and blocking it stops every agent at once. Teams that register MCP servers centrally can bring Data Workers in through Agent 365 and the Microsoft 365 admin center instead.

One request end to end, L0 to L4. The autonomy ladder is set per domain, and it maps onto Copilot Studio's own controls.

The autonomy ladder: L0 manual, L1 observe, L2 propose, L3 act reversibly, L4 autonomous
  • •L0 manual. The agent answers from its existing knowledge and connectors; your data team investigates breaks by hand.
  • •L1 observe. The Data Workers server is added with read tools only. Ask the Spend Assistant "why did logistics spend fall?" and the orchestrator calls Data Workers to resolve the metric definition, walk lineage, check load lag against its baseline and list open incidents.
  • •L2 propose. A maker turns on the proposal tools. Ask for the fix, confirm the proposal in chat, and Data Workers proposes a dbt diff with its blast radius. Nothing reaches production until the owner approves in Spellbook and CI passes.
  • •L3 act reversibly. For change classes with a proven record, such as reruns and backfills of failed partitions, Data Workers applies the change, re-runs the checks on the changed tables, with the undo recorded before it runs. The receipt is linked in the agent's answer.
  • •L4 autonomous. For a scoped domain like freshness failures in the spend marts, Data Workers fixes overnight without waiting for a question. In the morning, every agent answers from correct data and can show the receipt.

Each step up is a per-domain decision backed by receipts, and you can step back down at any time. For the full safety model, read is it safe to let AI agents change production data, and for where data and credentials live, read where does our data go.

The same server serves Microsoft 365 Copilot declarative agents and every other assistant, so the data team builds one integration: see you're on Microsoft 365 Copilot, you're on ChatGPT Enterprise and the hub, AI assistants are rolled out, now what. On Fabric, read Data Workers on Microsoft Fabric and Fabric data agents vs Data Workers.

What changes for your team

Copilot Studio gave every department the power to build an agent. Data Workers gives the data team a crew, so the agents built across the company don't turn into a queue of "is this number right?" tickets.

Six jobs that run on autopilot with Data Workers next to Copilot Studio, with a concrete example of each
  • •Incidents. Breaks are traced, fixed and verified overnight. The first person to ask any agent in the morning gets the right number.
  • •Data quality. Every break that reached an agent's answer becomes a check or a dbt test, so the same failure is caught upstream next time.
  • •Cloud spend. Snowflake credits are traced to the query and dbt model behind them, and each fix goes to its owner drafted.
  • •Access. "Can I see the margin table?" typed into an agent becomes a time-boxed grant proposal to the data owner, with the policy that justifies it.
  • •Audits. Power Platform governs the agent and its connectors. Data Workers holds the other half: who changed what in the data, why, what it touched and how to undo it.
  • •Migrations. Platform moves run in approved, parity-checked waves while every agent keeps answering against the same governed definitions.

Keep Copilot Studio, or consolidate?

Keep Copilot Studio if you love it; Data Workers works with it from day one. Many teams consolidate once Data Workers runs that slice too.

For most companies the answer is to keep it: it is where your makers build, inside the Power Platform governance your admins trust. What teams consolidate is the pile of one-off connectors and custom data tools each maker wired into each agent, replaced by one governed Data Workers tool, and often a separate data-quality and observability stack. If you are weighing whether to build this layer yourself on Copilot Studio's MCP support, read build it ourselves with Claude Code and MCP servers first; the MCP endpoint is the easy part, and the context graph, the approvals and the rollback are where the work is.

The case for your CFO

The outcome: the company already invested in Copilot Studio and a community of makers, and Data Workers makes the answers their agents give about the business correct, current and auditable. Every decision made from an agent in Teams rests on the data under it, and a successful maker program multiplies the number of agents reading that data.

The risk story has two locks. Power Platform admins decide through data policies whether the Data Workers connector is allowed at all, and makers decide which of its tools are on. Data Workers then sets autonomy per domain on the ladder from L0 manual to L4 autonomous, routes each change to a named approver, applies it reversibly, verifies it downstream and writes a receipt with who approved it, what it touched and how to undo it. There is zero migration: SAP, Databricks, dbt, Data Factory, Fabric and Power BI stay where they are.

Why now: agents are already live in Teams across departments, so a wrong number no longer reaches one analyst; it reaches every agent that reads it. The first win is one agent, such as the Spend Assistant, calling Data Workers read-only to answer "why does this number look wrong?" with lineage, owner, definition and open incidents, followed by one write class in one domain. What stays the same: environments, data policies, channels, admin approval, warehouse permissions and your dbt review process. For the numbers, see the ROI of agentic data operations. Start with a pilot (pricing); the pilot is credited in full against the first year.

The sentence to repeat upstairs: "Our makers build agents in Copilot Studio; Data Workers makes sure every one of them answers from governed numbers, and fixes the data when it isn't right, with an approval and a receipt."

Getting started

Start with a pilot. Pick one domain where a Copilot Studio agent already answers data questions, such as spend or sales pipeline, add Data Workers through the MCP onboarding wizard with read tools only, and run it for a few weeks before a maker enables the first write class. The pilot path and plans are on the pricing page, and the pilot is credited in full against the first year.

FAQ

Doesn't the Fabric data agent in Copilot Studio already do this? A Fabric data agent answers questions over its sources (lakehouse, warehouse, semantic model and more) with the asking user's permissions. Fabric's What's new lists its Copilot Studio integration as generally available in August 2026, while Microsoft's how-to for the connected-agent method still carries a preview label (both checked Oct 2, 2026). It answers from the data it is given. Data Workers keeps that data correct: it maintains the governed context, catches and fixes breaks and verifies the result, and many agents use both tools side by side. For Fabric IQ itself, see you're on Fabric IQ.

Will our data policies block Data Workers? Data policies treat the Data Workers MCP server like any Power Platform connector. Your admin places it in the Business group with the other connectors your agents use, and Copilot Studio enforces the policy in real time. If an admin later blocks it, every agent loses access to its tools at once, which is exactly the control most CoEs want.

Whose credentials does Data Workers use? Copilot Studio authenticates to Data Workers with OAuth 2.0 or an API key. With OAuth 2.0, each person signs in as themselves. Data Workers then acts on Databricks, dbt and orchestration with the connections you configure, scoped per domain, and its guardrails decide what each agent may change. Warehouse permissions stay the system of record, by design.

Is it safe to let a maker-built agent trigger writes to our data platform? Writes pass two locks. In Copilot Studio, with Allow all off, write tools stay off until a maker enables them, and data policies decide whether the connector runs at all. In Data Workers, each change has a blast radius, a named approver in Spellbook, a rollback path and a receipt, and autonomy is set per domain. Start read-only and add one write class at a time.

What happens when Data Workers adds new tools? Copilot Studio reflects MCP tool changes automatically. If you turn off Allow all on the server, new tools arrive switched off, and a maker turns each one on deliberately. Most data teams run it that way.

How many tools does this add to an agent? With generative orchestration, Copilot Studio supports up to 128 tools per agent and recommends 25 to 30 for best results. Data Workers enters as one MCP server, and you enable only the tools a given agent needs, so a spend agent might carry a handful of read tools and one proposal tool.

Sources

  • •Microsoft Learn, What is Copilot Studio (updated Sep 25, 2026), https://learn.microsoft.com/en-us/microsoft-copilot-studio/fundamentals-what-is-copilot-studio (checked Oct 2, 2026)
  • •Microsoft Learn, Extend your agent with Model Context Protocol (updated Aug 26, 2026), https://learn.microsoft.com/en-us/microsoft-copilot-studio/agent-extend-action-mcp (checked Oct 2, 2026)
  • •Microsoft Learn, Connect your agent to an existing MCP server (updated May 28, 2026), https://learn.microsoft.com/en-us/microsoft-copilot-studio/mcp-add-existing-server-to-agent (checked Oct 2, 2026)
  • •Microsoft Learn, Add tools and resources from an MCP server to your agent (updated Aug 19, 2026), https://learn.microsoft.com/en-us/microsoft-copilot-studio/mcp-add-components-to-agent (checked Oct 2, 2026)
  • •Microsoft Learn, Add tools to custom agents (updated Oct 1, 2026), https://learn.microsoft.com/en-us/microsoft-copilot-studio/add-tools-custom-agent (checked Oct 2, 2026)
  • •Microsoft Learn, Configure data policies for agents (updated Sep 25, 2026), https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention (checked Oct 2, 2026)
  • •Microsoft Learn, Use connectors in Copilot Studio agents (updated Aug 28, 2026), https://learn.microsoft.com/en-us/microsoft-copilot-studio/advanced-connectors (checked Oct 2, 2026)
  • •Microsoft Learn, Connect and configure an agent for Teams and Microsoft Copilot (updated Oct 1, 2026), https://learn.microsoft.com/en-us/microsoft-copilot-studio/publication-add-bot-to-microsoft-teams (checked Oct 2, 2026)
  • •Microsoft Learn, What's new in Microsoft Fabric (Fabric Data Agent integration with Microsoft Copilot Studio, Generally Available, August 2026; updated Sep 24, 2026), https://learn.microsoft.com/en-us/fabric/fundamentals/whats-new (checked Oct 2, 2026)
  • •Microsoft Learn, Consume a Fabric Data Agent in Microsoft Copilot Studio (preview label on the page; updated May 12, 2026), https://learn.microsoft.com/en-us/fabric/data-science/data-agent-microsoft-copilot-studio (checked Oct 2, 2026)
  • •Data Workers agent swarm repository (origin/main): README transports and packages/mcp-remote-transport (Streamable HTTP, OAuth and API-key auth), MLflow and W&B connectors (checked Oct 2, 2026)