Which agents does Sentinel cover?
Custom Copilot Studio agents across your tenant, plus Microsoft 365 Copilot. Each agent is inventoried and scored, and its sessions, tools, topics, and errors are pulled into the same console as your data-risk posture.
What drives an agent's risk score?
Reach (how many people and channels it touches), tool and connector access, credential hygiene (for example an aging application secret), and reliability. As with data risk, the numeric score is deterministic and the factor breakdown is shown.
What can Sentinel actually do about a risky agent?
Admins can block or unblock specific users from an agent, and quarantine an agent outright. Every action is gated by an admin role and written to an audit log - Sentinel surfaces risk and executes approved controls, it doesn't act on its own.
How does safety-incident tracking work?
Sentinel collects responsible-AI events - blocked responses, content-filter hits, and policy violations - and classifies them so you review evidence, not anecdotes. You can filter by agent, channel, and error code to investigate a spike.