generative orchestration
8 TopicsAll Copilot Studio Workflow Tools Suddenly Returning HTTP 403 Before Execution
Hello Copilot Studio Community, I am experiencing an authorization issue with multiple workflows connected to an agent built using the Copilot Studio new experience and new Workflows experience. These workflows worked successfully for multiple users yesterday. Today, all workflow tools connected to the agent began returning an immediate HTTP 403 authorization error. I did not intentionally change the agent, workflows, environment, or workflow permissions before the issue started. Error message: You don’t have permission to use this tool. You’re signed in, but access to this resource is blocked. Error details: Authorization - 403 Example error information: Status: Failed Error message: Flow returned HTTP 403 Error code: Http403 Inner error code: NotSpecified Tool duration: Approximately 93 milliseconds Configuration: - Copilot Studio new agent experience - Copilot Studio new Workflows experience - Agent and workflows are in the same Power Platform environment - Workflows use the "When an agent calls the workflow" trigger - Each workflow includes a "Respond to the agent" action - Workflows are saved and published - Agent is saved and published Observed behavior: The problem affects several independent workflows, including: - New-request submission - Current-user identity resolution - Approval decisions - Requester justification - Executive decisions - Fulfillment updates For every affected workflow: - The agent fills the workflow inputs correctly. - The tool call fails almost immediately. - No corresponding run appears in the workflow Activity history. - The workflow trigger is never reached. - No workflow actions execute. Because no workflow run is created, the rejection appears to occur before workflow execution, possibly within the Copilot Studio agent-to-workflow authorization or invocation layer. Troubleshooting already completed: - Confirmed that all workflows are published. - Confirmed that the agent is published. - Tested in a completely new conversation. - Removed an affected workflow tool from the agent. - Saved the agent. - Added the same published workflow back to the agent. - Reconfigured and verified the tool inputs. - Republished the agent. - Confirmed that no workflow Activity run is created. - Confirmed that the issue affects multiple workflows rather than one specific workflow. Removing and re-adding the workflow did not resolve the problem. Questions for the community: 1. Is anyone else currently experiencing HTTP 403 errors when Copilot Studio agents invoke workflows? 2. Is this a known issue or regression in the new Workflows experience? 3. Is there an environment-level or tenant-level permission that controls agent-to-workflow invocation? 4. Could a tenant policy, Conditional Access change, service principal, connection reference, or workflow-sharing configuration cause all workflow tools to fail simultaneously? 5. Where can an administrator find detailed authorization logs when the workflow never creates a run? 6. Has anyone found a workaround for this issue? Any guidance or confirmation from others experiencing the same behavior would be appreciated. I can provide screenshots, complete error details, timestamps, and additional configuration information if needed. Thank you.95Views1like1CommentDesigning a Governed RTO Compliance Agent Using Copilot Studio and Databricks Genie
Enterprise AI adoption in HR scenarios comes with a unique challenge: how do you deliver actionable insights without compromising privacy, trust, or policy boundaries? In this blog, I’ll share how we built an RTO (Return‑to‑Office) Compliance Agent using Microsoft Copilot Studio and Databricks Genie, focusing on governance‑first design, controlled data access, and real‑world enterprise constraints. This solution was developed as part of an HRLT proof‑of‑value initiative and is designed to support people managers with clear, aggregated compliance insights, delivered conversationally inside Microsoft Teams. The Problem We Were Solving As hybrid work models mature, organizations need a reliable way to answer questions such as: How compliant is my team with RTO expectations? Are there trends across regions or time periods? Traditional dashboards often fall short because they: Require manual interpretation Expose too much granular data Are difficult to govern at scale Our objective was to create an AI‑powered conversational interface that provides: Only manager‑authorized, aggregated insights Zero visibility into individual‑level behavior Built‑in enforcement of HR and privacy policies Architecture Overview The solution integrates Copilot Studio with Databricks Genie, backed by curated data sources. (Image: High-level Copilot Studio and Databricks Genie architecture) Key Components Copilot Studio – Conversational orchestration, policy enforcement, and Teams deployment Databricks Genie – Governed natural-language interface to curated datasets RokFusion Platform – Trusted HR and badge-swipe data This layered approach ensures governance is applied before data is ever queried. Controlled End-to-End Data Flow The interaction pattern follows a strict, auditable flow: A manager asks a question in Copilot Studio Copilot forwards the request to Genie with instruction constraints Genie executes logic only on curated, approved tables Calculations are performed at team or manager level only Copilot formats and returns compliant responses (text, tables, or charts) At no point are employee IDs, badge events, or individual metrics exposed. Using Genie as a Governance Layer, Not Just a Query Tool One of the most critical decisions was to treat Databricks Genie as a policy‑enforcement layer, not merely a natural‑language SQL generator. (Image: Genie instruction configuration enforcing compliance rules) What We Configured in Genie Synonyms and NL mappings for HR terminology Strict filtering logic for employee categories Population threshold enforcement (minimum count) Explicit rejection of sensitive attributes such as gender, race, religion, or age Prevention of formula or row‑level data exposure This approach ensured that even malformed or risky prompts could not bypass policy constraints. Compliance Scenarios Supported The agent supports multiple business‑aligned interpretations of RTO compliance: Hybrid Compliance Hybrid employees counted only on eligible hybrid days Onsite Compliance Onsite employees counted across standard working days All Employees View Weighted aggregation combining hybrid and onsite logic These scenarios are embedded into the agent’s instruction logic, not dynamically inferred at runtime—ensuring consistency and auditability. Why We Chose Conversational AI Over Dashboards A key insight early on was that managers don’t want spreadsheets—they want answers. Instead of navigating filters and charts, managers can ask: “What was my team’s compliance last week?” “Show me a comparison across regions.” When required, the agent can also render simple visual outputs. (Image: Sample Microsoft Teams output with compliance visualization) Importantly, visuals follow the same governance rules as text responses. Publishing and Validation in Microsoft Teams Once configured, the agent was published directly from Copilot Studio to Microsoft Teams, making adoption frictionless. (Image: Publishing Copilot Studio agent to Microsoft Teams) End‑to‑end testing validated: Authorization boundaries Population rules Safe handling of incomplete or ambiguous queries Key Engineering Learnings Governance must be instruction‑driven Relying on frontend filtering alone is insufficient for HR data. Natural language needs strong guardrails Enterprise AI benefits from being constrained, not free‑form. Aggregation builds trust Managers are more comfortable with insights when they know individual visibility is impossible. Copilot Studio accelerates enterprise delivery Security, deployment, and integration stay within the Microsoft ecosystem. Closing Thoughts This RTO Compliance Agent demonstrates how Copilot Studio and Databricks Genie can be used to build governed, enterprise‑ready AI solutions—especially in sensitive domains like HR. By embedding policy into architecture, instructions, and data access, we were able to deliver: Useful insights Strong privacy guarantees High user trust This pattern is extensible well beyond RTO—opening the door for future HR intelligence use cases built on the same foundation.255Views1like1Comment