← Back to blog·Trends·4 min read

Microsoft Gave Its Copilot Agent a Directory Identity, Claude Went to FedRAMP High, and Approval Gates Became a Product Feature

Microsoft revamped Copilot with Code and an always-on Autopilot agent that carries its own directory identity, Anthropic brought Claude to government under FedRAMP High, and low-code platforms like UiPath added tool-call confirmations. Three signs that identity, compliance and human approval are becoming core chatbot infrastructure.

By Maya Brennan · Writer, Smillee AI
October 3, 2026

The newest chatbot announcements are less about smarter answers and more about the plumbing around them: who an agent is, what it is allowed to touch, and when a person must say yes. Three recent stories show the same shift.

1. Autopilot: An Agent With a Name in the Directory

On September 25 Microsoft unveiled a revamped Copilot app. Two pieces stand out. "Code" lets users build apps and dashboards from natural-language prompts, using the same technology as GitHub Copilot, with early access at the end of the month and previews for 365 Premium and Pro subscribers later this year. "Autopilot" is an updated version of the Scout agent shown in June, entering private preview around the same time.

The detail worth a builder's attention is how Autopilot is described: a "digital coworker" that carries its own identity in the company directory, with specific permissions users can control. We are relying on wire-service summaries here, so exact rollout terms may differ.

Giving an agent its own identity, instead of letting it borrow a user's session, is the right default. It makes actions attributable, permissions revocable and audit trails readable. If your assistant calls tools with the end user's token, you cannot tell afterward whether a person or the agent did something, and you cannot narrow the agent's rights without narrowing the person's.

2. Claude for Government: Compliance as a Distribution Channel

Anthropic's Claude for Government platform is authorized at the FedRAMP High level, with the authorization held through Palantir's FedStart program and independent assessment by Schellman. At a September 9 event, Anthropic's head of public sector said its latest model was available there and that the desktop product, including Claude Code and Cowork, would move from public beta toward general availability in the coming weeks. One weekly roundup describes general availability as already announced; we could not confirm that, so check the current status before relying on it.

For teams selling chatbots into regulated sectors, the lesson is that the model is only one line in a procurement checklist. Data handling, authorization boundaries and auditability decide whether a pilot ever reaches production. If you expect to sell into government, healthcare or finance, log retention, regional processing and a clear subprocessor list are product work to schedule now, not paperwork to do later.

3. Approval Gates Go Mainstream

UiPath's July 2026 release notes for conversational agents added tool-call confirmations: a tool can be configured to pause before it runs so the user can review, approve, modify or reject the proposed inputs. The same release let inputs be templated into the system prompt and tool arguments and updated mid-conversation.

This is the human-in-the-loop pattern turning into a checkbox. A minimal version in your own stack looks like this:

type ToolCall = { name: string; args: Record<string, unknown> };

const NEEDS_APPROVAL = new Set(['send_email', 'issue_refund', 'delete_record']);

async function runTool(call: ToolCall, ask: (c: ToolCall) => Promise<ToolCall | null>) {
  if (!NEEDS_APPROVAL.has(call.name)) return execute(call);
  const approved = await ask(call); // user may edit args or return null to reject
  return approved ? execute(approved) : { status: 'rejected_by_user' };
}

Return the rejection to the model as a tool result so it can explain or propose an alternative, rather than silently dropping the call. A good visual for this section is a screenshot of the confirmation card showing the proposed arguments next to Approve, Edit and Reject buttons.

Conclusion

Identity, authorization and approval are no longer extras bolted on after the demo. Give agents their own credentials, treat compliance as a feature with a roadmap, and gate irreversible actions behind a human decision. The assistants that earn enterprise trust will be the ones whose behavior you can attribute, bound and audit.

— Maya

Frequently asked questions

What is Microsoft Copilot Autopilot?

An always-on agent in the revamped Copilot app, an update of the Scout agent shown in June. Microsoft describes it as a digital coworker with its own identity in the company directory and permissions users can control. Reporting says private preview begins at the end of September 2026.

Why should an AI agent have its own identity?

A separate identity makes the agent's actions attributable in audit logs and lets you grant or revoke its permissions without affecting the human user. Borrowing the user's session hides who did what and forces all-or-nothing access.

What is a tool-call confirmation in a chatbot?

A pause before a tool runs, where the user can review, approve, modify or reject the proposed parameters. It is typically applied to irreversible or high-impact actions such as sending messages, issuing refunds or deleting data.

Maya Brennan
Writer, Smillee AI

I'm Maya — I write most of what you'll read here. I spent years as a copywriter before I got a little obsessed with what these AI tools can actually do, so now I spend my days poking at chatbots, breaking them, and writing up what's worth your time. Everything here is something I've actually tried. If a prompt didn't work for me, it doesn't make the cut.

Want to try any of this?

Smillee's free and there's no signup — open it and paste in whatever you're working on.

Try it free: AI Coding Helper →

More from the blog