1
00:00:00,000 --> 00:00:06,320
Here is the promise we were all given. Artificial intelligence was going to democratize every piece of information in your company.

2
00:00:06,320 --> 00:00:12,560
It would close the gap between having data and making a decision. Teams would move faster. Compliance would be a breeze.

3
00:00:12,560 --> 00:00:18,320
Your organization would finally turn years of hidden knowledge into a massive competitive advantage.

4
00:00:18,320 --> 00:00:21,280
That was the pitch, and that is why you signed the checks for the licenses.

5
00:00:21,280 --> 00:00:26,640
But here is what is actually happening. Your teams are spending more time engineering prompts than actually doing their jobs.

6
00:00:26,640 --> 00:00:33,280
They ask co-pilot a question, they get back a massive wall of text, then they have to navigate back to SharePoint to find the source document.

7
00:00:33,280 --> 00:00:38,960
They jump over to Excel to pull the numbers, they switch to Outlook to send the final approval, somewhere in all that switching.

8
00:00:38,960 --> 00:00:43,280
The efficiency just evaporates, the problem isn't the AI itself, the problem is the interface.

9
00:00:43,280 --> 00:00:46,880
We have built the wrong model for how intelligence should work inside a business.

10
00:00:46,880 --> 00:00:52,560
We took the chatbot idea from consumer apps, text in, text out, and we dropped it into complex business processes.

11
00:00:52,560 --> 00:00:56,240
We never stopped to ask if a text box is the right way to get work done.

12
00:00:56,240 --> 00:00:59,760
It isn't, and the structural cost of that mistake is forcing a change.

13
00:00:59,760 --> 00:01:01,760
On July 1st, the math changes for everyone.

14
00:01:01,760 --> 00:01:04,720
Microsoft 365 base prices are going up.

15
00:01:04,720 --> 00:01:10,400
Even more importantly, the co-pilot features currently sitting inside your apps are moving behind a license gate.

16
00:01:10,400 --> 00:01:17,120
SPFX version 1.24 hits preview in a few weeks, bringing the first real alternative to this chat first world.

17
00:01:17,120 --> 00:01:22,640
By the end of 2026, the shift from chat as an interface to actions as an interface will be the only way forward.

18
00:01:22,640 --> 00:01:28,160
By the end of this video, you will see why the shift is a structural necessity rather than just another feature update.

19
00:01:28,160 --> 00:01:32,800
You will see how the company's preparing right now will be operating 18 months ahead of everyone else.

20
00:01:32,800 --> 00:01:37,040
And you will understand exactly what has to change in your governance model to make it work.

21
00:01:37,040 --> 00:01:39,360
The chatbox bottleneck.

22
00:01:39,360 --> 00:01:41,520
We have to start with a fundamental misdiagnosis.

23
00:01:41,520 --> 00:01:45,840
The story we're told about co-pilot is that text is efficient, we're told it's high density.

24
00:01:45,840 --> 00:01:49,680
You can ask a question in 20 words and get back 200 words of perfect context.

25
00:01:49,680 --> 00:01:52,400
That feels like speed, but in reality, it's the opposite.

26
00:01:52,400 --> 00:01:57,280
That efficiency is great for the machine, but it's a disaster for the human trying to finish a task.

27
00:01:57,280 --> 00:01:59,360
Think about the actual pattern in your office.

28
00:01:59,360 --> 00:02:02,640
A user in your operations team needs to approve a purchase order.

29
00:02:02,640 --> 00:02:03,840
They open co-pilot.

30
00:02:03,840 --> 00:02:07,040
They ask for the status of requisition 47382.

31
00:02:07,040 --> 00:02:11,120
Co-pilot gives them a clean paragraph with the order details, the approval chain and the timeline.

32
00:02:11,120 --> 00:02:14,160
The user reads it, they understand it, but then what?

33
00:02:14,160 --> 00:02:17,840
They still have to navigate back to the procurement system to click the approve button.

34
00:02:17,840 --> 00:02:22,000
If that requisition lives in a SharePoint list, they have to go search for it all over again.

35
00:02:22,000 --> 00:02:23,280
The text didn't finish the job.

36
00:02:23,280 --> 00:02:26,880
It just created a parallel track that the human now has to manually fix.

37
00:02:26,880 --> 00:02:31,040
When you multiply that by every user and every task, you see the real cost.

38
00:02:31,040 --> 00:02:32,640
This is the friction we aren't measuring.

39
00:02:32,640 --> 00:02:37,200
Every time someone jumps from a chat window to an action, they are burning mental energy.

40
00:02:37,200 --> 00:02:38,720
They are leaving the flow of their work.

41
00:02:38,720 --> 00:02:42,960
If you actually track the time from, "I need to do this too," this is finished.

42
00:02:42,960 --> 00:02:44,240
The bottleneck isn't the question.

43
00:02:44,240 --> 00:02:45,680
It's the jumping between systems.

44
00:02:45,680 --> 00:02:47,440
The chat was supposed to stop the searching.

45
00:02:47,440 --> 00:02:48,720
Instead, it just moved it.

46
00:02:48,720 --> 00:02:52,320
In regulated industries, this turns into a compliance nightmare.

47
00:02:52,320 --> 00:02:55,520
Every prompt is a new record to track every time a user switches context,

48
00:02:55,520 --> 00:02:57,360
you create a gap in the audit trail.

49
00:02:57,360 --> 00:03:00,880
When an employee manually matches what Copilot said with what the system shows,

50
00:03:00,880 --> 00:03:02,560
you've hit a control failure.

51
00:03:02,560 --> 00:03:04,240
You are paying for high-level intelligence,

52
00:03:04,240 --> 00:03:06,240
but running it through a broken structure.

53
00:03:06,240 --> 00:03:09,040
In operations, every small delay starts to add up.

54
00:03:09,040 --> 00:03:12,640
A decision that takes 10 minutes to reach should only take 3 minutes to finish.

55
00:03:12,640 --> 00:03:16,000
If it takes 10 minutes just to navigate to the right screen and execute,

56
00:03:16,000 --> 00:03:17,600
you've killed the value of the AI.

57
00:03:17,600 --> 00:03:18,960
You haven't solved the bottleneck.

58
00:03:18,960 --> 00:03:20,320
You've just built a new one.

59
00:03:20,320 --> 00:03:23,760
The core issue is that we've borrowed the model from chat GPT and Gemini.

60
00:03:23,760 --> 00:03:27,120
Those systems were built for individuals asking questions for personal use.

61
00:03:27,120 --> 00:03:30,000
When we dropped that model into the enterprise without asking if it fit,

62
00:03:30,000 --> 00:03:30,640
it doesn't.

63
00:03:30,640 --> 00:03:34,400
And that realization is what should be changing your entire architecture right now.

64
00:03:34,400 --> 00:03:36,640
Permission magnification, not a new risk.

65
00:03:36,640 --> 00:03:38,560
The security conversation needs a reframe.

66
00:03:38,560 --> 00:03:40,720
Most people think Copilot creates new risks.

67
00:03:40,720 --> 00:03:42,320
They think it's a data leakage vector.

68
00:03:42,320 --> 00:03:44,400
They think you have to shut it down or restrict it,

69
00:03:44,400 --> 00:03:46,960
because it might expose things you never intended to share.

70
00:03:46,960 --> 00:03:48,240
That narrative is wrong.

71
00:03:48,240 --> 00:03:50,080
It's a symptom of a deeper misunderstanding.

72
00:03:50,080 --> 00:03:52,000
Copilot doesn't create security risks.

73
00:03:52,000 --> 00:03:54,560
It exposes permission problems that already existed.

74
00:03:54,560 --> 00:03:58,000
And that distinction changes everything about how you approach this.

75
00:03:58,000 --> 00:03:59,520
Here is how it actually works.

76
00:03:59,520 --> 00:04:02,720
Copilot uses the same security trimming as SharePoint Search,

77
00:04:02,720 --> 00:04:05,520
the same filtering logic, the same access control model.

78
00:04:05,520 --> 00:04:07,120
When you ask Copilot a question,

79
00:04:07,120 --> 00:04:09,600
it isn't pulling data from outside your tenant boundary.

80
00:04:09,600 --> 00:04:11,600
It queries the same index that Search uses

81
00:04:11,600 --> 00:04:13,840
and that index respects your existing permissions.

82
00:04:13,840 --> 00:04:14,640
Full stop.

83
00:04:14,640 --> 00:04:18,080
A user cannot see content in Copilot that they couldn't see in Search.

84
00:04:18,080 --> 00:04:20,720
They cannot access a document through the AI

85
00:04:20,720 --> 00:04:22,880
that they wouldn't be able to open manually.

86
00:04:22,880 --> 00:04:25,440
Technically, Copilot isn't a new access vector.

87
00:04:25,440 --> 00:04:27,040
It's using the one you already have.

88
00:04:27,040 --> 00:04:28,880
But here is the amplification effect.

89
00:04:28,880 --> 00:04:30,880
And this is where the real conversation starts.

90
00:04:30,880 --> 00:04:34,720
If your SharePoint has anyone with the link shares on sensitive files,

91
00:04:34,720 --> 00:04:36,480
Copilot doesn't change that.

92
00:04:36,480 --> 00:04:37,920
That problem was already there,

93
00:04:37,920 --> 00:04:39,360
but the discovery time changes.

94
00:04:39,360 --> 00:04:42,400
Copilot makes that data discoverable in seconds instead of hours.

95
00:04:42,400 --> 00:04:45,040
Someone asks a natural language question.

96
00:04:45,040 --> 00:04:46,960
What are our contract terms with Acme?

97
00:04:46,960 --> 00:04:49,440
Find me the competitor analysis from Q3.

98
00:04:49,440 --> 00:04:50,880
They don't need to know the site name.

99
00:04:50,880 --> 00:04:52,640
They don't need the library path.

100
00:04:52,640 --> 00:04:54,480
They don't need to understand the document structure.

101
00:04:54,480 --> 00:04:55,760
They just get an answer instantly.

102
00:04:55,760 --> 00:04:57,120
Is Copilot the problem?

103
00:04:57,120 --> 00:04:57,840
No.

104
00:04:57,840 --> 00:04:59,600
The problem is that someone could share a document

105
00:04:59,600 --> 00:05:01,200
with anyone in the first place.

106
00:05:01,200 --> 00:05:02,800
Copilot didn't create that risk.

107
00:05:02,800 --> 00:05:04,240
It just made it visible.

108
00:05:04,240 --> 00:05:05,680
Architects usually miss this.

109
00:05:05,680 --> 00:05:07,680
They see Copilot surfacing sensitive data

110
00:05:07,680 --> 00:05:08,480
and they blame the tool.

111
00:05:08,480 --> 00:05:09,840
So they restrict access.

112
00:05:09,840 --> 00:05:12,000
They block sites from being indexed.

113
00:05:12,000 --> 00:05:14,400
They treat the symptom, but they don't fix the disease.

114
00:05:14,400 --> 00:05:17,840
The structural flaw is that most organizations have flat permissions.

115
00:05:17,840 --> 00:05:19,840
But hierarchical compliance requirements.

116
00:05:19,840 --> 00:05:21,440
Flat permissions look like this.

117
00:05:21,440 --> 00:05:23,760
You have a site called shared resources.

118
00:05:23,760 --> 00:05:25,600
Everyone in the department can access it.

119
00:05:25,600 --> 00:05:27,200
Everyone can see every folder.

120
00:05:27,200 --> 00:05:28,560
Everyone can edit documents.

121
00:05:28,560 --> 00:05:29,280
It's open.

122
00:05:29,280 --> 00:05:30,400
It's collaborative.

123
00:05:30,400 --> 00:05:32,080
And in a certain context, it makes sense.

124
00:05:32,080 --> 00:05:34,000
hierarchical compliance looks different.

125
00:05:34,000 --> 00:05:36,240
Some documents in that site are contract terms.

126
00:05:36,240 --> 00:05:37,760
Only legal should see those.

127
00:05:37,760 --> 00:05:39,760
Some are budget-focused for finance.

128
00:05:39,760 --> 00:05:41,520
Some are employee records for HR.

129
00:05:41,520 --> 00:05:44,560
But they all live in the same site with the same flat permission model.

130
00:05:44,560 --> 00:05:46,720
This gap is what Copilot makes visible.

131
00:05:46,720 --> 00:05:49,040
It's the distance between how you structured permissions

132
00:05:49,040 --> 00:05:51,360
and what your governance actually requires.

133
00:05:51,360 --> 00:05:54,160
When Copilot surfaces budget data to an individual contributor,

134
00:05:54,160 --> 00:05:55,760
the reflex is to blame the AI.

135
00:05:55,760 --> 00:05:58,400
The actual fix is to go back and restructure your permissions.

136
00:05:58,400 --> 00:06:01,520
You have to enforce compliance at the site and library level.

137
00:06:01,520 --> 00:06:03,280
Not assume it at the behavioral level.

138
00:06:03,280 --> 00:06:05,520
This is why the licensing change matters so much.

139
00:06:05,520 --> 00:06:07,920
Organizations with messy permissions will see Copilot

140
00:06:07,920 --> 00:06:09,120
and think it's too risky.

141
00:06:09,120 --> 00:06:10,640
Organizations with clean permissions

142
00:06:10,640 --> 00:06:13,680
will see Copilot and think it's their primary interface for work.

143
00:06:13,680 --> 00:06:14,720
One group blocks it.

144
00:06:14,720 --> 00:06:15,920
One group accelerates it.

145
00:06:15,920 --> 00:06:19,760
And that decision determines which group you're in by 2027.

146
00:06:19,760 --> 00:06:22,320
The July 1st cliff, licensing is architecture.

147
00:06:22,320 --> 00:06:24,880
What's happening on July 1st isn't just a price adjustment.

148
00:06:24,880 --> 00:06:27,520
It's the moment when licensing becomes a statement

149
00:06:27,520 --> 00:06:29,680
about how you architect AI into your business.

150
00:06:29,680 --> 00:06:30,640
Two things happen at once.

151
00:06:30,640 --> 00:06:33,120
Microsoft 365 base plan prices increase.

152
00:06:33,120 --> 00:06:35,760
E3 goes from $36 to $39.

153
00:06:35,760 --> 00:06:39,600
Business standard goes from $12.50 to $14.

154
00:06:39,600 --> 00:06:41,280
At scale, those numbers add up.

155
00:06:41,280 --> 00:06:44,160
But the pricing changes secondary to what happens to the features.

156
00:06:44,160 --> 00:06:45,920
Right now, if you have a Microsoft license,

157
00:06:45,920 --> 00:06:47,520
you get some AI assistance.

158
00:06:47,520 --> 00:06:48,320
It's limited.

159
00:06:48,320 --> 00:06:50,000
It's often in preview, but it's there.

160
00:06:50,000 --> 00:06:51,600
Starting July 1st, that changes.

161
00:06:51,600 --> 00:06:54,880
Users without an explicit $30 per month Copilot license

162
00:06:54,880 --> 00:06:56,160
lose the embedded AI.

163
00:06:56,160 --> 00:06:57,440
It disappears from Word.

164
00:06:57,440 --> 00:06:59,920
It disappears from Excel, PowerPoint, and OneNote.

165
00:06:59,920 --> 00:07:01,360
And it extends to SharePoint.

166
00:07:01,360 --> 00:07:03,360
If you rely on Copilot for list management

167
00:07:03,360 --> 00:07:04,800
or document workflows,

168
00:07:04,800 --> 00:07:07,440
that feature vanishes for anyone without the paid seat.

169
00:07:07,440 --> 00:07:09,520
Microsoft calls these premium features

170
00:07:09,520 --> 00:07:10,800
that's the marketing.

171
00:07:10,800 --> 00:07:11,520
Pay more.

172
00:07:11,520 --> 00:07:12,560
Get the better version.

173
00:07:12,560 --> 00:07:14,080
But the structural reality is different.

174
00:07:14,080 --> 00:07:15,360
This isn't about feature tiers.

175
00:07:15,360 --> 00:07:18,400
This is about declaring who operates inside the agent fabric.

176
00:07:18,400 --> 00:07:19,600
And who operates outside it?

177
00:07:19,600 --> 00:07:21,360
Think about what that means for your operations.

178
00:07:21,360 --> 00:07:22,880
You have a thousand person organization.

179
00:07:22,880 --> 00:07:26,640
Maybe 30% of those people do work that actually benefits from AI.

180
00:07:26,640 --> 00:07:28,320
The decision makers, the operators,

181
00:07:28,320 --> 00:07:29,920
the people managing workflows.

182
00:07:29,920 --> 00:07:32,400
For a thousand person org, that's 300 people.

183
00:07:32,400 --> 00:07:36,960
Licensing 30% of your staff at $30 a month is $108,000 a year.

184
00:07:36,960 --> 00:07:38,400
That's a budget conversation.

185
00:07:38,400 --> 00:07:39,840
But you aren't just buying a feature.

186
00:07:39,840 --> 00:07:41,920
You aren't even buying access to Copilot.

187
00:07:41,920 --> 00:07:43,920
You are declaring an architectural boundary.

188
00:07:43,920 --> 00:07:45,760
You're saying these 300 people work in a world

189
00:07:45,760 --> 00:07:48,000
where AI is integrated into their tools.

190
00:07:48,000 --> 00:07:51,600
The other 700 work in a world where AI is optional.

191
00:07:51,600 --> 00:07:52,560
Or peripheral.

192
00:07:52,560 --> 00:07:53,200
Or off limits.

193
00:07:53,200 --> 00:07:54,640
That's a governance decision.

194
00:07:54,640 --> 00:07:56,320
And it shapes everything downstream.

195
00:07:56,320 --> 00:07:58,000
Once you decide who gets the license,

196
00:07:58,000 --> 00:07:59,200
everything else follows.

197
00:07:59,200 --> 00:08:00,880
If operation staff have Copilot,

198
00:08:00,880 --> 00:08:02,320
but customer service doesn't,

199
00:08:02,320 --> 00:08:03,840
they are using different tooling.

200
00:08:03,840 --> 00:08:05,760
If project managers have AI in Excel,

201
00:08:05,760 --> 00:08:08,240
but their teams don't, you've created asymmetry.

202
00:08:08,240 --> 00:08:10,960
That asymmetry either becomes a competitive advantage

203
00:08:10,960 --> 00:08:12,480
or it fragments into friction.

204
00:08:12,480 --> 00:08:15,040
It all depends on how you architect the handoff points.

205
00:08:15,040 --> 00:08:16,880
Organizations that haven't thought about this

206
00:08:16,880 --> 00:08:18,560
will hit July 1st and react.

207
00:08:18,560 --> 00:08:20,400
They will either buy too many licenses

208
00:08:20,400 --> 00:08:22,320
or they will restrict it more than they should.

209
00:08:22,320 --> 00:08:23,760
Then they'll live with those consequences

210
00:08:23,760 --> 00:08:26,240
for 18 months while they try to find the right model.

211
00:08:26,240 --> 00:08:28,400
The organization is thinking about this now.

212
00:08:28,400 --> 00:08:29,440
Move differently.

213
00:08:29,440 --> 00:08:31,760
They see licensing as an architecture decision.

214
00:08:31,760 --> 00:08:32,560
Not a cost decision.

215
00:08:32,560 --> 00:08:34,880
They've mapped which workflows need embedded AI.

216
00:08:34,880 --> 00:08:36,880
They have clarity on their governance boundaries.

217
00:08:36,880 --> 00:08:38,560
They understand that the licensing choices

218
00:08:38,560 --> 00:08:40,720
the constraint that forces discipline.

219
00:08:40,720 --> 00:08:42,640
This moment matters because it reveals the shift

220
00:08:42,640 --> 00:08:44,000
in how enterprises operate.

221
00:08:44,000 --> 00:08:45,520
The change isn't arbitrary.

222
00:08:45,520 --> 00:08:48,400
It's the inflection point where chat stops being an option

223
00:08:48,400 --> 00:08:50,320
and becomes a declared operational boundary.

224
00:08:50,320 --> 00:08:53,520
Beyond text, the headless UI model.

225
00:08:53,520 --> 00:08:55,520
If the diagnosis is that chat is a bottleneck,

226
00:08:55,520 --> 00:08:57,920
the question becomes, what is the alternative?

227
00:08:57,920 --> 00:08:59,520
The answer isn't better chat.

228
00:08:59,520 --> 00:09:01,200
It is not about optimizing prompts

229
00:09:01,200 --> 00:09:03,040
or training people to ask smarter questions

230
00:09:03,040 --> 00:09:04,560
or getting faster response times.

231
00:09:04,560 --> 00:09:06,320
The answer is to stop relying on text

232
00:09:06,320 --> 00:09:08,080
to be the interface for action.

233
00:09:08,080 --> 00:09:09,520
Let me reframe what is actually happening

234
00:09:09,520 --> 00:09:11,040
with SharePoint co-pilot apps.

235
00:09:11,040 --> 00:09:12,960
This isn't about adding a feature to co-pilot.

236
00:09:12,960 --> 00:09:15,680
This is about fundamentally changing the interaction model.

237
00:09:15,680 --> 00:09:17,600
In the old way, a user asks a question,

238
00:09:17,600 --> 00:09:18,720
co-pilot returns text,

239
00:09:18,720 --> 00:09:20,800
and the user then has to navigate to a system

240
00:09:20,800 --> 00:09:22,960
to manually act on that text.

241
00:09:22,960 --> 00:09:24,160
The new model looks like this.

242
00:09:24,160 --> 00:09:25,680
A user asks a question,

243
00:09:25,680 --> 00:09:28,080
co-pilot surfaces an interactive component,

244
00:09:28,080 --> 00:09:30,400
a form, a button, or a dashboard,

245
00:09:30,400 --> 00:09:32,160
directly in the chat canvas,

246
00:09:32,160 --> 00:09:34,160
and the user interacts with that component

247
00:09:34,160 --> 00:09:35,760
so the action happens in context.

248
00:09:36,240 --> 00:09:37,360
That is the shift.

249
00:09:37,360 --> 00:09:39,440
That is what beyond text actually means.

250
00:09:39,440 --> 00:09:42,560
The technology enabling this is SharePoint co-pilot apps

251
00:09:42,560 --> 00:09:45,040
which enters preview in July of 2026.

252
00:09:45,040 --> 00:09:47,760
What it does is let SharePoint framework components,

253
00:09:47,760 --> 00:09:49,920
web parts you have already built for your internet,

254
00:09:49,920 --> 00:09:50,880
your dashboards,

255
00:09:50,880 --> 00:09:52,720
and your list management interfaces

256
00:09:52,720 --> 00:09:55,440
render directly inside the co-pilot canvas.

257
00:09:55,440 --> 00:09:58,160
These are not static images or pre-formatted responses.

258
00:09:58,160 --> 00:09:59,520
These are interactive components

259
00:09:59,520 --> 00:10:01,680
where you can click a button, fill out a form,

260
00:10:01,680 --> 00:10:03,840
approve something, or update a status,

261
00:10:03,840 --> 00:10:05,440
and all of that happens in line

262
00:10:05,440 --> 00:10:07,120
without leaving the conversation.

263
00:10:07,120 --> 00:10:08,160
Why does this matter?

264
00:10:08,160 --> 00:10:11,280
Because it collapses the distance between decision and action.

265
00:10:11,280 --> 00:10:13,440
Right now, if someone asks co-pilot,

266
00:10:13,440 --> 00:10:15,280
what is the status of this project?

267
00:10:15,280 --> 00:10:17,920
And co-pilot returns a paragraph describing the status.

268
00:10:17,920 --> 00:10:19,360
The user still needs to navigate

269
00:10:19,360 --> 00:10:20,880
to the project management system

270
00:10:20,880 --> 00:10:22,640
to actually update something.

271
00:10:22,640 --> 00:10:24,480
With the interactive component model,

272
00:10:24,480 --> 00:10:27,120
co-pilot surfaces a status dashboard in line,

273
00:10:27,120 --> 00:10:29,600
which means the user can see the data in context

274
00:10:29,600 --> 00:10:32,320
and hit a button right there to update it immediately.

275
00:10:32,320 --> 00:10:33,600
That is not just faster,

276
00:10:33,600 --> 00:10:35,280
that is a different operational reality.

277
00:10:35,280 --> 00:10:38,080
From a governance perspective, this changes everything.

278
00:10:38,080 --> 00:10:39,920
Every interaction stays inside your tenant.

279
00:10:39,920 --> 00:10:41,600
Every action is logged automatically

280
00:10:41,600 --> 00:10:44,400
because it is happening through your own sharepoint infrastructure

281
00:10:44,400 --> 00:10:47,280
and every component respects the same permission model

282
00:10:47,280 --> 00:10:49,440
that governs your regular sharepoint access.

283
00:10:49,440 --> 00:10:51,120
If you do not have permission to see a list,

284
00:10:51,120 --> 00:10:53,360
the component will not show your data from that list

285
00:10:53,360 --> 00:10:55,600
and if you do not have permission to modify something,

286
00:10:55,600 --> 00:10:57,600
the update button will not even be active.

287
00:10:57,600 --> 00:10:59,360
Nothing happens outside your audit trail.

288
00:10:59,360 --> 00:11:00,800
Nothing escapes your security boundary.

289
00:11:00,800 --> 00:11:03,040
This is critical because it means the agent fabric

290
00:11:03,040 --> 00:11:04,640
isn't some external AI system

291
00:11:04,640 --> 00:11:07,440
that you are integrating with and managing separately.

292
00:11:07,440 --> 00:11:10,160
It is an evolution of the infrastructure you already have.

293
00:11:10,160 --> 00:11:12,160
You are not layering a new security model on top.

294
00:11:12,160 --> 00:11:14,560
You are extending the one that exists for developers.

295
00:11:14,560 --> 00:11:16,000
This is the inflection point.

296
00:11:16,000 --> 00:11:18,560
You have probably spent years building SPFX webpots

297
00:11:18,560 --> 00:11:20,000
for sharepoint pages,

298
00:11:20,000 --> 00:11:21,120
so you know how to build them,

299
00:11:21,120 --> 00:11:23,200
how to structure data and how to call APIs.

300
00:11:23,200 --> 00:11:25,760
That expertise, which was valuable for Internet work,

301
00:11:25,760 --> 00:11:29,200
is now your primary asset for operationalizing enterprise AI.

302
00:11:29,200 --> 00:11:30,960
This isn't about learning a new framework.

303
00:11:30,960 --> 00:11:32,240
It is not about retraining.

304
00:11:32,240 --> 00:11:35,200
It is about understanding that the skills you have already built

305
00:11:35,200 --> 00:11:36,800
are now the primary mechanism

306
00:11:36,800 --> 00:11:38,960
for moving intelligence into the hands of people

307
00:11:38,960 --> 00:11:40,160
who need to act on it.

308
00:11:40,160 --> 00:11:41,920
The component appears in co-pilot.

309
00:11:41,920 --> 00:11:43,440
The user interacts with it.

310
00:11:43,440 --> 00:11:44,560
The action is logged.

311
00:11:44,560 --> 00:11:46,000
The permission is enforced.

312
00:11:46,000 --> 00:11:47,440
The result is immediate.

313
00:11:47,440 --> 00:11:49,280
That is the operational model shift.

314
00:11:49,280 --> 00:11:51,200
That is what changes everything downstream.

315
00:11:51,200 --> 00:11:53,520
And it only works if you understand what comes next.

316
00:11:53,520 --> 00:11:56,000
The difference between how we have been organizing work

317
00:11:56,000 --> 00:11:58,240
and how we are about to have to organize it,

318
00:11:58,240 --> 00:12:00,240
that is the old model versus the new model.

319
00:12:00,240 --> 00:12:03,120
And that distinction is where the real architecture decisions happen.

320
00:12:03,120 --> 00:12:05,760
The old model versus the new model,

321
00:12:05,760 --> 00:12:07,840
to understand why this transition is unavoidable,

322
00:12:07,840 --> 00:12:09,440
you need to see exactly what changes

323
00:12:09,440 --> 00:12:12,320
when you move from text-based chat to interactive components.

324
00:12:12,320 --> 00:12:13,840
The difference isn't cosmetic.

325
00:12:13,840 --> 00:12:15,040
It is structural.

326
00:12:15,040 --> 00:12:17,680
And it reveals why most organizations are currently stuck

327
00:12:17,680 --> 00:12:19,440
in a place they did not intend to be.

328
00:12:19,440 --> 00:12:21,200
Here is how work happens in the old model.

329
00:12:21,200 --> 00:12:22,400
You are in operations.

330
00:12:22,400 --> 00:12:23,600
You need to approve a budget.

331
00:12:23,600 --> 00:12:25,440
You navigate to SharePoint.

332
00:12:25,440 --> 00:12:28,240
You know the site name, finance operations.

333
00:12:28,240 --> 00:12:29,920
So you get there directly.

334
00:12:29,920 --> 00:12:31,200
You look for the folder.

335
00:12:31,200 --> 00:12:33,840
It is in shared documents under Q4 approvals.

336
00:12:33,840 --> 00:12:35,200
You find the spreadsheet.

337
00:12:35,200 --> 00:12:37,520
You download it or open it in line.

338
00:12:37,520 --> 00:12:39,280
And then you read through the line items

339
00:12:39,280 --> 00:12:41,440
to see the budget code, the amount,

340
00:12:41,440 --> 00:12:43,760
the department, and the justification.

341
00:12:43,760 --> 00:12:45,760
Now you understand what you are approving.

342
00:12:45,760 --> 00:12:47,600
But you are not in the approval system yet.

343
00:12:47,600 --> 00:12:48,800
That is in a different place.

344
00:12:48,800 --> 00:12:49,840
So you navigate there.

345
00:12:49,840 --> 00:12:51,440
You search for the same budget item.

346
00:12:51,440 --> 00:12:52,800
You find it in the workflow.

347
00:12:52,800 --> 00:12:54,480
And you finally hit approve.

348
00:12:54,480 --> 00:12:55,440
And add your comments.

349
00:12:55,440 --> 00:12:56,720
So the action is logged.

350
00:12:56,720 --> 00:12:57,520
Start to finish.

351
00:12:57,520 --> 00:12:58,720
That took 15 minutes.

352
00:12:58,720 --> 00:13:00,640
Most of that time was not decision making.

353
00:13:00,640 --> 00:13:02,640
It was navigation, searching.

354
00:13:02,640 --> 00:13:04,320
Context switching between the document

355
00:13:04,320 --> 00:13:05,680
and the approval interface.

356
00:13:05,680 --> 00:13:07,760
Now let's look at why that model is breaking.

357
00:13:07,760 --> 00:13:09,440
The friction points are cumulative.

358
00:13:09,440 --> 00:13:11,680
You are switching contexts multiple times.

359
00:13:11,680 --> 00:13:13,600
And each switch costs cognitive load

360
00:13:13,600 --> 00:13:15,040
because your brain has to reset.

361
00:13:15,040 --> 00:13:16,080
You are doing manual search

362
00:13:16,080 --> 00:13:18,240
because you might not remember exactly where things live.

363
00:13:18,240 --> 00:13:20,480
And if the organization has changed the folder structure

364
00:13:20,480 --> 00:13:22,560
or renamed sites, you are lost.

365
00:13:22,560 --> 00:13:24,720
The content you are reading is separated from the action

366
00:13:24,720 --> 00:13:25,520
you are taking.

367
00:13:25,520 --> 00:13:27,680
So you are holding mental state in working memory.

368
00:13:27,680 --> 00:13:29,760
And all of that extends the time between

369
00:13:29,760 --> 00:13:31,120
I need to make a decision.

370
00:13:31,120 --> 00:13:33,600
And the decision is actually recorded.

371
00:13:33,600 --> 00:13:34,640
That is the old model.

372
00:13:34,640 --> 00:13:36,640
And it is the way most organizations

373
00:13:36,640 --> 00:13:38,080
have built their share point.

374
00:13:38,080 --> 00:13:40,240
The new model is different from the ground up.

375
00:13:40,240 --> 00:13:42,880
You ask co-pilot, what budgets need my approval?

376
00:13:42,880 --> 00:13:44,480
Co-pilot does not return a paragraph

377
00:13:44,480 --> 00:13:46,000
describing what needs approval.

378
00:13:46,000 --> 00:13:48,000
Instead, it surfaces a custom component.

379
00:13:48,000 --> 00:13:50,320
That component shows you the pending items

380
00:13:50,320 --> 00:13:52,160
displaying the budget code, amount,

381
00:13:52,160 --> 00:13:53,600
department and justification

382
00:13:53,600 --> 00:13:55,200
all in a formatted view

383
00:13:55,200 --> 00:13:57,360
in line in the co-pilot canvas.

384
00:13:57,360 --> 00:13:59,680
If you want more detail, you can expand an item.

385
00:13:59,680 --> 00:14:01,120
And if you are ready to decide,

386
00:14:01,120 --> 00:14:02,960
there is an approved button right there.

387
00:14:02,960 --> 00:14:03,760
You click it.

388
00:14:03,760 --> 00:14:05,200
The action is recorded.

389
00:14:05,200 --> 00:14:06,000
You are done.

390
00:14:06,000 --> 00:14:07,360
Start to finish.

391
00:14:07,360 --> 00:14:08,560
That took two minutes.

392
00:14:08,560 --> 00:14:09,520
No navigation.

393
00:14:09,520 --> 00:14:10,320
No search.

394
00:14:10,320 --> 00:14:11,840
No context switching.

395
00:14:11,840 --> 00:14:14,000
No cognitive overhead of holding the budget details

396
00:14:14,000 --> 00:14:16,320
in your head while you jump to another system.

397
00:14:16,320 --> 00:14:20,000
The architectural difference is subtle but fundamental.

398
00:14:20,000 --> 00:14:22,880
In the old model, humans are the primary navigation layer.

399
00:14:22,880 --> 00:14:23,840
You know where things are.

400
00:14:23,840 --> 00:14:24,880
You know how to find them.

401
00:14:24,880 --> 00:14:27,280
The system assumes you are going to navigate manually.

402
00:14:27,280 --> 00:14:29,200
AI is an optional help tool.

403
00:14:29,200 --> 00:14:31,120
You ask it questions, it gives you answers

404
00:14:31,120 --> 00:14:32,480
and you go find the thing.

405
00:14:32,480 --> 00:14:35,360
In the new model, AI becomes the navigation layer.

406
00:14:35,360 --> 00:14:37,200
You tell co-pilot what you need.

407
00:14:37,200 --> 00:14:39,040
It does not just answer your question.

408
00:14:39,040 --> 00:14:41,360
It presents the actionable interface directly.

409
00:14:41,360 --> 00:14:42,800
You interact with the component.

410
00:14:42,800 --> 00:14:44,000
You do not navigate separately.

411
00:14:44,000 --> 00:14:45,840
The system assumes you are going to engage

412
00:14:45,840 --> 00:14:46,800
through co-pilot first.

413
00:14:46,800 --> 00:14:49,520
This is why most organizations are stuck between the two.

414
00:14:49,520 --> 00:14:51,280
They have spent years building sharepoint

415
00:14:51,280 --> 00:14:52,400
around the old model.

416
00:14:52,400 --> 00:14:54,080
Sites are organized around navigation.

417
00:14:54,080 --> 00:14:55,840
Documents are structured for discovery.

418
00:14:55,840 --> 00:14:58,000
Workflows require manual entry points.

419
00:14:58,000 --> 00:15:00,000
The entire information architecture assumes

420
00:15:00,000 --> 00:15:01,600
humans are searching and navigating.

421
00:15:01,600 --> 00:15:03,360
Migrating to the new model requires

422
00:15:03,360 --> 00:15:05,280
rethinking that entire structure.

423
00:15:05,280 --> 00:15:06,560
It is not a technical change.

424
00:15:06,560 --> 00:15:08,000
It is a governance change.

425
00:15:08,000 --> 00:15:09,280
That is why some organizations

426
00:15:09,280 --> 00:15:12,160
that have already restructured their information architecture

427
00:15:12,160 --> 00:15:13,520
classified their data,

428
00:15:13,520 --> 00:15:14,720
built permission boundaries

429
00:15:14,720 --> 00:15:16,720
that match compliance requirements

430
00:15:16,720 --> 00:15:19,840
and invested in sensitivity labels and DLP policies

431
00:15:19,840 --> 00:15:22,160
can move to this new model immediately.

432
00:15:22,160 --> 00:15:24,240
Their governance foundation supports it

433
00:15:24,240 --> 00:15:26,480
for organizations that have not done that work.

434
00:15:26,480 --> 00:15:28,560
The new model creates visibility problems

435
00:15:28,560 --> 00:15:30,240
before it creates efficiency gains.

436
00:15:30,240 --> 00:15:32,480
This is observable in early adoption data.

437
00:15:32,480 --> 00:15:34,480
Organizations moving to the new model

438
00:15:34,480 --> 00:15:37,680
are seeing 40 to 60% reduction in time to decision

439
00:15:37,680 --> 00:15:38,960
for structured workflows.

440
00:15:38,960 --> 00:15:40,480
That is not marginal improvement.

441
00:15:40,480 --> 00:15:42,800
That is the difference between operational efficiency

442
00:15:42,800 --> 00:15:44,160
and operational friction.

443
00:15:44,160 --> 00:15:47,200
And this is why SPFX 1.24 isn't just a feature release.

444
00:15:47,200 --> 00:15:49,760
It is the moment when you have to make an explicit governance

445
00:15:49,760 --> 00:15:52,640
choice about which model your organization is operating in.

446
00:15:52,640 --> 00:15:53,920
You are choosing right now

447
00:15:53,920 --> 00:15:55,680
whether to keep building for the old model

448
00:15:55,680 --> 00:15:57,760
or start architecting for the new one.

449
00:15:57,760 --> 00:16:00,640
Why SPFX 1.24 is the inflection point.

450
00:16:00,640 --> 00:16:03,040
This is the moment where the architecture becomes real.

451
00:16:03,040 --> 00:16:04,320
It stops being theoretical.

452
00:16:04,320 --> 00:16:07,280
SharePoint co-pilot apps.

453
00:16:07,280 --> 00:16:09,280
The actual mechanism for surfacing components

454
00:16:09,280 --> 00:16:12,320
in co-pilot enters preview in July 2026

455
00:16:12,320 --> 00:16:15,120
and it arrives alongside SPFX 1.24.

456
00:16:15,120 --> 00:16:17,440
That timing isn't a coincidence.

457
00:16:17,440 --> 00:16:19,520
It is the point where every technical decision you make

458
00:16:19,520 --> 00:16:21,760
about SharePoint becomes an architectural decision

459
00:16:21,760 --> 00:16:22,960
about how you run your AI.

460
00:16:22,960 --> 00:16:25,200
We need to be clear about what actually changed here.

461
00:16:25,200 --> 00:16:27,680
SPFX was originally designed for SharePoint pages

462
00:16:27,680 --> 00:16:29,920
and it was the framework you used to build web parts

463
00:16:29,920 --> 00:16:32,080
or custom interfaces that lived on your internet sites.

464
00:16:32,080 --> 00:16:33,280
That was the use case.

465
00:16:33,280 --> 00:16:34,160
That was the domain.

466
00:16:34,160 --> 00:16:36,720
You used it to extend the page layer of SharePoint.

467
00:16:36,720 --> 00:16:38,960
But now, SPFX is the primary way

468
00:16:38,960 --> 00:16:41,360
to build what Microsoft calls "Egentic UX".

469
00:16:41,360 --> 00:16:43,920
It is the mechanism for putting interactive components

470
00:16:43,920 --> 00:16:46,160
directly into the co-pilot orchestration layer.

471
00:16:46,160 --> 00:16:48,480
This isn't just an expansion of what SPFX can do.

472
00:16:48,480 --> 00:16:51,600
It's a fundamental shift in what the framework is actually for.

473
00:16:51,600 --> 00:16:54,480
But here's the problem with calling it just another version release.

474
00:16:54,480 --> 00:16:56,400
Version 1.24 is the inflection point

475
00:16:56,400 --> 00:16:59,600
because it includes a full suite of dependency modernizations

476
00:16:59,600 --> 00:17:01,600
that go way beyond incremental updates.

477
00:17:01,600 --> 00:17:04,080
You're getting updated NPM packages across the board

478
00:17:04,080 --> 00:17:05,840
which finally reduces the technical debt

479
00:17:05,840 --> 00:17:07,840
you've been carrying from earlier versions.

480
00:17:07,840 --> 00:17:09,600
You're getting React 18 support

481
00:17:09,600 --> 00:17:11,920
and that finally aligns SPFX development

482
00:17:11,920 --> 00:17:13,840
with the mainstream JavaScript ecosystem

483
00:17:13,840 --> 00:17:17,040
instead of keeping you tethered to older, slower patterns.

484
00:17:17,040 --> 00:17:18,880
You're also getting navigation customizers

485
00:17:18,880 --> 00:17:22,560
that let you override how navigation itself works inside SharePoint.

486
00:17:22,560 --> 00:17:23,920
Each of these changes was designed

487
00:17:23,920 --> 00:17:26,320
to remove the friction of building modern components.

488
00:17:26,320 --> 00:17:27,600
So why does that matter?

489
00:17:27,600 --> 00:17:30,720
It matters because if you already have a mature SPFX estate

490
00:17:30,720 --> 00:17:32,640
and you've spent years building webpots

491
00:17:32,640 --> 00:17:34,640
and custom interfaces for your internet,

492
00:17:34,640 --> 00:17:37,680
you can now surface those exact components inside co-pilot

493
00:17:37,680 --> 00:17:39,520
without rebuilding them from scratch.

494
00:17:39,520 --> 00:17:41,120
The components you already built,

495
00:17:41,120 --> 00:17:42,560
the patterns you already established,

496
00:17:42,560 --> 00:17:44,640
the teams that already know how to maintain them,

497
00:17:44,640 --> 00:17:46,080
you aren't starting over.

498
00:17:46,080 --> 00:17:47,840
You're extending.

499
00:17:47,840 --> 00:17:50,560
That is the reuse story that makes this actually achievable

500
00:17:50,560 --> 00:17:51,440
for a business.

501
00:17:51,440 --> 00:17:56,080
If SPFX 1.24 required you to rewrite every existing component,

502
00:17:56,080 --> 00:17:58,800
adoption would be slow and it would be expensive.

503
00:17:58,800 --> 00:18:00,240
Instead, the process is additive.

504
00:18:00,240 --> 00:18:01,680
You take what you've already built,

505
00:18:01,680 --> 00:18:04,160
you apply the 1.24 modernizations

506
00:18:04,160 --> 00:18:06,000
and then you expose it in co-pilot.

507
00:18:06,000 --> 00:18:08,160
The investment you've already made doesn't become obsolete,

508
00:18:08,160 --> 00:18:09,760
it actually becomes more valuable.

509
00:18:09,760 --> 00:18:11,120
And from a governance perspective,

510
00:18:11,120 --> 00:18:14,160
this is where the security stack inheritance really matters.

511
00:18:14,160 --> 00:18:16,160
SPFX runs inside your tenant boundary.

512
00:18:16,160 --> 00:18:18,880
It doesn't crawl out to external servers for logic or data,

513
00:18:18,880 --> 00:18:22,000
so it inherits the full Microsoft 365 security

514
00:18:22,000 --> 00:18:23,760
and governance stack directly.

515
00:18:23,760 --> 00:18:25,520
EntraID handles your identity,

516
00:18:25,520 --> 00:18:27,360
SharePoint enforces your permissions.

517
00:18:27,360 --> 00:18:31,120
Sensitivity labels flow through automatically

518
00:18:31,120 --> 00:18:33,200
and DLP policies apply without you having

519
00:18:33,200 --> 00:18:34,880
to do any additional configuration.

520
00:18:34,880 --> 00:18:36,880
The compliance controls you've already implemented

521
00:18:36,880 --> 00:18:38,640
for regular SharePoint don't need to be redone

522
00:18:38,640 --> 00:18:41,120
for co-pilot components, they're just automatic.

523
00:18:41,120 --> 00:18:43,040
This is a fundamentally different security model

524
00:18:43,040 --> 00:18:44,400
than building custom integrations

525
00:18:44,400 --> 00:18:45,920
that sit outside your tenant boundary.

526
00:18:45,920 --> 00:18:47,280
There is no credential management

527
00:18:47,280 --> 00:18:48,640
across different boundaries.

528
00:18:48,640 --> 00:18:51,040
There are no external API keys to rotate.

529
00:18:51,040 --> 00:18:52,720
There isn't a separate audit trail

530
00:18:52,720 --> 00:18:54,320
that you have to manually correlate

531
00:18:54,320 --> 00:18:55,680
with your internal logging.

532
00:18:55,680 --> 00:18:57,120
The governance model is unified

533
00:18:57,120 --> 00:18:59,280
because the execution model is unified.

534
00:18:59,280 --> 00:19:02,080
The licensing alignment reinforces this even further.

535
00:19:02,080 --> 00:19:04,080
SPFX co-pilot apps are licensed

536
00:19:04,080 --> 00:19:06,880
through the same Microsoft 365 co-pilot seat

537
00:19:06,880 --> 00:19:08,000
you're already paying for.

538
00:19:08,000 --> 00:19:09,760
You aren't buying a separate skew for this.

539
00:19:09,760 --> 00:19:11,840
You aren't dealing with consumption-based billing,

540
00:19:11,840 --> 00:19:13,520
where every component interaction

541
00:19:13,520 --> 00:19:15,200
gets metered and charged per action.

542
00:19:15,200 --> 00:19:16,720
You make one licensing decision

543
00:19:16,720 --> 00:19:19,040
who gets the $30 per month co-pilot seat

544
00:19:19,040 --> 00:19:22,400
and that decision automatically covers your SPFX co-pilot apps.

545
00:19:22,400 --> 00:19:24,640
It's simple, it's predictable, it's governable.

546
00:19:24,640 --> 00:19:27,440
For developers, this completely reframes

547
00:19:27,440 --> 00:19:29,440
what your existing expertise is worth.

548
00:19:29,440 --> 00:19:31,120
Your SharePoint framework skills,

549
00:19:31,120 --> 00:19:33,680
the things you learned for page-level customization

550
00:19:33,680 --> 00:19:36,560
are now your primary asset for running enterprise intelligence.

551
00:19:36,560 --> 00:19:38,240
You aren't becoming an AI developer,

552
00:19:38,240 --> 00:19:40,080
you're becoming an orchestration developer,

553
00:19:40,080 --> 00:19:42,320
and the interface for that orchestration

554
00:19:42,320 --> 00:19:44,480
is the exact skill set you already have.

555
00:19:44,480 --> 00:19:46,800
This is why 1.24 is the inflection point.

556
00:19:46,800 --> 00:19:48,480
It's not because of one single feature.

557
00:19:48,480 --> 00:19:50,000
It's because all of these elements,

558
00:19:50,000 --> 00:19:52,240
the dependencies, the reusable components,

559
00:19:52,240 --> 00:19:53,920
the governance, the licensing,

560
00:19:53,920 --> 00:19:57,200
and the developer relevance all converge at the same moment.

561
00:19:57,200 --> 00:19:59,120
And that convergence is exactly when

562
00:19:59,120 --> 00:20:01,520
the choice between different architectural parts

563
00:20:01,520 --> 00:20:04,560
becomes unavoidable because SPFX isn't your only option.

564
00:20:04,560 --> 00:20:06,000
There is another path entirely,

565
00:20:06,000 --> 00:20:07,520
MCP apps, the open path,

566
00:20:07,520 --> 00:20:08,720
that other paths is MCP,

567
00:20:08,720 --> 00:20:10,000
and understanding what it is

568
00:20:10,000 --> 00:20:11,520
and why it's fundamentally different

569
00:20:11,520 --> 00:20:13,200
from the SPFX approach,

570
00:20:13,200 --> 00:20:16,000
clarifies the entire governance trade-off you're making

571
00:20:16,000 --> 00:20:18,640
when you choose how to build your agent fabric.

572
00:20:18,640 --> 00:20:21,200
MCP stands for Model Context Protocol.

573
00:20:21,200 --> 00:20:23,840
It's a vendor neutral standard created to define

574
00:20:23,840 --> 00:20:27,680
how AI agents discover, call, and interact with tools.

575
00:20:27,680 --> 00:20:29,200
You can think of it as a contract language

576
00:20:29,200 --> 00:20:31,840
between an AI system and external capabilities.

577
00:20:31,840 --> 00:20:33,680
You define what your system can do,

578
00:20:33,680 --> 00:20:35,440
you list the tools it exposes,

579
00:20:35,440 --> 00:20:37,920
and you set the format for the data it returns.

580
00:20:37,920 --> 00:20:39,280
You publish that definition,

581
00:20:39,280 --> 00:20:41,760
and then any AI system that understands MCP

582
00:20:41,760 --> 00:20:43,840
can call those tools, and that is the core appeal,

583
00:20:43,840 --> 00:20:45,040
vendor neutrality.

584
00:20:45,040 --> 00:20:49,200
The same MCP server you build can work with Microsoft 365 Copilot,

585
00:20:49,200 --> 00:20:50,720
but it can also work with Claude,

586
00:20:50,720 --> 00:20:52,800
ChapGPT, or GitHub Copilot.

587
00:20:52,800 --> 00:20:54,480
You write the integration once,

588
00:20:54,480 --> 00:20:57,040
and then you can reuse it across multiple AI platforms.

589
00:20:57,040 --> 00:20:59,280
That's powerful when you think about your investment.

590
00:20:59,280 --> 00:21:02,720
You aren't locking your work into a single AI vendor's ecosystem.

591
00:21:02,720 --> 00:21:04,400
MCP apps take this a step further.

592
00:21:04,400 --> 00:21:07,040
They let your MCP server return interactive UI widgets

593
00:21:07,040 --> 00:21:08,240
alongside the data.

594
00:21:08,240 --> 00:21:09,280
So instead of Copilot,

595
00:21:09,280 --> 00:21:12,080
just giving you a text response about an order status,

596
00:21:12,080 --> 00:21:14,240
your MCP server returns the status data

597
00:21:14,240 --> 00:21:15,520
and a visual component.

598
00:21:15,520 --> 00:21:17,840
That component lets the user update the status,

599
00:21:17,840 --> 00:21:20,080
track the shipping, or start a refund right there.

600
00:21:20,080 --> 00:21:22,640
The widget renders inline in the Copilot canvas.

601
00:21:22,640 --> 00:21:23,840
The user interacts with it.

602
00:21:23,840 --> 00:21:26,080
The data gets updated back through your system.

603
00:21:26,080 --> 00:21:27,360
Here is how it actually works.

604
00:21:27,360 --> 00:21:29,600
You host an MCP server somewhere,

605
00:21:29,600 --> 00:21:31,200
like on-premises, in Azure,

606
00:21:31,200 --> 00:21:33,120
or in any cloud provider you choose.

607
00:21:33,120 --> 00:21:36,000
You write the server in whatever language fits your architecture,

608
00:21:36,000 --> 00:21:37,920
whether that's node, Python, or .NET.

609
00:21:37,920 --> 00:21:39,840
That server defines the tools it exposes

610
00:21:39,840 --> 00:21:41,040
and what those tools do.

611
00:21:41,040 --> 00:21:43,280
When Copilot needs to interact with your system,

612
00:21:43,280 --> 00:21:44,880
it calls your MCP server

613
00:21:44,880 --> 00:21:46,880
and then your server processes the request.

614
00:21:46,880 --> 00:21:49,920
It returns the structured data and the UI metadata.

615
00:21:49,920 --> 00:21:51,360
Copilot renders the response,

616
00:21:51,360 --> 00:21:52,560
the user interacts with it,

617
00:21:52,560 --> 00:21:53,760
and the loop closes.

618
00:21:53,760 --> 00:21:54,960
That sounds straightforward.

619
00:21:54,960 --> 00:22:00,080
But the friction points reveal why this is a different governance category entirely.

620
00:22:00,080 --> 00:22:01,280
To make this work securely,

621
00:22:01,280 --> 00:22:03,440
you need OAuth 2 properly configured.

622
00:22:03,440 --> 00:22:04,640
You need Mutual TLS,

623
00:22:04,640 --> 00:22:07,760
which means both sides of the connection have to authenticate each other.

624
00:22:07,760 --> 00:22:09,760
You need federated credentials in Entra

625
00:22:09,760 --> 00:22:11,920
so that Copilot can authenticate your MCP server

626
00:22:11,920 --> 00:22:14,160
without your server storing credentials in a database.

627
00:22:14,160 --> 00:22:16,160
If you want custom connectors in Power Apps

628
00:22:16,160 --> 00:22:17,680
to call your MCP server,

629
00:22:17,680 --> 00:22:19,120
you have to register those two.

630
00:22:19,120 --> 00:22:20,480
If you want to log what's happening,

631
00:22:20,480 --> 00:22:22,400
you have to instrument your own server.

632
00:22:22,400 --> 00:22:24,320
Each of these steps is very precise.

633
00:22:24,320 --> 00:22:25,680
One misconfigured redirect,

634
00:22:25,680 --> 00:22:27,360
URI breaks the entire flow.

635
00:22:27,360 --> 00:22:29,520
One certificate issue stops everything.

636
00:22:29,520 --> 00:22:31,680
The real governance cost is that your MCP server

637
00:22:31,680 --> 00:22:32,880
is external to your tenant.

638
00:22:32,880 --> 00:22:34,160
That isn't inherently bad,

639
00:22:34,160 --> 00:22:36,160
and sometimes that's exactly what you need.

640
00:22:36,160 --> 00:22:38,800
But it means you are managing identity across a boundary.

641
00:22:38,800 --> 00:22:40,480
You're securing a new integration point.

642
00:22:40,480 --> 00:22:42,160
You're responsible for secret rotation.

643
00:22:42,160 --> 00:22:44,480
You're maintaining audit logs that span your tenant

644
00:22:44,480 --> 00:22:45,680
and an external server.

645
00:22:45,680 --> 00:22:46,560
If something goes wrong,

646
00:22:46,560 --> 00:22:49,760
the forensics require you to correlate data across two different systems.

647
00:22:49,760 --> 00:22:51,920
This is the right choice in specific scenarios.

648
00:22:51,920 --> 00:22:53,360
If your data is scattered,

649
00:22:53,360 --> 00:22:55,120
some in dynamics, some in Salesforce,

650
00:22:55,120 --> 00:22:56,320
some in a custom ERP,

651
00:22:56,320 --> 00:22:57,920
and some in a data warehouse,

652
00:22:57,920 --> 00:23:00,160
then you need something that can orchestrate across all of it.

653
00:23:00,160 --> 00:23:03,120
You can't build every one of those integrations into your tenant.

654
00:23:03,120 --> 00:23:03,920
In that case,

655
00:23:03,920 --> 00:23:06,480
an MCP server becomes the translation layer.

656
00:23:06,480 --> 00:23:08,240
You build ones, you call from co-pilot,

657
00:23:08,240 --> 00:23:10,160
you get vendor agnostic tool reuse.

658
00:23:10,160 --> 00:23:12,000
But you have to notice what you're trading away.

659
00:23:12,000 --> 00:23:13,600
You gain flexibility and portability

660
00:23:13,600 --> 00:23:15,120
across different platforms.

661
00:23:15,120 --> 00:23:16,880
But you lose the unified governance

662
00:23:16,880 --> 00:23:19,200
that comes from staying inside your tenant boundary.

663
00:23:19,200 --> 00:23:21,760
You gain the ability to integrate anything you want.

664
00:23:21,760 --> 00:23:23,920
But you lose the automatic security inheritance

665
00:23:23,920 --> 00:23:26,960
that comes from running on Microsoft 365 infrastructure.

666
00:23:26,960 --> 00:23:28,720
That trade-off is the entire question,

667
00:23:28,720 --> 00:23:30,960
and how you answer it determines which architecture

668
00:23:30,960 --> 00:23:32,400
you are actually building.

669
00:23:32,400 --> 00:23:34,640
SPFX co-pilot apps, the fortified path.

670
00:23:34,640 --> 00:23:37,360
SPFX co-pilot apps operate on a completely different premise.

671
00:23:37,360 --> 00:23:39,840
Instead of building an external MCP server

672
00:23:39,840 --> 00:23:42,080
and figuring out how to integrate it,

673
00:23:42,080 --> 00:23:45,280
you're taking components you've already built inside SharePoint

674
00:23:45,280 --> 00:23:48,240
and exposing them directly into the co-pilot canvas.

675
00:23:48,240 --> 00:23:50,400
The component you created for your internet page

676
00:23:50,400 --> 00:23:52,960
becomes a tool that co-pilot surfaces in line.

677
00:23:52,960 --> 00:23:55,920
No external servers, no authentication bridge,

678
00:23:55,920 --> 00:23:57,600
no integration complexity.

679
00:23:57,600 --> 00:23:58,880
Here's the technical model.

680
00:23:58,880 --> 00:24:02,000
You build a web part or extension using SharePoint framework,

681
00:24:02,000 --> 00:24:04,240
which is the same way you've been doing it for years.

682
00:24:04,240 --> 00:24:07,760
You package it, you deploy it to the SharePoint app catalog.

683
00:24:07,760 --> 00:24:10,560
When co-pilot needs to surface interactive capabilities,

684
00:24:10,560 --> 00:24:13,280
it pulls that component and renders it in the chat canvas.

685
00:24:13,280 --> 00:24:15,120
The user interacts with the component

686
00:24:15,120 --> 00:24:18,560
and the data flows directly through your SharePoint infrastructure.

687
00:24:18,560 --> 00:24:19,840
Everything stays inside.

688
00:24:19,840 --> 00:24:20,960
This different sounds minor.

689
00:24:20,960 --> 00:24:22,160
It's actually fundamental.

690
00:24:22,160 --> 00:24:24,800
The governance advantage is where this becomes concrete.

691
00:24:24,800 --> 00:24:26,960
Everything runs inside your tenant boundary,

692
00:24:26,960 --> 00:24:29,120
so there is no external server to secure

693
00:24:29,120 --> 00:24:32,320
and no authentication handshake across a network boundary.

694
00:24:32,320 --> 00:24:34,240
Identity is handled by Enter directly.

695
00:24:34,240 --> 00:24:36,160
The component runs with the user's credentials

696
00:24:36,160 --> 00:24:37,440
in the user's context.

697
00:24:37,440 --> 00:24:40,400
Permissions are enforced through your existing SharePoint permission model.

698
00:24:40,400 --> 00:24:41,680
If you don't have access to a list,

699
00:24:41,680 --> 00:24:43,520
the component won't fetch data from it.

700
00:24:43,520 --> 00:24:46,080
If you can't modify something, the button will be disabled.

701
00:24:46,080 --> 00:24:48,240
That's not a separate security layer

702
00:24:48,240 --> 00:24:51,120
that's your existing permission model being applied automatically.

703
00:24:51,120 --> 00:24:52,400
Audit logging is built in.

704
00:24:52,400 --> 00:24:56,160
Every interaction with an SPFX component in co-pilot gets logged

705
00:24:56,160 --> 00:24:59,040
to purview the same way any other SharePoint action does.

706
00:24:59,040 --> 00:25:00,640
You don't need to instrument custom logging.

707
00:25:00,640 --> 00:25:02,720
You don't need to correlate logs across systems.

708
00:25:02,720 --> 00:25:05,840
The audit trail is unified because the execution is unified.

709
00:25:05,840 --> 00:25:09,120
The reuse story is what makes this actually practical at scale.

710
00:25:09,120 --> 00:25:12,000
If you spent the last five years building SPFX webpots

711
00:25:12,000 --> 00:25:14,400
for your internet like a dashboard for project status

712
00:25:14,400 --> 00:25:16,160
or a form for incident reporting,

713
00:25:16,160 --> 00:25:17,280
you don't throw those away.

714
00:25:17,280 --> 00:25:18,640
You surface them in co-pilot.

715
00:25:18,640 --> 00:25:20,240
The component code doesn't need to change

716
00:25:20,240 --> 00:25:22,080
because you aren't rewriting from scratch.

717
00:25:22,080 --> 00:25:23,840
You're exposing what you already have.

718
00:25:23,840 --> 00:25:25,600
That's a massive practical advantage.

719
00:25:25,600 --> 00:25:27,520
You inherit five years of refinement,

720
00:25:27,520 --> 00:25:29,440
five years of performance optimization,

721
00:25:29,440 --> 00:25:31,520
and five years of user feedback baked in.

722
00:25:31,520 --> 00:25:33,520
You're not starting a new technical project.

723
00:25:33,520 --> 00:25:35,760
You're using an existing asset in a new context.

724
00:25:35,760 --> 00:25:38,560
The licensing alignment reinforces the simplicity.

725
00:25:38,560 --> 00:25:40,400
SPFX co-pilot apps are licensed

726
00:25:40,400 --> 00:25:43,120
through the standard M365 co-pilot seat.

727
00:25:43,120 --> 00:25:44,320
There's no additional SKU.

728
00:25:44,320 --> 00:25:45,680
There's no consumption-based billing

729
00:25:45,680 --> 00:25:47,680
where component interactions get metered.

730
00:25:47,680 --> 00:25:50,880
You made the decision about who gets the $30 per month license

731
00:25:50,880 --> 00:25:54,080
and that decision automatically extends to SPFX co-pilot apps.

732
00:25:54,080 --> 00:25:56,000
Every person with a co-pilot license can interact

733
00:25:56,000 --> 00:25:57,440
with every SPFX component.

734
00:25:57,440 --> 00:25:59,440
The licensing model is clear and predictable.

735
00:25:59,440 --> 00:26:01,120
But there's a constraint you need to acknowledge.

736
00:26:01,120 --> 00:26:04,320
SPFX is fundamentally locked into the Microsoft 365 ecosystem.

737
00:26:04,320 --> 00:26:05,600
It doesn't work with Claude.

738
00:26:05,600 --> 00:26:06,880
It doesn't work with ChatGPT.

739
00:26:06,880 --> 00:26:08,480
It doesn't work with any AI platform

740
00:26:08,480 --> 00:26:09,920
that doesn't understand SPFX.

741
00:26:09,920 --> 00:26:12,320
If you're building for maximum vendor portability

742
00:26:12,320 --> 00:26:14,560
or if you're planning to use the same integration logic

743
00:26:14,560 --> 00:26:17,680
across multiple AI systems, SPFX constrains you.

744
00:26:17,680 --> 00:26:18,480
That's not a bug.

745
00:26:18,480 --> 00:26:19,360
It's a trade-off.

746
00:26:19,360 --> 00:26:21,440
The use case fit is where you see this play out.

747
00:26:21,440 --> 00:26:24,720
SPFX co-pilot apps excel at internet orchestration,

748
00:26:24,720 --> 00:26:28,000
which means surfacing company news, organizational information

749
00:26:28,000 --> 00:26:30,160
and employee resources directly in Chat.

750
00:26:30,160 --> 00:26:31,600
They excel at knowledge management

751
00:26:31,600 --> 00:26:33,680
by bringing documentation, FAQs,

752
00:26:33,680 --> 00:26:36,000
and procedural guides into the flow of work.

753
00:26:36,000 --> 00:26:37,840
They excel at list-driven workflows

754
00:26:37,840 --> 00:26:40,080
like approvals, requests, and status updates

755
00:26:40,080 --> 00:26:42,160
where the data lives in SharePoint lists.

756
00:26:42,160 --> 00:26:44,000
They excel at document-centric actions,

757
00:26:44,000 --> 00:26:46,800
allowing someone to search, preview, and modify documents

758
00:26:46,800 --> 00:26:48,080
without leaving the conversation.

759
00:26:48,080 --> 00:26:50,160
Anywhere SharePoint is already the system of record.

760
00:26:50,160 --> 00:26:52,000
SPFX is the natural path.

761
00:26:52,000 --> 00:26:54,480
Where they don't fit is scenarios where your data

762
00:26:54,480 --> 00:26:56,800
is scattered across multiple platforms

763
00:26:56,800 --> 00:26:59,520
and you need a single integration layer that works everywhere.

764
00:26:59,520 --> 00:27:00,800
That's the MCP scenario.

765
00:27:00,800 --> 00:27:03,600
That's where you need the flexibility of an external server

766
00:27:03,600 --> 00:27:06,080
and the portability of a vendor neutral standard.

767
00:27:06,080 --> 00:27:08,080
So when you're standing at the fork in the road,

768
00:27:08,080 --> 00:27:10,800
deciding whether to build MCP or build SPFX,

769
00:27:10,800 --> 00:27:14,480
you're not actually choosing between two equally flexible options.

770
00:27:14,480 --> 00:27:18,160
You're choosing between two completely different governance philosophies.

771
00:27:18,160 --> 00:27:19,440
The governance trade-off.

772
00:27:19,440 --> 00:27:22,640
So here's where we get concrete about the decision you're actually making.

773
00:27:22,640 --> 00:27:25,200
There's attention sitting underneath this entire choice

774
00:27:25,200 --> 00:27:27,120
and it determines everything that comes after

775
00:27:27,120 --> 00:27:28,960
MCP offers flexibility.

776
00:27:28,960 --> 00:27:30,880
SPFX offers assurance.

777
00:27:30,880 --> 00:27:32,960
Those two things point in opposite directions

778
00:27:32,960 --> 00:27:35,840
and where you land on that spectrum depends entirely on

779
00:27:35,840 --> 00:27:38,480
what your organization can actually afford to govern.

780
00:27:38,480 --> 00:27:41,200
That's unpack what governance actually means in each scenario.

781
00:27:41,200 --> 00:27:43,840
With MCP, you're managing a new integration boundary.

782
00:27:43,840 --> 00:27:46,000
Your server sits somewhere, whether it's in Azure,

783
00:27:46,000 --> 00:27:48,400
your own data center, or managed by a vendor.

784
00:27:48,400 --> 00:27:49,600
The moment you deploy it,

785
00:27:49,600 --> 00:27:53,200
you've created a new place where secrets need to be stored and rotated.

786
00:27:53,200 --> 00:27:57,120
O-auth credentials, API keys, certificates for mutual TLS.

787
00:27:57,120 --> 00:27:58,800
All of that is your responsibility now.

788
00:27:58,800 --> 00:28:00,640
You can't delegate that to Microsoft.

789
00:28:00,640 --> 00:28:02,480
You can't inherit it from the platform.

790
00:28:02,480 --> 00:28:03,440
You have to own it.

791
00:28:03,440 --> 00:28:05,600
Identity propagation becomes your problem too.

792
00:28:05,600 --> 00:28:07,440
When co-pilot calls your MCP server,

793
00:28:07,440 --> 00:28:09,440
it needs to pass along the user's identity

794
00:28:09,440 --> 00:28:12,720
so that your server can enforce the right permissions on the right data.

795
00:28:12,720 --> 00:28:14,560
That handoff has to be set up correctly.

796
00:28:14,560 --> 00:28:17,120
A misconfiguration means users see data they shouldn't,

797
00:28:17,120 --> 00:28:18,800
or legitimate requests get blocked.

798
00:28:19,440 --> 00:28:21,280
Audit logging spans two systems now.

799
00:28:21,280 --> 00:28:22,640
Co-pilot logs what it did.

800
00:28:22,640 --> 00:28:24,480
Your MCP server logs what it did.

801
00:28:24,480 --> 00:28:25,440
But those logs are separate.

802
00:28:25,440 --> 00:28:27,520
If you need a complete forensic trail of what happened,

803
00:28:27,520 --> 00:28:29,840
you're correlating logs from two different places.

804
00:28:29,840 --> 00:28:32,480
And you need to make sure that correlation is actually possible,

805
00:28:32,480 --> 00:28:35,040
ensuring that timestamps align and user identities match

806
00:28:35,040 --> 00:28:36,320
so the story is coherent.

807
00:28:36,320 --> 00:28:39,120
If your MCP server calls external APIs,

808
00:28:39,120 --> 00:28:41,920
like pulling data from Salesforce or an ERP system,

809
00:28:41,920 --> 00:28:44,320
you need to implement DLP at the API level.

810
00:28:44,320 --> 00:28:45,920
You need custom logic that says,

811
00:28:45,920 --> 00:28:47,760
don't return this field because it's sensitive.

812
00:28:47,760 --> 00:28:50,000
Or don't allow this combination of data flows

813
00:28:50,000 --> 00:28:51,440
because it violates compliance.

814
00:28:51,440 --> 00:28:53,440
That's not something Microsoft can do for you.

815
00:28:53,440 --> 00:28:54,640
That's code you write.

816
00:28:54,640 --> 00:28:57,520
All of this requires security engineering expertise.

817
00:28:57,520 --> 00:28:59,920
Not I know how to configure Azure AD.

818
00:28:59,920 --> 00:29:03,200
Not I understand how to manage SharePoint permissions.

819
00:29:03,200 --> 00:29:06,000
This is I know how to build secure API integrations

820
00:29:06,000 --> 00:29:08,480
with proper credential rotation and audit trails.

821
00:29:08,480 --> 00:29:09,760
That's a different skill set.

822
00:29:09,760 --> 00:29:12,000
SPFX has a different governance surface.

823
00:29:12,000 --> 00:29:13,840
You're not managing a separate security boundary

824
00:29:13,840 --> 00:29:15,520
because there is no separate boundary.

825
00:29:15,520 --> 00:29:17,520
Your components run inside your tenant.

826
00:29:17,520 --> 00:29:20,720
Identity is handled by Android permissions flow from SharePoint.

827
00:29:20,720 --> 00:29:23,680
DLP policies that you've already set up apply automatically.

828
00:29:23,680 --> 00:29:24,560
Audit is built in.

829
00:29:24,560 --> 00:29:25,760
You're not solving new problems.

830
00:29:25,760 --> 00:29:27,840
Your extending governance that already exists.

831
00:29:27,840 --> 00:29:29,280
Your governance requirements are different.

832
00:29:29,280 --> 00:29:31,840
You need to control who can deploy to the app catalog.

833
00:29:31,840 --> 00:29:33,680
You need SharePoint governance discipline,

834
00:29:33,680 --> 00:29:36,640
which means making sure permissions are structured correctly,

835
00:29:36,640 --> 00:29:37,600
data is classified,

836
00:29:37,600 --> 00:29:40,000
and your sensitivity labeling is consistent.

837
00:29:40,000 --> 00:29:42,400
You need to enforce your existing policies rigorously

838
00:29:42,400 --> 00:29:44,160
because the component will inherit them.

839
00:29:44,160 --> 00:29:46,160
But you're not inventing new governance layers.

840
00:29:46,160 --> 00:29:49,680
This requires SharePoint expertise and governance discipline.

841
00:29:49,680 --> 00:29:51,600
Not I know how to write OAuth flows.

842
00:29:51,600 --> 00:29:53,920
This is I understand how SharePoint permissions work

843
00:29:53,920 --> 00:29:55,600
and how to structure a site hierarchy

844
00:29:55,600 --> 00:29:57,360
that actually matches your compliance requirements.

845
00:29:57,360 --> 00:29:59,840
Here's where organizations get stuck.

846
00:29:59,840 --> 00:30:01,360
Someone MCP's flexibility,

847
00:30:01,360 --> 00:30:03,200
but can't afford the security overhead.

848
00:30:03,200 --> 00:30:04,480
They don't have the infrastructure,

849
00:30:04,480 --> 00:30:05,200
the expertise,

850
00:30:05,200 --> 00:30:06,560
or the governance maturity

851
00:30:06,560 --> 00:30:08,800
to manage external integration securely.

852
00:30:08,800 --> 00:30:10,160
So they look at MCP and realize

853
00:30:10,160 --> 00:30:11,760
it's not actually an option for them.

854
00:30:11,760 --> 00:30:13,600
Others want SPFX's assurance

855
00:30:13,600 --> 00:30:15,920
but lack the SharePoint governance foundation.

856
00:30:15,920 --> 00:30:17,280
Their sites are overshared,

857
00:30:17,280 --> 00:30:18,800
their data is unclassified,

858
00:30:18,800 --> 00:30:19,920
their permissions are flat,

859
00:30:19,920 --> 00:30:21,680
they look at SPFX and realize

860
00:30:21,680 --> 00:30:24,080
they can't safely expose their components in co-pilot

861
00:30:24,080 --> 00:30:26,240
because the governance underneath is too weak.

862
00:30:26,240 --> 00:30:27,840
The decision framework is simple.

863
00:30:27,840 --> 00:30:30,400
If your data lives in SharePoint, use SPFX.

864
00:30:30,400 --> 00:30:31,840
Get your governance house in order.

865
00:30:31,840 --> 00:30:34,880
The investment pays itself back in operational simplicity.

866
00:30:34,880 --> 00:30:37,840
If your data is scattered across systems, use MCP.

867
00:30:37,840 --> 00:30:40,320
But budget for the security investment is not optional.

868
00:30:40,320 --> 00:30:42,000
Some organizations do both.

869
00:30:42,000 --> 00:30:44,480
They use SPFX for SharePoint centric workflows

870
00:30:44,480 --> 00:30:46,480
and MCP for cross-system orchestration.

871
00:30:46,480 --> 00:30:48,560
But that requires dual governance models.

872
00:30:48,560 --> 00:30:50,720
Two security patterns, two audit frameworks.

873
00:30:50,720 --> 00:30:51,760
That's only sustainable

874
00:30:51,760 --> 00:30:53,840
if you have the organizational maturity to manage it.

875
00:30:53,840 --> 00:30:55,040
The core insight is this.

876
00:30:55,040 --> 00:30:56,560
The agent fabric isn't one solution.

877
00:30:56,560 --> 00:30:58,320
It's a framework that chooses based

878
00:30:58,320 --> 00:30:59,760
on your governance constraints.

879
00:30:59,760 --> 00:31:01,360
And understanding those constraints right now

880
00:31:01,360 --> 00:31:03,360
determines whether you're building something sustainable

881
00:31:03,360 --> 00:31:05,680
or something you'll have to remediate later.

882
00:31:05,680 --> 00:31:07,840
The death of TeamsFX and the consolidation.

883
00:31:07,840 --> 00:31:10,240
There is a deprecation notice sitting in the documentation

884
00:31:10,240 --> 00:31:12,320
that most organizations haven't even registered yet.

885
00:31:12,320 --> 00:31:14,400
The TeamsFX SDK is going away.

886
00:31:14,400 --> 00:31:16,960
It will be fully retired by July 2026.

887
00:31:16,960 --> 00:31:19,680
If you have TeamsFX solutions running in production right now,

888
00:31:19,680 --> 00:31:21,520
you need to understand exactly what that means

889
00:31:21,520 --> 00:31:23,520
and why Microsoft is making this move.

890
00:31:23,520 --> 00:31:25,280
TeamsFX was originally positioned

891
00:31:25,280 --> 00:31:27,520
as the primary way to build Teams apps.

892
00:31:27,520 --> 00:31:29,920
It was an attempt to create a simplified developer experience

893
00:31:29,920 --> 00:31:31,280
for building custom applications

894
00:31:31,280 --> 00:31:33,600
that lived specifically inside the Teams client.

895
00:31:33,600 --> 00:31:36,720
Instead of dealing with the full complexity of the SharePoint framework,

896
00:31:36,720 --> 00:31:38,800
you could use TeamsFX to get templates

897
00:31:38,800 --> 00:31:40,400
and a much lighter toolkit.

898
00:31:40,400 --> 00:31:41,360
It made sense at the time

899
00:31:41,360 --> 00:31:42,480
because Teams was exploding

900
00:31:42,480 --> 00:31:45,360
and every organization wanted to build custom experiences

901
00:31:45,360 --> 00:31:46,320
for their channels.

902
00:31:46,320 --> 00:31:48,320
TeamsFX was supposed to make that easy,

903
00:31:48,320 --> 00:31:50,240
but the enterprise moved in a different direction.

904
00:31:50,240 --> 00:31:52,160
And that movement is what is killing TeamsFX.

905
00:31:52,160 --> 00:31:53,600
The shift is fundamental.

906
00:31:53,600 --> 00:31:55,920
Organizations stopped thinking about Teams apps

907
00:31:55,920 --> 00:31:56,800
as a distinct category

908
00:31:56,800 --> 00:31:58,800
and started thinking about co-pilot apps instead.

909
00:31:58,800 --> 00:32:00,160
These are experiences that operate

910
00:32:00,160 --> 00:32:01,920
through the AI orchestration layer

911
00:32:01,920 --> 00:32:04,480
rather than through a specific surface like a Teams tab.

912
00:32:04,480 --> 00:32:06,320
That is a different architecture entirely.

913
00:32:06,320 --> 00:32:07,680
The moment that shift happened,

914
00:32:07,680 --> 00:32:09,200
maintaining two separate frameworks

915
00:32:09,200 --> 00:32:12,160
like SPFX and TeamsFX became unnecessary overhead.

916
00:32:12,160 --> 00:32:13,360
Here is what it means practically.

917
00:32:13,360 --> 00:32:16,000
If you built a request approval app in TeamsFX,

918
00:32:16,000 --> 00:32:18,800
that app lived inside a specific Teams channel.

919
00:32:18,800 --> 00:32:20,480
Users had to navigate to the channel,

920
00:32:20,480 --> 00:32:22,240
open the app and fill out a form

921
00:32:22,240 --> 00:32:23,520
for the request to go through.

922
00:32:23,520 --> 00:32:25,440
It worked, but it only worked inside Teams.

923
00:32:25,440 --> 00:32:27,280
It was not discoverable through co-pilot,

924
00:32:27,280 --> 00:32:29,200
it was not accessible through SharePoint

925
00:32:29,200 --> 00:32:30,240
and it did not participate

926
00:32:30,240 --> 00:32:31,760
in the broader orchestration layer.

927
00:32:31,760 --> 00:32:33,280
It was a single surface solution.

928
00:32:33,280 --> 00:32:35,600
SPFX co-pilot apps changed that equation.

929
00:32:35,600 --> 00:32:36,880
The same approval experience

930
00:32:36,880 --> 00:32:38,720
can now surface inside co-pilot,

931
00:32:38,720 --> 00:32:39,760
inside SharePoint,

932
00:32:39,760 --> 00:32:42,400
or inside the Microsoft 365 app.

933
00:32:42,400 --> 00:32:43,760
You build the logic once

934
00:32:43,760 --> 00:32:46,400
and surface it everywhere the organization needs it.

935
00:32:46,400 --> 00:32:48,320
That is not just a marginal improvement.

936
00:32:48,320 --> 00:32:50,560
It is a different value proposition entirely.

937
00:32:50,560 --> 00:32:51,600
From that perspective,

938
00:32:51,600 --> 00:32:53,520
maintaining TeamsFX as a separate framework

939
00:32:53,520 --> 00:32:54,560
no longer makes sense.

940
00:32:54,560 --> 00:32:56,080
The framework that can do everything

941
00:32:56,080 --> 00:32:57,760
is the one you want to standardize on.

942
00:32:57,760 --> 00:33:00,000
So TeamsFX is being deprecated.

943
00:33:00,000 --> 00:33:02,000
If you have it in production, you have two paths.

944
00:33:02,000 --> 00:33:04,960
You can rewrite for SPFX 1.24

945
00:33:04,960 --> 00:33:07,600
to gain all that multi-surface capability.

946
00:33:07,600 --> 00:33:09,440
Or you can migrate to Power Apps.

947
00:33:09,440 --> 00:33:11,440
If your solution is heavy on business logic

948
00:33:11,440 --> 00:33:12,960
and light on custom UI,

949
00:33:12,960 --> 00:33:14,400
Power Apps is getting much better

950
00:33:14,400 --> 00:33:16,000
at building structured applications

951
00:33:16,000 --> 00:33:17,200
and it integrates directly

952
00:33:17,200 --> 00:33:19,040
with co-pilot studio for orchestration.

953
00:33:19,040 --> 00:33:20,800
The timing creates real pressure.

954
00:33:20,800 --> 00:33:23,200
July 2026 is the hard deadline

955
00:33:23,200 --> 00:33:25,680
and that is not as far away as it sounds.

956
00:33:25,680 --> 00:33:28,080
If you have a production TeamsFX application right now,

957
00:33:28,080 --> 00:33:30,000
you have roughly a year to decide on a path

958
00:33:30,000 --> 00:33:31,280
and execute the migration.

959
00:33:31,280 --> 00:33:32,480
Delaying does not make sense

960
00:33:32,480 --> 00:33:34,560
because the work won't get easier if you wait.

961
00:33:34,560 --> 00:33:35,440
The sooner you move,

962
00:33:35,440 --> 00:33:37,520
the sooner you can take advantage of the capabilities

963
00:33:37,520 --> 00:33:38,800
that come with the new architecture.

964
00:33:38,800 --> 00:33:40,480
But here is what actually matters about this.

965
00:33:40,480 --> 00:33:43,440
The TeamsFX deprecation is not just a technology problem.

966
00:33:43,440 --> 00:33:45,840
It is an opportunity because the forced migration

967
00:33:45,840 --> 00:33:47,760
is exactly the moment to re-architect

968
00:33:47,760 --> 00:33:49,360
how you think about these solutions.

969
00:33:49,360 --> 00:33:51,200
Instead of just patching your existing app

970
00:33:51,200 --> 00:33:52,400
and moving it to SPFX,

971
00:33:52,400 --> 00:33:53,520
you can step back and ask

972
00:33:53,520 --> 00:33:55,200
what the application is actually trying to do.

973
00:33:55,200 --> 00:33:57,920
Is it better modeled as an SPFX component exposed

974
00:33:57,920 --> 00:33:59,040
through co-pilot?

975
00:33:59,040 --> 00:34:00,400
Is it actually a business process

976
00:34:00,400 --> 00:34:01,920
that belongs in Power Apps

977
00:34:01,920 --> 00:34:03,680
with governance-driven automation?

978
00:34:03,680 --> 00:34:05,520
Does it need to orchestrate across systems?

979
00:34:05,520 --> 00:34:07,760
Which might mean building an MCP server instead?

980
00:34:07,760 --> 00:34:09,920
The people writing TeamsFX code right now

981
00:34:09,920 --> 00:34:12,480
are about to make a career inflection point decision.

982
00:34:12,480 --> 00:34:14,080
You can upskill to SPFX

983
00:34:14,080 --> 00:34:15,920
and become an agentex UX developer

984
00:34:15,920 --> 00:34:17,600
who builds the interactive components

985
00:34:17,600 --> 00:34:19,920
that operationalize enterprise intelligence.

986
00:34:19,920 --> 00:34:22,320
That is a growing market where all the investment is going.

987
00:34:22,320 --> 00:34:24,080
Or you can pivot toward Power Apps

988
00:34:24,080 --> 00:34:25,840
and become a business process architect.

989
00:34:25,840 --> 00:34:27,600
That is also a massive growth area

990
00:34:27,600 --> 00:34:29,120
but you cannot stay in TeamsFX

991
00:34:29,120 --> 00:34:30,240
that door is closing.

992
00:34:30,240 --> 00:34:31,760
And that closure is a signal

993
00:34:31,760 --> 00:34:33,520
about the bigger structural shift.

994
00:34:33,520 --> 00:34:36,240
Microsoft is consolidating its extensibility stack.

995
00:34:36,240 --> 00:34:39,360
The future is not multiple frameworks for multiple surfaces.

996
00:34:39,360 --> 00:34:42,320
It is unified orchestration through the agent fabric

997
00:34:42,320 --> 00:34:44,720
with SPFX as the primary mechanism

998
00:34:44,720 --> 00:34:46,800
for interactive components and Power Apps

999
00:34:46,800 --> 00:34:49,200
as the primary mechanism for business logic.

1000
00:34:49,200 --> 00:34:50,960
That consolidation makes sense.

1001
00:34:50,960 --> 00:34:52,640
It reduces complexity

1002
00:34:52,640 --> 00:34:55,200
and aligns everything around a coherent architecture.

1003
00:34:55,200 --> 00:34:57,120
It reveals what the next generation

1004
00:34:57,120 --> 00:34:59,520
of enterprise development actually looks like.

1005
00:34:59,520 --> 00:35:00,720
The security hardening,

1006
00:35:00,720 --> 00:35:02,720
CSP enforcement and beyond.

1007
00:35:02,720 --> 00:35:04,080
There is another date on the calendar

1008
00:35:04,080 --> 00:35:06,560
that matters just as much as the TeamsFX deadline.

1009
00:35:06,560 --> 00:35:08,400
And it is going to break a lot of assumptions

1010
00:35:08,400 --> 00:35:11,200
about how you have been building SPFX solutions.

1011
00:35:11,200 --> 00:35:13,200
On March 1st, 2026,

1012
00:35:13,200 --> 00:35:15,280
Content Security Policy Enforcement moves

1013
00:35:15,280 --> 00:35:18,560
from report-only mode to enforced mode in SharePoint Online.

1014
00:35:18,560 --> 00:35:19,680
What does that actually mean?

1015
00:35:19,680 --> 00:35:23,280
Right now, if an SPFX solution loads a script from a CDN

1016
00:35:23,280 --> 00:35:24,800
that is not on the approved list,

1017
00:35:24,800 --> 00:35:26,240
SharePoint logs the event.

1018
00:35:26,240 --> 00:35:28,080
It reports it but it does not block it.

1019
00:35:28,080 --> 00:35:30,800
The script still runs and the solution still works.

1020
00:35:30,800 --> 00:35:32,160
You might get a warning in the console

1021
00:35:32,160 --> 00:35:34,240
but nothing actually breaks for the end user.

1022
00:35:34,240 --> 00:35:36,080
Starting March 1st, that changes.

1023
00:35:36,080 --> 00:35:38,160
Inline scripts will be blocked outright.

1024
00:35:38,160 --> 00:35:40,240
External scripts will have to be explicitly registered

1025
00:35:40,240 --> 00:35:41,840
as trusted script sources

1026
00:35:41,840 --> 00:35:43,280
in the SharePoint Admin Center.

1027
00:35:43,280 --> 00:35:45,040
If a script is not on that approved list,

1028
00:35:45,040 --> 00:35:47,200
the browser will simply refuse to execute it.

1029
00:35:47,200 --> 00:35:49,280
The violation will get logged in per view audit

1030
00:35:49,280 --> 00:35:50,800
so you can see what was attempted

1031
00:35:50,800 --> 00:35:52,640
but the code itself will not run.

1032
00:35:52,640 --> 00:35:53,840
This matters for SPFX

1033
00:35:53,840 --> 00:35:56,480
because many existing solutions rely on loading libraries

1034
00:35:56,480 --> 00:35:58,240
from external CDNs like JQuery

1035
00:35:58,240 --> 00:35:59,840
or specialized charting helpers.

1036
00:35:59,840 --> 00:36:02,560
If those sources are not pre-registered as trusted,

1037
00:36:02,560 --> 00:36:04,720
they will stop working and the solution will break.

1038
00:36:04,720 --> 00:36:07,680
Users will see incomplete functionality or errors on the page.

1039
00:36:07,680 --> 00:36:09,920
It is not just a security issue at that point.

1040
00:36:09,920 --> 00:36:11,840
It is a total loss of capability.

1041
00:36:11,840 --> 00:36:13,920
If you have SPFX solutions in production right now,

1042
00:36:13,920 --> 00:36:15,920
you need to audit your dependencies immediately.

1043
00:36:15,920 --> 00:36:18,400
You need to know what external scripts you are loading

1044
00:36:18,400 --> 00:36:19,840
and where they are hosted.

1045
00:36:19,840 --> 00:36:22,720
This is the work that must happen between now and March 1st.

1046
00:36:22,720 --> 00:36:25,520
If you discover a dependency that is not trusted,

1047
00:36:25,520 --> 00:36:28,800
you can register the source, move the code to a trusted host

1048
00:36:28,800 --> 00:36:32,240
or refactor the solution to eliminate the dependency entirely.

1049
00:36:32,240 --> 00:36:34,800
But you have to know about it before the enforcement date hits.

1050
00:36:34,800 --> 00:36:37,440
The governance implication is what makes this architectural.

1051
00:36:37,440 --> 00:36:39,280
CSP is becoming a central control

1052
00:36:39,280 --> 00:36:41,040
for what code can execute in your tenant.

1053
00:36:41,040 --> 00:36:43,280
Microsoft is not just blocking random scripts.

1054
00:36:43,280 --> 00:36:45,600
They are enforcing a white list of approved sources.

1055
00:36:45,600 --> 00:36:48,000
That is a governance model that applies uniformly

1056
00:36:48,000 --> 00:36:49,520
across the entire tenant.

1057
00:36:49,520 --> 00:36:52,960
Here is where the SPFX security model is actually quite elegant.

1058
00:36:52,960 --> 00:36:56,080
SPFX solutions do not run with elevated privileges.

1059
00:36:56,080 --> 00:36:58,560
They run with the user's identity and permissions.

1060
00:36:58,560 --> 00:37:02,960
When a component executes, it can only do what that specific user is allowed to do manually.

1061
00:37:02,960 --> 00:37:05,040
The security boundary is the user's permissions,

1062
00:37:05,040 --> 00:37:06,480
not the code's privileges.

1063
00:37:06,480 --> 00:37:09,760
That is different from systems where code runs with service account privileges,

1064
00:37:09,760 --> 00:37:11,040
which would be much riskier.

1065
00:37:11,040 --> 00:37:13,440
SPFX is delegation based by design.

1066
00:37:13,440 --> 00:37:15,920
The code inherits the user's permission context.

1067
00:37:15,920 --> 00:37:17,280
But here is the part that matters.

1068
00:37:17,280 --> 00:37:19,120
CSP controls whether code runs at all,

1069
00:37:19,120 --> 00:37:22,480
while DLP controls what that code can do with data once it is running.

1070
00:37:22,480 --> 00:37:25,840
You can build an SPFX component that is perfectly CSP compliant

1071
00:37:25,840 --> 00:37:28,000
where every script comes from a trusted source.

1072
00:37:28,000 --> 00:37:30,880
But that component could still send data to an external API

1073
00:37:30,880 --> 00:37:32,160
if the browser can reach it,

1074
00:37:32,160 --> 00:37:34,880
and your DLP policy does not block the traffic.

1075
00:37:34,880 --> 00:37:37,200
CSP does not prevent data exfiltration.

1076
00:37:37,200 --> 00:37:39,200
It only controls code execution.

1077
00:37:39,200 --> 00:37:40,880
Those are two different layers of the stack.

1078
00:37:40,880 --> 00:37:45,040
So the real security question is not just whether your solution is compliant with CSP.

1079
00:37:45,040 --> 00:37:47,040
The real question is where that code can send data

1080
00:37:47,040 --> 00:37:49,440
and whether you have restricted those flows with DLP.

1081
00:37:49,440 --> 00:37:51,520
The mitigation layers are very specific.

1082
00:37:51,520 --> 00:37:54,080
First, you must classify your data systematically

1083
00:37:54,080 --> 00:37:56,560
because you cannot protect what you haven't identified.

1084
00:37:56,560 --> 00:37:58,560
Apply sensitivity labels to high-risk content

1085
00:37:58,560 --> 00:38:01,760
and configure DLP policies that are scoped to co-pilot interactions.

1086
00:38:01,760 --> 00:38:05,040
If you have a policy that says not to share data with external systems,

1087
00:38:05,040 --> 00:38:07,520
make sure it applies when data flows through co-pilot.

1088
00:38:07,520 --> 00:38:10,240
Monitor external API calls from your SPFX components.

1089
00:38:10,240 --> 00:38:11,920
If you see requests going to domains,

1090
00:38:11,920 --> 00:38:14,320
you do not recognize you need to investigate them.

1091
00:38:14,320 --> 00:38:17,360
This is where security becomes a first-class design concern

1092
00:38:17,360 --> 00:38:18,800
rather than an afterthought.

1093
00:38:18,800 --> 00:38:21,280
You are no longer just asking if a component works.

1094
00:38:21,280 --> 00:38:23,360
You are asking where that component sends data

1095
00:38:23,360 --> 00:38:24,960
and if that flow is authorized.

1096
00:38:24,960 --> 00:38:27,440
The CSP Enforcement Deadline is a forcing function.

1097
00:38:27,440 --> 00:38:30,720
It makes you audit your scripts, discover your dependencies

1098
00:38:30,720 --> 00:38:32,320
and register what is trusted.

1099
00:38:32,320 --> 00:38:34,720
By doing that, you build the governance discipline you need

1100
00:38:34,720 --> 00:38:37,040
for the agent fabric to work safely at scale.

1101
00:38:37,040 --> 00:38:39,360
Governance first, the permission audit.

1102
00:38:39,360 --> 00:38:41,920
You've decided to move forward with the agent fabric.

1103
00:38:41,920 --> 00:38:45,760
You've picked your architecture, SPFX, MCP, or a mix of both.

1104
00:38:45,760 --> 00:38:47,280
You've mapped out the licensing.

1105
00:38:47,280 --> 00:38:48,800
You've hardened your CSP.

1106
00:38:48,800 --> 00:38:51,520
Now comes the part most organizations try to ignore

1107
00:38:51,520 --> 00:38:54,080
because it isn't flashy or technically elegant.

1108
00:38:54,080 --> 00:38:56,000
Before you turn on co-pilot for everyone,

1109
00:38:56,000 --> 00:38:58,640
you have to know what your SharePoint actually looks like.

1110
00:38:58,640 --> 00:39:00,560
Not the clean version you have in your head,

1111
00:39:00,560 --> 00:39:02,560
but the messy version that exists in reality,

1112
00:39:02,560 --> 00:39:03,760
this is the audit phase.

1113
00:39:03,760 --> 00:39:05,040
And it is not optional.

1114
00:39:05,040 --> 00:39:06,720
You start in the SharePoint Admin Center

1115
00:39:06,720 --> 00:39:08,480
with Data Access Governance Reports.

1116
00:39:08,480 --> 00:39:10,720
You aren't looking for tiny individual errors here.

1117
00:39:10,720 --> 00:39:12,400
You're looking for structural patterns.

1118
00:39:12,400 --> 00:39:13,680
When you run that DAG report,

1119
00:39:13,680 --> 00:39:15,920
look closely at the distribution of access.

1120
00:39:15,920 --> 00:39:18,720
You'll see exactly which sites are shared with too many people,

1121
00:39:18,720 --> 00:39:20,160
where inheritance is broken

1122
00:39:20,160 --> 00:39:22,000
and where external sharing is wide open.

1123
00:39:22,000 --> 00:39:25,040
What you're hunting for are sites that are broadly shared for no reason.

1124
00:39:25,040 --> 00:39:28,000
Maybe it's a project site shared with everyone in the organization

1125
00:39:28,000 --> 00:39:30,320
because a consultant needed a file four years ago.

1126
00:39:30,320 --> 00:39:32,400
Maybe it's a finance folder left open to everyone

1127
00:39:32,400 --> 00:39:34,480
because managing groups felt too slow.

1128
00:39:34,480 --> 00:39:37,120
Maybe it's a classified library sitting inside a research site

1129
00:39:37,120 --> 00:39:39,680
with default permissions that let anyone wander in.

1130
00:39:39,680 --> 00:39:42,480
These aren't security breaches in the traditional sense.

1131
00:39:42,480 --> 00:39:43,520
They're permission drift.

1132
00:39:43,520 --> 00:39:46,480
It's a slow accumulation of access that stays invisible

1133
00:39:46,480 --> 00:39:48,080
until something forces you to look at it.

1134
00:39:48,080 --> 00:39:49,920
Co-pilot forces you to look immediately.

1135
00:39:49,920 --> 00:39:51,520
Once you find these overshared sites,

1136
00:39:51,520 --> 00:39:53,760
you have to follow a specific sequence to fix them.

1137
00:39:53,760 --> 00:39:55,920
First, you kill the broad sharing.

1138
00:39:55,920 --> 00:39:57,680
Everyone becomes a specific group

1139
00:39:57,680 --> 00:40:01,600
and anyone with the link becomes people I explicitly approved.

1140
00:40:01,600 --> 00:40:03,200
You aren't changing the content itself.

1141
00:40:03,200 --> 00:40:05,360
You're just fixing the boundary of who can see it.

1142
00:40:05,360 --> 00:40:08,000
Second, you layer in restricted access control

1143
00:40:08,000 --> 00:40:09,520
for your most sensitive sites.

1144
00:40:09,520 --> 00:40:11,200
Think of RAC as a fortress mode,

1145
00:40:11,200 --> 00:40:14,080
where you explicitly state that only specific groups can enter

1146
00:40:14,080 --> 00:40:16,640
and no one else can be added without a major escalation.

1147
00:40:16,640 --> 00:40:18,480
You use this for the high-risk stuff.

1148
00:40:18,480 --> 00:40:21,680
Mergers executive strategy or sensitive financial data

1149
00:40:21,680 --> 00:40:23,600
where you need absolute certainty.

1150
00:40:23,600 --> 00:40:25,600
Third, you use restricted content discovery

1151
00:40:25,600 --> 00:40:27,840
to hide certain sites from co-pilot entirely.

1152
00:40:27,840 --> 00:40:29,280
If a site is already locked down,

1153
00:40:29,280 --> 00:40:30,640
but you want an extra layer of safety,

1154
00:40:30,640 --> 00:40:32,800
you tell co-pilot not to index it at all.

1155
00:40:32,800 --> 00:40:35,440
Users can still find those files through a normal search,

1156
00:40:35,440 --> 00:40:38,240
but co-pilot will never use them as a source for an answer.

1157
00:40:38,240 --> 00:40:39,520
Then comes the labeling.

1158
00:40:39,520 --> 00:40:41,600
This is where you define what your data actually is.

1159
00:40:41,600 --> 00:40:43,360
You deploy sensitivity labels,

1160
00:40:43,360 --> 00:40:45,120
like confidential, internal, or public,

1161
00:40:45,120 --> 00:40:46,480
and you make the mandatory.

1162
00:40:46,480 --> 00:40:48,480
New documents can't be saved without a label,

1163
00:40:48,480 --> 00:40:50,880
and existing files get classified through automation

1164
00:40:50,880 --> 00:40:51,920
or manual review.

1165
00:40:51,920 --> 00:40:54,400
For the highest risk data, you apply encryption.

1166
00:40:54,400 --> 00:40:57,120
If a document is labeled confidential and encrypted,

1167
00:40:57,120 --> 00:40:59,360
only specific users can actually read it.

1168
00:40:59,360 --> 00:41:01,920
Co-pilot can still index the file for search,

1169
00:41:01,920 --> 00:41:03,680
but the actual content stays protected

1170
00:41:03,680 --> 00:41:05,200
behind that encryption layer.

1171
00:41:05,200 --> 00:41:06,800
Your DLP strategy sits on top of this.

1172
00:41:06,800 --> 00:41:09,760
You create policies specifically for co-pilot interactions,

1173
00:41:09,760 --> 00:41:11,680
like a rule that blocks the AI

1174
00:41:11,680 --> 00:41:14,720
if it tries to touch a document containing social security numbers.

1175
00:41:14,720 --> 00:41:17,840
You start an audit mode to watch the patterns without breaking anything.

1176
00:41:17,840 --> 00:41:19,920
And after a few weeks of monitoring the logs,

1177
00:41:19,920 --> 00:41:21,040
you move to active blocking.

1178
00:41:21,040 --> 00:41:22,560
This isn't a one-time project.

1179
00:41:22,560 --> 00:41:24,000
It's a baseline you have to maintain.

1180
00:41:24,000 --> 00:41:25,840
You should be running DAG reports every quarter

1181
00:41:25,840 --> 00:41:28,160
and checking your DLP match rates constantly.

1182
00:41:28,160 --> 00:41:30,720
If you see a spike in violations for a specific team,

1183
00:41:30,720 --> 00:41:32,560
you investigate and tighten the screws.

1184
00:41:32,560 --> 00:41:34,640
The timeline is the most important part here.

1185
00:41:34,640 --> 00:41:36,880
You need this foundation solid before co-pilot goes wide,

1186
00:41:36,880 --> 00:41:38,640
because once the AI is out there,

1187
00:41:38,640 --> 00:41:40,960
trying to retrofit governance is almost impossible.

1188
00:41:40,960 --> 00:41:44,400
The agent fabric, what it actually means.

1189
00:41:44,400 --> 00:41:46,320
Now we need to name what we're actually building,

1190
00:41:46,320 --> 00:41:48,000
because the licensing, the architecture,

1191
00:41:48,000 --> 00:41:51,600
and the permission audits all lead to one place, the agent fabric.

1192
00:41:51,600 --> 00:41:54,240
People use that term a lot and usually it's pretty vague.

1193
00:41:54,240 --> 00:41:56,800
So let's be concrete about what it is, how it works,

1194
00:41:56,800 --> 00:41:58,640
and why your governance foundation matters

1195
00:41:58,640 --> 00:42:00,080
to every single layer of it.

1196
00:42:00,080 --> 00:42:01,840
The agent fabric is the infrastructure

1197
00:42:01,840 --> 00:42:03,920
that lets AI agents work across your business

1198
00:42:03,920 --> 00:42:05,360
while respecting your boundaries.

1199
00:42:05,360 --> 00:42:07,760
It isn't a way for AI to bypass your security.

1200
00:42:07,760 --> 00:42:10,320
It's the system that forces AI to operate inside of it.

1201
00:42:10,320 --> 00:42:11,760
The components are very specific.

1202
00:42:11,760 --> 00:42:12,960
Identity is the floor.

1203
00:42:12,960 --> 00:42:15,520
Entra ID, that's where you verify who the user is.

1204
00:42:15,520 --> 00:42:17,040
Authorization is the next layer.

1205
00:42:17,040 --> 00:42:18,720
This isn't just checking a group membership.

1206
00:42:18,720 --> 00:42:20,160
It's checking SharePoint permissions,

1207
00:42:20,160 --> 00:42:22,960
sensitivity labels, and DLP policies.

1208
00:42:22,960 --> 00:42:26,320
Every time an agent touches data, the system checks if it's allowed to.

1209
00:42:26,320 --> 00:42:27,200
Ordered is the memory.

1210
00:42:27,200 --> 00:42:29,440
Microsoft Perview logs every tool call

1211
00:42:29,440 --> 00:42:31,120
and every action the agent takes.

1212
00:42:31,120 --> 00:42:32,720
This isn't for compliance theatre.

1213
00:42:32,720 --> 00:42:36,400
It's so you actually understand what the system did and why it did it.

1214
00:42:36,400 --> 00:42:37,920
Orchestration is the engine.

1215
00:42:37,920 --> 00:42:40,880
This is co-pilot, power automate, or co-pilot studio.

1216
00:42:40,880 --> 00:42:43,360
These platforms are the interface between what the human needs

1217
00:42:43,360 --> 00:42:45,360
and what the tool actually executes.

1218
00:42:45,360 --> 00:42:47,120
But here's the reality most people miss.

1219
00:42:47,120 --> 00:42:48,960
An agent doesn't think of itself as an agent.

1220
00:42:48,960 --> 00:42:50,720
It isn't a separate autonomous entity.

1221
00:42:50,720 --> 00:42:53,120
It's just a co-pilot instance with access to a toolbox.

1222
00:42:53,120 --> 00:42:56,000
Those tools might be SPFX components in your tenant,

1223
00:42:56,000 --> 00:42:58,720
MCP server sitting outside, or power automate flows.

1224
00:42:58,720 --> 00:43:00,880
But to the agent, they're just functions it can call.

1225
00:43:00,880 --> 00:43:01,760
You ask a question.

1226
00:43:01,760 --> 00:43:02,880
The agent reasons through it.

1227
00:43:02,880 --> 00:43:05,520
It decides it needs a specific tool to answer you.

1228
00:43:05,520 --> 00:43:06,560
It calls that tool.

1229
00:43:06,560 --> 00:43:08,960
The tool sends back data or an interactive card

1230
00:43:08,960 --> 00:43:10,000
and the agent shows it to you.

1231
00:43:10,000 --> 00:43:11,920
You click a button, the result flows back,

1232
00:43:11,920 --> 00:43:13,680
and the agent finishes its thought.

1233
00:43:13,680 --> 00:43:15,680
That cycle is the agent fabric in action.

1234
00:43:15,680 --> 00:43:19,200
The governance model is the only thing that makes this safe for a real company.

1235
00:43:19,200 --> 00:43:21,760
Every action is logged, every call is audited,

1236
00:43:21,760 --> 00:43:23,840
and every piece of data is permission trimmed.

1237
00:43:23,840 --> 00:43:26,240
If the agent tries to grab a file you aren't allowed to see,

1238
00:43:26,240 --> 00:43:27,920
the permission check fails instantly.

1239
00:43:27,920 --> 00:43:29,360
The tool returns nothing,

1240
00:43:29,360 --> 00:43:31,280
and the agent can't show you the secret.

1241
00:43:31,280 --> 00:43:33,040
And none of this happens without you.

1242
00:43:33,040 --> 00:43:36,000
If an agent is supposed to update a list or modify a document,

1243
00:43:36,000 --> 00:43:37,120
there are checkpoints.

1244
00:43:37,120 --> 00:43:38,320
You build in approval steps

1245
00:43:38,320 --> 00:43:41,200
so the agent can't act unilaterally on your behalf.

1246
00:43:41,200 --> 00:43:42,240
Why does this matter?

1247
00:43:42,240 --> 00:43:44,960
Because this is the shift from chat to orchestration.

1248
00:43:44,960 --> 00:43:46,240
The old model was simple.

1249
00:43:46,240 --> 00:43:48,320
You type a question, get some text back,

1250
00:43:48,320 --> 00:43:50,320
and then you go do the work yourself.

1251
00:43:50,320 --> 00:43:51,760
The interface was conversational,

1252
00:43:51,760 --> 00:43:53,760
but the actual execution was manual.

1253
00:43:53,760 --> 00:43:55,840
You had to leave the chat to get anything done.

1254
00:43:55,840 --> 00:43:57,280
The agent fabric changes that.

1255
00:43:57,280 --> 00:43:58,640
You're still talking to an agent,

1256
00:43:58,640 --> 00:44:00,880
but now the agent can actually move the gears.

1257
00:44:00,880 --> 00:44:03,120
It surfaces interactive components right in the chat

1258
00:44:03,120 --> 00:44:05,520
so you can finish a task without switching tabs.

1259
00:44:05,520 --> 00:44:07,520
The distance between "I need to do this"

1260
00:44:07,520 --> 00:44:08,640
and "this is done"

1261
00:44:08,640 --> 00:44:09,920
drops from hours to seconds.

1262
00:44:09,920 --> 00:44:12,160
The business outcome is obvious.

1263
00:44:12,160 --> 00:44:13,760
Workflows that used to take half a day

1264
00:44:13,760 --> 00:44:14,720
now take five minutes.

1265
00:44:14,720 --> 00:44:16,640
Data lookups that require digging through folders

1266
00:44:16,640 --> 00:44:17,680
now just appear.

1267
00:44:17,680 --> 00:44:19,520
Status updates that used to mean opening

1268
00:44:19,520 --> 00:44:21,840
three different systems now happen in one click.

1269
00:44:21,840 --> 00:44:22,800
But there is a catch.

1270
00:44:22,800 --> 00:44:24,000
If your governance is weak,

1271
00:44:24,000 --> 00:44:25,520
the agent fabric won't fix it.

1272
00:44:25,520 --> 00:44:26,640
It will amplify it.

1273
00:44:26,640 --> 00:44:29,200
Bad permissions become visible the second you turn this on.

1274
00:44:29,200 --> 00:44:31,600
Poor data classification becomes a total blocker.

1275
00:44:31,600 --> 00:44:34,240
Missing audits become a massive liability.

1276
00:44:34,240 --> 00:44:35,840
That's why governance has to come first.

1277
00:44:35,840 --> 00:44:37,600
The agent fabric is a powerful engine,

1278
00:44:37,600 --> 00:44:40,240
but it only works if the tracks are laid down correctly.

1279
00:44:40,240 --> 00:44:42,160
If this shift from chat to orchestration

1280
00:44:42,160 --> 00:44:43,760
changed how you think about AI.

1281
00:44:43,760 --> 00:44:45,600
Follow me, Mucopeter's on LinkedIn,

1282
00:44:45,600 --> 00:44:47,040
and if you want more of this,

1283
00:44:47,040 --> 00:44:47,840
leave a review.

1284
00:44:47,840 --> 00:44:49,760
It helps more people find the show.

1285
00:44:49,760 --> 00:44:51,040
Share this with your team,

1286
00:44:51,040 --> 00:44:53,440
especially if you're dealing with these permission issues right now.

1287
00:44:53,440 --> 00:44:56,080
Why governance must precede architecture?

1288
00:44:56,080 --> 00:44:58,720
The entire framework breaks if you get the sequence wrong.

1289
00:44:58,720 --> 00:45:01,040
Most organizations make this mistake when they start.

1290
00:45:01,040 --> 00:45:02,000
It looks like this.

1291
00:45:02,000 --> 00:45:04,320
You get budget approval for co-pilot licenses.

1292
00:45:04,320 --> 00:45:06,320
You're excited about the productivity gains.

1293
00:45:06,320 --> 00:45:07,200
You buy the seats.

1294
00:45:07,200 --> 00:45:08,160
You enable the feature.

1295
00:45:08,160 --> 00:45:09,440
You train a few teams.

1296
00:45:09,440 --> 00:45:11,520
And then you wait for the ROI to show up,

1297
00:45:11,520 --> 00:45:12,320
but it doesn't.

1298
00:45:12,320 --> 00:45:14,800
Teams use co-pilot for a few weeks and the novelty wears off.

1299
00:45:14,800 --> 00:45:15,680
Adoption plateaus.

1300
00:45:15,680 --> 00:45:18,480
You're paying for licenses that people aren't actually using.

1301
00:45:18,480 --> 00:45:20,320
The ROI story just evaporates.

1302
00:45:20,320 --> 00:45:21,600
The reason this happens

1303
00:45:21,600 --> 00:45:23,280
isn't because co-pilot doesn't work.

1304
00:45:23,280 --> 00:45:24,960
It's because you skipped the prerequisite.

1305
00:45:24,960 --> 00:45:26,560
You tried to build the architecture

1306
00:45:26,560 --> 00:45:28,560
before the governance foundation was in place.

1307
00:45:28,560 --> 00:45:29,840
And without that foundation,

1308
00:45:29,840 --> 00:45:32,640
the architecture becomes a liability instead of an asset.

1309
00:45:32,640 --> 00:45:34,160
When I say governance foundation,

1310
00:45:34,160 --> 00:45:36,160
I'm not talking about a compliance checkbox.

1311
00:45:36,160 --> 00:45:38,800
So I'm not talking about a policy document that sits on a shelf.

1312
00:45:38,800 --> 00:45:40,640
So I'm talking about an operational reality.

1313
00:45:40,640 --> 00:45:42,400
It means your permissions are actually clear.

1314
00:45:42,400 --> 00:45:44,880
You can look at a site and know exactly who should have access

1315
00:45:44,880 --> 00:45:45,680
and who shouldn't.

1316
00:45:45,680 --> 00:45:47,760
It means your sensitive data is classified

1317
00:45:47,760 --> 00:45:49,360
so you know what needs protection.

1318
00:45:49,360 --> 00:45:52,800
It means you have DLP policies that actually prevent violations

1319
00:45:52,800 --> 00:45:54,480
instead of just logging them after the fact.

1320
00:45:54,480 --> 00:45:56,720
That means your audit trail is complete and trustworthy

1321
00:45:56,720 --> 00:45:57,920
when you have that foundation.

1322
00:45:57,920 --> 00:46:00,320
You can build the agent fabric on top of it with confidence.

1323
00:46:00,320 --> 00:46:02,240
When you don't, you're building on sand.

1324
00:46:02,240 --> 00:46:04,000
The sequence is non-negotiable.

1325
00:46:04,000 --> 00:46:05,760
Governance first, then architecture,

1326
00:46:05,760 --> 00:46:07,680
then implementation, skip governance,

1327
00:46:07,680 --> 00:46:09,360
and everything else becomes fragile.

1328
00:46:09,360 --> 00:46:12,000
There is a structural problem that makes this harder than it sounds.

1329
00:46:12,000 --> 00:46:13,760
Most organizations built their sharepoint

1330
00:46:13,760 --> 00:46:16,080
around a permission model that made sense 10 years ago.

1331
00:46:16,080 --> 00:46:16,720
It's flat.

1332
00:46:16,720 --> 00:46:18,080
The default is broad access.

1333
00:46:18,080 --> 00:46:20,880
Everyone in the organization gets access to most sites.

1334
00:46:20,880 --> 00:46:23,200
That model works fine when people are navigating manually

1335
00:46:23,200 --> 00:46:24,480
and searching for content.

1336
00:46:24,480 --> 00:46:26,960
But it breaks immediately when you introduce an AI system

1337
00:46:26,960 --> 00:46:29,280
that can surface any content to any user

1338
00:46:29,280 --> 00:46:30,240
with a single prompt.

1339
00:46:30,240 --> 00:46:33,360
At the same time, compliance requirements have gotten more sophisticated.

1340
00:46:33,360 --> 00:46:36,560
You have regulations that say certain data can only be accessed by certain people.

1341
00:46:36,560 --> 00:46:40,240
You have internal policies that say executive strategy documents

1342
00:46:40,240 --> 00:46:42,000
shouldn't be visible to operational staff.

1343
00:46:42,000 --> 00:46:43,520
So you have a structural mismatch.

1344
00:46:43,520 --> 00:46:44,880
Your permission model is flat.

1345
00:46:44,880 --> 00:46:46,720
Your compliance requirements are hierarchical.

1346
00:46:46,720 --> 00:46:48,880
For years, people could work around that gap

1347
00:46:48,880 --> 00:46:50,560
because navigation was manual.

1348
00:46:50,560 --> 00:46:53,440
You'd search for something, find some documents, and move on.

1349
00:46:53,440 --> 00:46:55,600
If you stumbled onto something you shouldn't see,

1350
00:46:55,600 --> 00:46:57,040
it wasn't a systemic problem.

1351
00:46:57,040 --> 00:46:59,200
Copilot makes that gap visible immediately.

1352
00:46:59,200 --> 00:47:01,440
Suddenly, data that was technically accessible

1353
00:47:01,440 --> 00:47:03,760
but practically hidden is one prompt away.

1354
00:47:03,760 --> 00:47:05,360
The friction of navigation and search,

1355
00:47:05,360 --> 00:47:07,360
the thing that was actually protecting compliance,

1356
00:47:07,360 --> 00:47:08,320
disappears.

1357
00:47:08,320 --> 00:47:09,760
The fix requires months of work.

1358
00:47:09,760 --> 00:47:12,320
You implement restricted access control on sensitive sites,

1359
00:47:12,320 --> 00:47:14,160
so access is explicit and limited.

1360
00:47:14,160 --> 00:47:16,080
You apply sensitivity labels to data

1361
00:47:16,080 --> 00:47:17,680
so you know what needs protection.

1362
00:47:17,680 --> 00:47:19,120
You use restricted content discovery

1363
00:47:19,120 --> 00:47:22,400
so certain categories of data aren't indexed by copilot at all.

1364
00:47:22,400 --> 00:47:23,760
This work can't be rushed.

1365
00:47:23,760 --> 00:47:26,480
It requires IT to understand the permission structure.

1366
00:47:26,480 --> 00:47:29,920
It requires security to understand the compliance requirements.

1367
00:47:29,920 --> 00:47:32,720
It requires business to weigh in on which data is sensitive.

1368
00:47:32,720 --> 00:47:34,000
It's not a technical project.

1369
00:47:34,000 --> 00:47:35,520
It's an organizational alignment project.

1370
00:47:35,520 --> 00:47:36,640
The cost is real.

1371
00:47:36,640 --> 00:47:37,280
It's budget.

1372
00:47:37,280 --> 00:47:37,760
It's time.

1373
00:47:37,760 --> 00:47:38,960
It's cross-functional meetings.

1374
00:47:38,960 --> 00:47:40,400
It's decisions made and remade.

1375
00:47:40,400 --> 00:47:41,520
And here's the hard part.

1376
00:47:41,520 --> 00:47:43,440
The July 1st licensing deadline

1377
00:47:43,440 --> 00:47:45,760
doesn't care whether your governance foundation is ready.

1378
00:47:45,760 --> 00:47:47,200
The deadline is coming regardless.

1379
00:47:47,200 --> 00:47:48,080
So you face a choice.

1380
00:47:48,080 --> 00:47:49,760
You can invest in governance now,

1381
00:47:49,760 --> 00:47:51,840
which means delaying your copilot rollout

1382
00:47:51,840 --> 00:47:52,640
by several months

1383
00:47:52,640 --> 00:47:54,640
but setting yourself up for real value.

1384
00:47:54,640 --> 00:47:57,680
Or you can ignore governance and rollout copilot broadly today

1385
00:47:57,680 --> 00:47:59,600
knowing that you'll either get minimal adoption

1386
00:47:59,600 --> 00:48:00,400
or worse.

1387
00:48:00,400 --> 00:48:01,840
You'll discover compliance problems

1388
00:48:01,840 --> 00:48:03,520
that force expensive remediation.

1389
00:48:03,520 --> 00:48:04,800
That's the decision point.

1390
00:48:04,800 --> 00:48:07,840
And it has to be made consciously, not accidentally.

1391
00:48:07,840 --> 00:48:09,600
The developer career inflection.

1392
00:48:09,600 --> 00:48:11,600
For a decade, the job title was clear.

1393
00:48:11,600 --> 00:48:13,360
You were a SharePoint developer.

1394
00:48:13,360 --> 00:48:14,640
Or maybe a team's developer.

1395
00:48:14,640 --> 00:48:16,480
Your work was about building interfaces.

1396
00:48:16,480 --> 00:48:17,600
You took business requirements

1397
00:48:17,600 --> 00:48:18,960
for what the page should look like.

1398
00:48:18,960 --> 00:48:20,320
The flow the user should follow

1399
00:48:20,320 --> 00:48:21,840
and the data that should display.

1400
00:48:21,840 --> 00:48:23,040
You build React components.

1401
00:48:23,040 --> 00:48:24,160
You called APIs.

1402
00:48:24,160 --> 00:48:26,000
You deployed to the app catalog.

1403
00:48:26,000 --> 00:48:28,640
Your success was measured by whether the interface worked

1404
00:48:28,640 --> 00:48:30,000
and whether people used it.

1405
00:48:30,000 --> 00:48:31,520
That role is about to become something

1406
00:48:31,520 --> 00:48:32,720
fundamentally different.

1407
00:48:32,720 --> 00:48:34,400
Not because the technology changed,

1408
00:48:34,400 --> 00:48:36,320
but because what the organization needs

1409
00:48:36,320 --> 00:48:37,680
from developers changed.

1410
00:48:37,680 --> 00:48:40,000
Building an SPFX component for a SharePoint page

1411
00:48:40,000 --> 00:48:41,120
is about UX.

1412
00:48:41,120 --> 00:48:42,880
How does the user navigate this interface?

1413
00:48:42,880 --> 00:48:44,640
How is the data organized visually?

1414
00:48:44,640 --> 00:48:46,560
Those are legitimate technical questions

1415
00:48:46,560 --> 00:48:47,760
and answering them well matters.

1416
00:48:47,760 --> 00:48:49,200
But they're bounded questions.

1417
00:48:49,200 --> 00:48:50,960
The component lives in a specific place.

1418
00:48:50,960 --> 00:48:52,320
It serves a specific purpose.

1419
00:48:52,320 --> 00:48:55,360
Building an SPFX component for the agent fabric

1420
00:48:55,360 --> 00:48:57,200
is about something else entirely.

1421
00:48:57,200 --> 00:48:59,760
You're not designing an interface for human navigation.

1422
00:48:59,760 --> 00:49:01,280
You're designing an orchestration point

1423
00:49:01,280 --> 00:49:02,720
where an agent can call your code

1424
00:49:02,720 --> 00:49:04,160
and execute business logic.

1425
00:49:04,160 --> 00:49:06,160
That changes every decision you make.

1426
00:49:06,160 --> 00:49:07,520
Consider a simple example.

1427
00:49:07,520 --> 00:49:10,560
You built a web part that displays a list of pending approvals.

1428
00:49:10,560 --> 00:49:12,960
The user sees a nice grid with filters and sorting.

1429
00:49:12,960 --> 00:49:14,640
They click "Approve" or "Reject".

1430
00:49:14,640 --> 00:49:15,840
The action gets recorded.

1431
00:49:15,840 --> 00:49:18,560
That's a well-designed SPFX component for a page.

1432
00:49:18,560 --> 00:49:20,640
Now expose that same component in co-pilot.

1433
00:49:20,640 --> 00:49:21,920
The agent is calling it.

1434
00:49:21,920 --> 00:49:23,600
The user asks co-pilot a question.

1435
00:49:23,600 --> 00:49:25,520
The agent reason that showing pending approvals

1436
00:49:25,520 --> 00:49:26,960
would help answer that question.

1437
00:49:26,960 --> 00:49:30,000
Now your component is rendering inside a conversational interface.

1438
00:49:30,000 --> 00:49:32,320
The user can still click to approve or reject.

1439
00:49:32,320 --> 00:49:33,600
But the context is different.

1440
00:49:33,600 --> 00:49:35,920
The agent is going to interpret the user's decision.

1441
00:49:35,920 --> 00:49:37,920
The agent is going to decide what to show next.

1442
00:49:37,920 --> 00:49:40,640
Your component is now part of a larger orchestration flow.

1443
00:49:40,640 --> 00:49:42,320
That requires different thinking.

1444
00:49:42,320 --> 00:49:45,440
You need to understand what data the agent might pass to your component.

1445
00:49:45,440 --> 00:49:47,920
You need to handle edge cases where the agent's reasoning

1446
00:49:47,920 --> 00:49:50,720
led to your component being surfaced in an unexpected context.

1447
00:49:50,720 --> 00:49:53,680
You need to think about how your component reports back to the agent.

1448
00:49:53,680 --> 00:49:55,840
Not just the user clicked "Approve",

1449
00:49:55,840 --> 00:49:59,280
but what does that approval mean in the context of the larger workflow?

1450
00:49:59,280 --> 00:50:01,920
More importantly, you need to understand governance.

1451
00:50:01,920 --> 00:50:05,200
When your component executes, whose permissions is it running under?

1452
00:50:05,200 --> 00:50:06,720
What data is it allowed to access?

1453
00:50:06,720 --> 00:50:08,240
If the component tries to fetch data,

1454
00:50:08,240 --> 00:50:09,840
the user shouldn't see what happens.

1455
00:50:09,840 --> 00:50:11,120
That's not a UX question.

1456
00:50:11,120 --> 00:50:12,480
That's an authorization question.

1457
00:50:12,480 --> 00:50:13,920
And it's now your responsibility.

1458
00:50:13,920 --> 00:50:16,320
Most SPFX developers today understand React.

1459
00:50:16,320 --> 00:50:18,480
They understand the SharePoint Rest API.

1460
00:50:18,480 --> 00:50:20,560
Fewer understand identity propagation.

1461
00:50:20,560 --> 00:50:24,560
How to verify that the user running the component is actually the user they claim to be.

1462
00:50:24,560 --> 00:50:26,640
Fewer understand DLP policies

1463
00:50:26,640 --> 00:50:28,960
and how to design a component that respects them.

1464
00:50:28,960 --> 00:50:31,760
Fewer understand audit logging and how to instrument their code

1465
00:50:31,760 --> 00:50:33,600
so governance teams can see what it did.

1466
00:50:33,600 --> 00:50:35,120
Those aren't optional skills anymore.

1467
00:50:35,120 --> 00:50:37,600
They're table stakes for building in the agent fabric.

1468
00:50:37,600 --> 00:50:38,640
That's the skill gap.

1469
00:50:38,640 --> 00:50:39,600
And it's a real one.

1470
00:50:39,600 --> 00:50:41,040
But it's also an opportunity.

1471
00:50:41,040 --> 00:50:44,000
Because organizations desperately need developers who can bridge that gap.

1472
00:50:44,000 --> 00:50:46,640
They need people who understand both the technical side.

1473
00:50:46,640 --> 00:50:49,040
How to build React components and the governance side.

1474
00:50:49,040 --> 00:50:51,920
How to make sure those components operate safely within compliance boundaries.

1475
00:50:51,920 --> 00:50:53,440
The market signal is clear.

1476
00:50:53,440 --> 00:50:58,160
Demand for co-pilot app developers or agent architects is growing faster than the supply of people

1477
00:50:58,160 --> 00:50:59,840
who actually have those skills.

1478
00:50:59,840 --> 00:51:01,520
This is a career inflection point.

1479
00:51:01,520 --> 00:51:03,200
You can train yourself now

1480
00:51:03,200 --> 00:51:07,760
and you'll be significantly more valuable to your organization in 18 months than you are today.

1481
00:51:07,760 --> 00:51:10,720
Or you can stay focused on page level SPFX components

1482
00:51:10,720 --> 00:51:12,480
and watch the market move past you.

1483
00:51:12,480 --> 00:51:14,160
The training path is straightforward.

1484
00:51:14,160 --> 00:51:16,320
Start with SPFX 1.24.

1485
00:51:16,320 --> 00:51:18,800
Understand how components render and co-pilot.

1486
00:51:18,800 --> 00:51:21,920
Move to MCP and understand when to use it versus SPFX.

1487
00:51:21,920 --> 00:51:23,120
Study governance patterns.

1488
00:51:23,120 --> 00:51:25,600
Learn how authorization and audit actually work.

1489
00:51:25,600 --> 00:51:29,840
Build a component in a test environment that respects permissions and logs its actions.

1490
00:51:29,840 --> 00:51:32,480
That foundation prepares you for the work that's coming.

1491
00:51:32,480 --> 00:51:34,720
Because the agent fabric doesn't need page developers.

1492
00:51:34,720 --> 00:51:36,480
It needs orchestration developers.

1493
00:51:36,480 --> 00:51:37,840
The licensing paradox.

1494
00:51:37,840 --> 00:51:40,720
Every CFO has the same question on their spreadsheet right now.

1495
00:51:40,720 --> 00:51:44,080
Is $30 per user every single month actually worth it?

1496
00:51:44,080 --> 00:51:47,280
They want to know what the organization gets for that investment.

1497
00:51:47,280 --> 00:51:49,040
But asking that is asking the wrong question.

1498
00:51:49,040 --> 00:51:51,200
The real question is both economic and strategic.

1499
00:51:51,200 --> 00:51:52,560
What happens if you don't pay it?

1500
00:51:52,560 --> 00:51:55,840
Let's look at the math for a thousand person organization.

1501
00:51:55,840 --> 00:51:59,040
If you move 30% of your stuff onto co-pilot licenses,

1502
00:51:59,040 --> 00:52:00,800
you are looking at 300 people.

1503
00:52:00,800 --> 00:52:04,000
At $30 a month that is $9,000 monthly

1504
00:52:04,000 --> 00:52:05,840
or $108,000 every year.

1505
00:52:05,840 --> 00:52:08,320
For a mid-market company that is a significant line item

1506
00:52:08,320 --> 00:52:10,720
that requires real justification and budget approval.

1507
00:52:10,720 --> 00:52:12,880
But this is where the analysis usually stops.

1508
00:52:12,880 --> 00:52:15,760
Finance asks if the return justifies the spend.

1509
00:52:15,760 --> 00:52:19,200
Without a clear way to measure it, the answer is usually we don't know.

1510
00:52:19,200 --> 00:52:21,280
So the license gets treated like a cost center.

1511
00:52:21,280 --> 00:52:23,680
And in every business, cost centers get minimized.

1512
00:52:23,680 --> 00:52:25,680
The deeper math changes the entire conversation.

1513
00:52:25,680 --> 00:52:27,920
If those 300 people are the ones who make decisions

1514
00:52:27,920 --> 00:52:29,200
and move workflows forward,

1515
00:52:29,200 --> 00:52:32,000
their time has a multiplier effect on the whole company.

1516
00:52:32,000 --> 00:52:35,920
The ROI calculation isn't about how much faster one person works.

1517
00:52:35,920 --> 00:52:37,680
It's about how much value you unlock

1518
00:52:37,680 --> 00:52:40,960
when a decision maker cuts their cycle time by 50%.

1519
00:52:40,960 --> 00:52:44,560
Think about an operations manager who currently spends four hours every week

1520
00:52:44,560 --> 00:52:46,560
on status updates and data lookups.

1521
00:52:46,560 --> 00:52:48,960
Through the agent fabric, that work drops to two hours.

1522
00:52:48,960 --> 00:52:51,440
That is two hours of brain power freed up every week,

1523
00:52:51,440 --> 00:52:54,720
allowing that person to focus on strategy instead of tactical overhead.

1524
00:52:54,720 --> 00:52:57,360
Over a year, you have recovered 100 hours of capacity.

1525
00:52:57,360 --> 00:52:59,680
If that role costs the company $100 per hour,

1526
00:52:59,680 --> 00:53:02,800
you just save $10,000 in productivity for a single person.

1527
00:53:02,800 --> 00:53:04,480
When 30% of your staff has a license

1528
00:53:04,480 --> 00:53:08,080
and the average recovered productivity is between 5,000 and 15,000 per person,

1529
00:53:08,080 --> 00:53:10,880
your return on investment is 10 to 30 times the cost.

1530
00:53:10,880 --> 00:53:12,800
Suddenly, the license looks incredibly cheap.

1531
00:53:12,800 --> 00:53:13,920
But here is the problem.

1532
00:53:13,920 --> 00:53:16,960
That ROI only happens if the licenses go to the right people.

1533
00:53:16,960 --> 00:53:19,040
If you hand them out randomly or give them to people

1534
00:53:19,040 --> 00:53:21,440
whose roles don't have that decision making power,

1535
00:53:21,440 --> 00:53:22,640
the ROI collapses.

1536
00:53:22,640 --> 00:53:24,960
You are paying for tools that aren't generating value.

1537
00:53:24,960 --> 00:53:26,160
That is the paradox.

1538
00:53:26,160 --> 00:53:28,640
The strategic decision isn't whether you license everyone.

1539
00:53:28,640 --> 00:53:30,320
You can't. The budget won't allow it.

1540
00:53:30,320 --> 00:53:32,080
And most people don't actually need it yet.

1541
00:53:32,080 --> 00:53:34,400
The real decision is figuring out who needs it most

1542
00:53:34,400 --> 00:53:36,320
and what value you unlock when they have it.

1543
00:53:36,320 --> 00:53:37,600
You have to be specific.

1544
00:53:37,600 --> 00:53:40,320
Start with roles that make high-frequency decisions.

1545
00:53:40,320 --> 00:53:42,160
Operations teams managing resources,

1546
00:53:42,160 --> 00:53:44,560
project managers coordinating across departments,

1547
00:53:44,560 --> 00:53:46,880
customer service leaders, handling escalations.

1548
00:53:46,880 --> 00:53:48,560
Finance teams managing approvals.

1549
00:53:48,560 --> 00:53:50,800
These are the spots where AI-driven decisions create

1550
00:53:50,800 --> 00:53:52,480
compounding value for the business.

1551
00:53:52,480 --> 00:53:54,880
License those roles first and then measure what happens.

1552
00:53:54,880 --> 00:53:57,440
Did the time it takes to make a decision actually go down?

1553
00:53:57,440 --> 00:53:59,280
Did the quality of those decisions improve?

1554
00:53:59,280 --> 00:54:01,040
Did you see fewer compliance violations?

1555
00:54:01,040 --> 00:54:03,120
You need to know if people are actually using the tools

1556
00:54:03,120 --> 00:54:04,880
or just treating them like a new toy.

1557
00:54:04,880 --> 00:54:07,920
Once you have the data, you expand to the next tier of roles.

1558
00:54:07,920 --> 00:54:10,000
You show the organization what became possible

1559
00:54:10,000 --> 00:54:12,000
and look for where else that patent fits.

1560
00:54:12,000 --> 00:54:13,920
You grow the license based methodically,

1561
00:54:13,920 --> 00:54:16,800
based on real measurement rather than just hoping for the best.

1562
00:54:16,800 --> 00:54:18,640
Timing makes this even more urgent.

1563
00:54:18,640 --> 00:54:20,800
On July 1, Microsoft is changing the rules.

1564
00:54:20,800 --> 00:54:23,360
Copilot features inside Office Apps will be restricted

1565
00:54:23,360 --> 00:54:25,840
to paid licenses and prices are going up.

1566
00:54:25,840 --> 00:54:28,240
If you wait, you aren't just delaying the benefits.

1567
00:54:28,240 --> 00:54:31,120
You are going to pay more per seat when you finally move forward.

1568
00:54:31,120 --> 00:54:33,440
The cost of waiting is compounding every month.

1569
00:54:33,440 --> 00:54:34,960
The work of building your foundation

1570
00:54:34,960 --> 00:54:38,320
and identifying the right roles needs to happen in the next few months.

1571
00:54:38,320 --> 00:54:39,120
Not next year.

1572
00:54:39,120 --> 00:54:40,160
That is the paradox.

1573
00:54:40,160 --> 00:54:41,600
The license isn't cheap.

1574
00:54:41,600 --> 00:54:43,760
But the cost of doing nothing is much worse.

1575
00:54:43,760 --> 00:54:45,120
The measurement problem.

1576
00:54:45,120 --> 00:54:46,800
How do you know it's working?

1577
00:54:46,800 --> 00:54:48,000
You have made the investment,

1578
00:54:48,000 --> 00:54:50,320
you built the architecture and deployed the components.

1579
00:54:50,320 --> 00:54:51,840
The agent fabric is finally running.

1580
00:54:51,840 --> 00:54:53,520
Now comes the question nobody wants to ask

1581
00:54:53,520 --> 00:54:54,880
because the answer is difficult.

1582
00:54:54,880 --> 00:54:56,320
Is this actually working?

1583
00:54:56,320 --> 00:54:58,720
Most people reach for the metrics they already know.

1584
00:54:58,720 --> 00:55:01,120
They look at engagement rates, daily active users,

1585
00:55:01,120 --> 00:55:02,800
or how long a session lasts.

1586
00:55:02,800 --> 00:55:04,720
These are the numbers that work for social media

1587
00:55:04,720 --> 00:55:05,600
or consumer apps.

1588
00:55:05,600 --> 00:55:07,200
They tell you if people are showing up.

1589
00:55:07,200 --> 00:55:09,920
But they tell you nothing about whether the agent fabric

1590
00:55:09,920 --> 00:55:11,200
is actually delivering.

1591
00:55:11,200 --> 00:55:13,600
The agent fabric isn't there to entertain your employees.

1592
00:55:13,600 --> 00:55:15,280
It is there to move work forward.

1593
00:55:15,280 --> 00:55:18,720
The metric that matters isn't how long someone stayed inside co-pilot.

1594
00:55:18,720 --> 00:55:21,760
It's how much faster they finished the task they were trying to do.

1595
00:55:21,760 --> 00:55:24,560
A traditional productivity metrics miss the point entirely.

1596
00:55:24,560 --> 00:55:27,200
You can have high engagement where people spend hours in co-pilot

1597
00:55:27,200 --> 00:55:28,320
and still be wasting time.

1598
00:55:28,320 --> 00:55:30,880
The interface might feel smooth and the chat might feel natural.

1599
00:55:30,880 --> 00:55:33,600
But if nothing gets done faster, it is just elegant friction.

1600
00:55:33,600 --> 00:55:34,400
It isn't progress.

1601
00:55:34,400 --> 00:55:37,600
The measurements that actually matter are operational.

1602
00:55:37,600 --> 00:55:39,280
Take time to decision.

1603
00:55:39,840 --> 00:55:43,440
How long does it take from the moment a request arrives until it is approved?

1604
00:55:43,440 --> 00:55:45,840
In the old model, that might take two hours.

1605
00:55:45,840 --> 00:55:48,160
You get an email, you navigate to a system,

1606
00:55:48,160 --> 00:55:50,400
you find the request, you review it,

1607
00:55:50,400 --> 00:55:51,600
and then you click approve.

1608
00:55:51,600 --> 00:55:55,200
The time is measured in hours because navigation and context switching

1609
00:55:55,200 --> 00:55:56,720
are built into the process.

1610
00:55:56,720 --> 00:55:59,600
In the agent fabric, you just ask co-pilot for pending approvals.

1611
00:55:59,600 --> 00:56:01,040
The component appears right there.

1612
00:56:01,040 --> 00:56:02,720
You click approve and you're done.

1613
00:56:02,720 --> 00:56:05,120
The time to decision is now measured in seconds.

1614
00:56:05,120 --> 00:56:07,680
That compressed timeline adds up across the whole company.

1615
00:56:07,680 --> 00:56:09,600
If 50 approvals happen every day,

1616
00:56:09,600 --> 00:56:11,920
and each one saves 90 minutes of clicking around,

1617
00:56:11,920 --> 00:56:15,040
you just freed up 75 hours of capacity in a single day.

1618
00:56:15,040 --> 00:56:17,040
Over a year, that is 1,500 hours.

1619
00:56:17,040 --> 00:56:18,720
That is how value becomes concrete.

1620
00:56:18,720 --> 00:56:20,960
You also need to look at the task completion rate.

1621
00:56:20,960 --> 00:56:23,280
How many tasks start in the agent fabric

1622
00:56:23,280 --> 00:56:25,760
and actually finish without the user leaving the screen?

1623
00:56:25,760 --> 00:56:28,800
In the old way of working, a task involves three different systems.

1624
00:56:28,800 --> 00:56:31,280
You check a status here, update a list there,

1625
00:56:31,280 --> 00:56:33,040
and send a notification somewhere else.

1626
00:56:33,040 --> 00:56:36,640
Users often quit halfway through because the friction is too high.

1627
00:56:36,640 --> 00:56:39,760
In the agent fabric, the component handles all those systems at once.

1628
00:56:39,760 --> 00:56:41,840
The task finishes right in front of the user

1629
00:56:41,840 --> 00:56:43,600
and your completion rates go up.

1630
00:56:43,600 --> 00:56:46,720
Error reduction is another huge factor that people overlook.

1631
00:56:46,720 --> 00:56:49,680
When users have to jump between systems, they make mistakes.

1632
00:56:49,680 --> 00:56:52,080
They update the wrong line because they lost their place

1633
00:56:52,080 --> 00:56:53,600
or they approve something they shouldn't

1634
00:56:53,600 --> 00:56:55,520
because they didn't have the full picture.

1635
00:56:55,520 --> 00:56:58,000
The agent fabric solves this by showing exactly

1636
00:56:58,000 --> 00:56:59,680
what is needed to make the right call.

1637
00:56:59,680 --> 00:57:01,920
It flags risks and highlights missing info.

1638
00:57:01,920 --> 00:57:05,280
When errors go down, your operational and compliance value goes up,

1639
00:57:05,280 --> 00:57:07,040
then you have the governance metrics.

1640
00:57:07,040 --> 00:57:08,400
Are all the actions being logged?

1641
00:57:08,400 --> 00:57:09,920
Can you trace exactly who did what?

1642
00:57:09,920 --> 00:57:11,600
Are the permissions being respected?

1643
00:57:11,600 --> 00:57:13,520
If someone tries to see data they shouldn't,

1644
00:57:13,520 --> 00:57:15,200
does the system actually stop them?

1645
00:57:15,200 --> 00:57:16,720
You need to know if there are audit gaps

1646
00:57:16,720 --> 00:57:19,040
where actions are happening outside the lines.

1647
00:57:19,040 --> 00:57:21,760
These questions determine if your system is controlled

1648
00:57:21,760 --> 00:57:24,000
or just a faster way to break the rules.

1649
00:57:24,000 --> 00:57:27,200
Risk metrics show you if your governance is actually holding firm.

1650
00:57:27,200 --> 00:57:30,080
You need to track how many unauthorized access attempts were blocked

1651
00:57:30,080 --> 00:57:31,680
and how many data leaks were prevented.

1652
00:57:31,680 --> 00:57:34,240
You need to see if permissions are creeping upward over time

1653
00:57:34,240 --> 00:57:35,360
or staying tight.

1654
00:57:35,360 --> 00:57:38,160
These numbers tell you if your foundation is preventing bad outcomes

1655
00:57:38,160 --> 00:57:40,080
or just recording them after they happen.

1656
00:57:40,080 --> 00:57:41,760
The framework for this measurement has to start

1657
00:57:41,760 --> 00:57:42,960
before you turn anything on.

1658
00:57:42,960 --> 00:57:44,800
You need to establish your baselines now.

1659
00:57:44,800 --> 00:57:47,440
Document how long a typical decision takes today.

1660
00:57:47,440 --> 00:57:49,440
Record how many tasks never get finished

1661
00:57:49,440 --> 00:57:51,600
and what your current error rate looks like.

1662
00:57:51,600 --> 00:57:53,680
Six months after the agent fabric is live,

1663
00:57:53,680 --> 00:57:55,120
run those same tests again.

1664
00:57:55,120 --> 00:57:57,840
The difference between those numbers tells you what changed.

1665
00:57:57,840 --> 00:58:00,880
More importantly, it tells you if those changes match your goals.

1666
00:58:00,880 --> 00:58:02,480
If your decision time dropped by half

1667
00:58:02,480 --> 00:58:04,240
but your error rate stayed the same,

1668
00:58:04,240 --> 00:58:05,680
you have speed without safety.

1669
00:58:05,680 --> 00:58:06,960
You need to investigate why.

1670
00:58:06,960 --> 00:58:08,720
Maybe the governance controls missed something

1671
00:58:08,720 --> 00:58:11,040
or the component is showing incomplete data.

1672
00:58:11,040 --> 00:58:12,720
If people are finishing tasks faster

1673
00:58:12,720 --> 00:58:14,720
but compliance violations are spiking,

1674
00:58:14,720 --> 00:58:16,160
you are moving in the wrong direction.

1675
00:58:16,160 --> 00:58:18,720
You have to recalibrate, tighten your data protections

1676
00:58:18,720 --> 00:58:20,000
and add more checkpoints.

1677
00:58:20,000 --> 00:58:22,880
You might even need to slow down to make sure you are moving safely.

1678
00:58:22,880 --> 00:58:24,560
Measurement is what reveals the truth.

1679
00:58:24,560 --> 00:58:27,360
It cuts through the hype and shows you the structural reality

1680
00:58:27,360 --> 00:58:28,320
of your business.

1681
00:58:28,320 --> 00:58:30,480
That is where real improvement actually starts.

1682
00:58:31,440 --> 00:58:33,360
The organizations that will struggle.

1683
00:58:33,360 --> 00:58:36,880
A clear pattern is emerging in organizations piloting co-pilot right now.

1684
00:58:36,880 --> 00:58:40,000
It is worth naming because you might be seeing it in your own office.

1685
00:58:40,000 --> 00:58:42,720
The companies struggling the hardest are not failing

1686
00:58:42,720 --> 00:58:44,400
because the technology is broken.

1687
00:58:44,400 --> 00:58:47,680
They are struggling because their governance foundation is fractured.

1688
00:58:47,680 --> 00:58:50,640
Weak governance is easy to spot once you know what to look for.

1689
00:58:50,640 --> 00:58:53,280
It looks like overshared sites where access was never tightened

1690
00:58:53,280 --> 00:58:54,560
after the first deployment.

1691
00:58:54,560 --> 00:58:58,400
It looks like unclassified data sitting inconsistently across the tenant

1692
00:58:58,400 --> 00:59:00,560
where some folders have labels but most do not.

1693
00:59:00,560 --> 00:59:04,800
You see it in DLP policies that only exist as templates nobody ever configured.

1694
00:59:04,800 --> 00:59:07,680
Permission models vary wildly from one side to the next

1695
00:59:07,680 --> 00:59:09,520
because there is no central standard.

1696
00:59:09,520 --> 00:59:11,680
Audit practices log events into a black hole

1697
00:59:11,680 --> 00:59:14,400
because nobody defined what actually matters to monitor.

1698
00:59:14,400 --> 00:59:17,040
This mess is invisible when people navigate manually.

1699
00:59:17,040 --> 00:59:20,160
A user searches for a document, finds it and moves on.

1700
00:59:20,160 --> 00:59:22,400
If they stumble into something they should not see,

1701
00:59:22,400 --> 00:59:24,400
it is just an isolated incident.

1702
00:59:24,400 --> 00:59:27,040
Nobody traces it back to a systemic permission problem.

1703
00:59:27,040 --> 00:59:30,160
The friction of discovery actually provides a layer of protection.

1704
00:59:30,160 --> 00:59:32,800
You have to actively look to find overshared content

1705
00:59:32,800 --> 00:59:34,800
and most people simply do not bother.

1706
00:59:34,800 --> 00:59:37,040
Co-pilot changes that equation instantly.

1707
00:59:37,040 --> 00:59:40,320
The moment you enable co-pilot in an organization with weak governance,

1708
00:59:40,320 --> 00:59:43,440
you have created a discovery engine that operates at machine speed.

1709
00:59:43,440 --> 00:59:46,000
A user asks co-pilot for sales forecasts

1710
00:59:46,000 --> 00:59:48,640
and the engine searches across the entire tenant to find them.

1711
00:59:48,640 --> 00:59:51,040
It finds them in the main sales site which is appropriate

1712
00:59:51,040 --> 00:59:53,360
but it also finds them in the shared CEO folder

1713
00:59:53,360 --> 00:59:55,760
because that site inherits permissions from its parent.

1714
00:59:55,760 --> 00:59:57,920
It finds them in a departmental sharepoint site

1715
00:59:57,920 --> 01:00:00,080
that was supposed to be restricted but never was.

1716
01:00:00,080 --> 01:00:02,400
It even finds them in a years old archive site

1717
01:00:02,400 --> 01:00:04,800
that still has default company-wide access.

1718
01:00:04,800 --> 01:00:07,520
Data that was technically accessible but practically hidden

1719
01:00:07,520 --> 01:00:09,200
is now surfaced in seconds.

1720
01:00:09,200 --> 01:00:11,680
The security and compliance teams notice this immediately.

1721
01:00:11,680 --> 01:00:14,240
They see the data flow, they see the risk, and they panic.

1722
01:00:14,240 --> 01:00:16,720
The response is predictable.

1723
01:00:16,720 --> 01:00:19,280
They block co-pilot access to sensitive sites.

1724
01:00:19,280 --> 01:00:22,000
They refuse to index entire categories of data.

1725
01:00:22,000 --> 01:00:24,640
They restrict co-pilot to a tiny white list of approved sites

1726
01:00:24,640 --> 01:00:26,160
instead of letting it search broadly.

1727
01:00:26,160 --> 01:00:29,440
In some cases, organizations simply refuse to enable co-pilot at all

1728
01:00:29,440 --> 01:00:31,040
because the risk feels too high.

1729
01:00:31,040 --> 01:00:32,880
The result is organizational paralysis.

1730
01:00:32,880 --> 01:00:35,280
You have bought the licenses, you have trained the teams,

1731
01:00:35,280 --> 01:00:36,880
you have announced the deployment.

1732
01:00:36,880 --> 01:00:38,960
Now you are telling those teams they cannot use it

1733
01:00:38,960 --> 01:00:42,000
or they can only use it in ways that eliminate most of its value.

1734
01:00:42,000 --> 01:00:43,600
The initiative becomes a liability.

1735
01:00:43,600 --> 01:00:45,280
It costs money and delivers nothing.

1736
01:00:45,280 --> 01:00:48,320
Adoption flatlines and the investment becomes a sunk cost.

1737
01:00:48,320 --> 01:00:50,480
This creates a 12 to 18 month lag

1738
01:00:50,480 --> 01:00:52,320
where the organization is paying for co-pilot

1739
01:00:52,320 --> 01:00:54,000
while the technology sits idle.

1740
01:00:54,000 --> 01:00:56,640
The licenses keep renewing and the budget stays active

1741
01:00:56,640 --> 01:00:58,480
but nothing meaningful is happening.

1742
01:00:58,480 --> 01:01:01,120
Security feels vindicated because they prevented a breach.

1743
01:01:01,120 --> 01:01:03,600
Business feels frustrated because they were promised capability

1744
01:01:03,600 --> 01:01:05,280
and got a sandbox instead.

1745
01:01:05,280 --> 01:01:07,520
It is caught in the middle trying to find a compromise

1746
01:01:07,520 --> 01:01:09,200
that satisfies both sides.

1747
01:01:09,200 --> 01:01:10,720
The cost compounds over time.

1748
01:01:10,720 --> 01:01:13,440
During those 18 months, your competitors are moving forward.

1749
01:01:13,440 --> 01:01:15,040
They invested in governance first

1750
01:01:15,040 --> 01:01:18,240
so their co-pilot deployment actually accelerates their decision making.

1751
01:01:18,240 --> 01:01:19,680
Their operations get faster.

1752
01:01:19,680 --> 01:01:21,280
They capture efficiency gains.

1753
01:01:21,280 --> 01:01:23,680
Meanwhile, your organization is stuck explaining

1754
01:01:23,680 --> 01:01:26,480
why you have licenses that nobody can use.

1755
01:01:26,480 --> 01:01:27,920
The exit from this trap exists

1756
01:01:27,920 --> 01:01:29,360
but only if you start now.

1757
01:01:29,360 --> 01:01:31,680
Do not wait for co-pilot to force the issue.

1758
01:01:31,680 --> 01:01:33,440
Start the governance work immediately.

1759
01:01:33,440 --> 01:01:35,760
Run the permission audits, classify the data,

1760
01:01:35,760 --> 01:01:38,720
implement the DLP policies, build the controls.

1761
01:01:38,720 --> 01:01:40,080
It is slower in the short term

1762
01:01:40,080 --> 01:01:42,480
and it requires everyone to get on the same page.

1763
01:01:42,480 --> 01:01:43,440
It takes months.

1764
01:01:43,440 --> 01:01:46,640
But by the time SPFX 1.24 reaches general availability

1765
01:01:46,640 --> 01:01:48,480
and adoption accelerates, you will be ready.

1766
01:01:48,480 --> 01:01:50,960
You will move from concept to production at speed.

1767
01:01:50,960 --> 01:01:52,880
You will capture the gains while competitors

1768
01:01:52,880 --> 01:01:54,720
are still arguing about permissions.

1769
01:01:54,720 --> 01:01:56,080
The choice is clear.

1770
01:01:56,080 --> 01:01:57,840
Govern now or struggle later.

1771
01:01:57,840 --> 01:02:01,200
The organizations that will win.

1772
01:02:01,200 --> 01:02:02,720
Contrast that with the organizations

1773
01:02:02,720 --> 01:02:04,480
making different decisions right now.

1774
01:02:04,480 --> 01:02:05,520
They are not waiting.

1775
01:02:05,520 --> 01:02:08,480
They are not stuck in permission audits and compliance debates.

1776
01:02:08,480 --> 01:02:10,560
They are already moving through that work methodically

1777
01:02:10,560 --> 01:02:12,400
because they treat it as a prerequisite.

1778
01:02:12,400 --> 01:02:14,080
What is different about their approach?

1779
01:02:14,080 --> 01:02:17,840
They have accepted that governance is not a friction point to minimize.

1780
01:02:17,840 --> 01:02:20,400
It is the foundation that makes everything else possible.

1781
01:02:20,400 --> 01:02:21,840
They are building it deliberately.

1782
01:02:21,840 --> 01:02:24,000
They run data access governance reports

1783
01:02:24,000 --> 01:02:27,760
as an operational baseline rather than a one-time exercise.

1784
01:02:27,760 --> 01:02:29,760
They classify their data because they understand

1785
01:02:29,760 --> 01:02:31,760
that classification enables automation.

1786
01:02:31,760 --> 01:02:33,200
They implement DLP policies

1787
01:02:33,200 --> 01:02:35,680
because they know those policies will eventually govern

1788
01:02:35,680 --> 01:02:36,960
how the agent fabric operates.

1789
01:02:36,960 --> 01:02:39,360
They build discipline across IT security and business

1790
01:02:39,360 --> 01:02:41,520
because they know this is not a technical project

1791
01:02:41,520 --> 01:02:43,280
for security to own an isolation.

1792
01:02:43,280 --> 01:02:46,000
That cross-functional alignment is what separates them

1793
01:02:46,000 --> 01:02:47,760
from the organizations that struggle.

1794
01:02:47,760 --> 01:02:49,840
When IT proposes a governance control,

1795
01:02:49,840 --> 01:02:52,000
security understands why it matters.

1796
01:02:52,000 --> 01:02:54,560
When compliance asks for audit trails, business accepts the cost

1797
01:02:54,560 --> 01:02:56,080
because they understand the value.

1798
01:02:56,080 --> 01:02:57,600
When business wants to move fast,

1799
01:02:57,600 --> 01:02:59,680
IT and security have frameworks in place

1800
01:02:59,680 --> 01:03:01,120
that let them move safely.

1801
01:03:01,120 --> 01:03:02,320
There is a shared language.

1802
01:03:02,320 --> 01:03:05,840
There is alignment on what secure actually means in their context.

1803
01:03:05,840 --> 01:03:07,440
That alignment creates momentum.

1804
01:03:07,440 --> 01:03:09,120
It is a different pace entirely.

1805
01:03:09,120 --> 01:03:13,120
They are not waiting for SPF X1.24 to go live in autumn of 2026

1806
01:03:13,120 --> 01:03:14,560
before they start preparing.

1807
01:03:14,560 --> 01:03:17,920
They are using the preview period between July and late 2026

1808
01:03:17,920 --> 01:03:21,120
to test components and understand how co-pilot surfaces them.

1809
01:03:21,120 --> 01:03:23,840
They are training developers on the new model right now.

1810
01:03:23,840 --> 01:03:26,720
By the time general availability arrives, they are not learning.

1811
01:03:26,720 --> 01:03:27,840
They are scaling.

1812
01:03:27,840 --> 01:03:29,680
That timing advantage is measurable.

1813
01:03:29,680 --> 01:03:32,880
While struggling organizations are still debating if co-pilot is safe,

1814
01:03:32,880 --> 01:03:35,600
these organizations are moving from pilot to production.

1815
01:03:35,600 --> 01:03:38,400
They are not dealing with proof of concept friction.

1816
01:03:38,400 --> 01:03:39,920
They are dealing with scale challenges

1817
01:03:39,920 --> 01:03:41,840
which are fundamentally different problems.

1818
01:03:41,840 --> 01:03:44,560
Scale is about infrastructure and monitoring,

1819
01:03:44,560 --> 01:03:45,760
which are solvable.

1820
01:03:45,760 --> 01:03:48,640
Proof of concept friction is about misaligned governance and fear,

1821
01:03:48,640 --> 01:03:50,320
which is much harder to fix.

1822
01:03:50,320 --> 01:03:53,040
The competitive consequence becomes visible within months.

1823
01:03:53,040 --> 01:03:55,280
These organizations start capturing efficiency gains

1824
01:03:55,280 --> 01:03:57,280
that competitors are not even attempting yet.

1825
01:03:57,280 --> 01:03:59,360
Their operations teams make decisions faster

1826
01:03:59,360 --> 01:04:02,080
because the data surfaces exactly where they need it.

1827
01:04:02,080 --> 01:04:04,400
Their project managers coordinate work in half the time

1828
01:04:04,400 --> 01:04:07,200
because the agent fabric handles the communication and approvals.

1829
01:04:07,200 --> 01:04:10,160
Their customer service teams resolve escalations with better information

1830
01:04:10,160 --> 01:04:13,040
because co-pilot synthesizes context from multiple sources.

1831
01:04:13,040 --> 01:04:14,880
Meanwhile, the organizations that delayed

1832
01:04:14,880 --> 01:04:17,200
are still stuck in the governance debate phase

1833
01:04:17,200 --> 01:04:18,960
that efficiency gap compounds.

1834
01:04:18,960 --> 01:04:21,840
By the end of 2026, the speed difference is obvious.

1835
01:04:21,840 --> 01:04:23,920
By mid-2027, it is undeniable.

1836
01:04:23,920 --> 01:04:26,400
These organizations have built organizational muscle

1837
01:04:26,400 --> 01:04:27,760
around the agent fabric.

1838
01:04:27,760 --> 01:04:29,200
Their teams know how to work with it.

1839
01:04:29,200 --> 01:04:31,280
Their governance controls are running routinely,

1840
01:04:31,280 --> 01:04:32,640
not as special projects.

1841
01:04:32,640 --> 01:04:35,040
Their data is classified, their permissions are tight,

1842
01:04:35,040 --> 01:04:36,960
and their audit trails are complete.

1843
01:04:36,960 --> 01:04:38,400
They are operating in the new model,

1844
01:04:38,400 --> 01:04:40,640
while competitors are still planning to transition.

1845
01:04:40,640 --> 01:04:42,560
The talent dynamics shifts too.

1846
01:04:42,560 --> 01:04:46,080
These organizations become known as places where the technology actually works.

1847
01:04:46,080 --> 01:04:48,240
You can build something and actually use it in production

1848
01:04:48,240 --> 01:04:49,680
without fighting restrictions.

1849
01:04:49,680 --> 01:04:52,080
That reputation attracts developers and architects

1850
01:04:52,080 --> 01:04:54,080
who want to work on modern infrastructure.

1851
01:04:54,080 --> 01:04:57,360
They want to build a GEN-TIC UX instead of old-page components.

1852
01:04:57,360 --> 01:04:58,720
They want to solve governance problems

1853
01:04:58,720 --> 01:05:00,480
instead of fighting compliance blocks.

1854
01:05:00,480 --> 01:05:03,200
The talent advantage becomes self-reinforcing,

1855
01:05:03,200 --> 01:05:04,880
better talent builds better systems

1856
01:05:04,880 --> 01:05:06,800
and better systems attract more talent.

1857
01:05:06,800 --> 01:05:08,560
The business outcome is measurable

1858
01:05:08,560 --> 01:05:10,400
in ways that go beyond simple metrics.

1859
01:05:10,400 --> 01:05:12,560
These organizations improve their compliance posture

1860
01:05:12,560 --> 01:05:14,640
because their controls are tight and well integrated.

1861
01:05:14,640 --> 01:05:17,360
They achieve real ROI on their co-pilot investment

1862
01:05:17,360 --> 01:05:19,200
because they are actually using it productively.

1863
01:05:19,200 --> 01:05:20,480
They reduce operational risk

1864
01:05:20,480 --> 01:05:22,160
because decisions happen with better data

1865
01:05:22,160 --> 01:05:23,920
and complete audit trails.

1866
01:05:23,920 --> 01:05:26,480
They build institutional knowledge about how to operate

1867
01:05:26,480 --> 01:05:28,880
at the intersection of innovation and control.

1868
01:05:28,880 --> 01:05:31,200
By 2028, when the market has fully caught up

1869
01:05:31,200 --> 01:05:32,480
to the architectural shift,

1870
01:05:32,480 --> 01:05:34,560
the gap will be visible in every metric.

1871
01:05:34,560 --> 01:05:35,760
It will not be theoretical.

1872
01:05:35,760 --> 01:05:37,680
It will be measurable in decision cycle time

1873
01:05:37,680 --> 01:05:40,640
in project completion rates and in ROI per license.

1874
01:05:40,640 --> 01:05:42,640
The organizations that prepared now are ahead,

1875
01:05:42,640 --> 01:05:44,720
the organizations that delayed are playing catch-up.

1876
01:05:44,720 --> 01:05:47,120
This reckoning clarifies what is actually at stake

1877
01:05:47,120 --> 01:05:49,040
in the decisions you make right now.

1878
01:05:49,040 --> 01:05:50,480
The structural inevitability.

1879
01:05:50,480 --> 01:05:52,320
The question isn't whether this shift happens,

1880
01:05:52,320 --> 01:05:54,560
it's whether you're ahead of it or behind it when it does.

1881
01:05:54,560 --> 01:05:56,480
The forces pushing us toward the agent fabric

1882
01:05:56,480 --> 01:05:58,480
aren't just trends, they're structural.

1883
01:05:58,480 --> 01:06:01,440
For years, text has been the bottleneck for complex work.

1884
01:06:01,440 --> 01:06:03,680
You type a question, you get back a wall of text,

1885
01:06:03,680 --> 01:06:05,120
then you have to leave that interface

1886
01:06:05,120 --> 01:06:07,360
just to actually do something with the information

1887
01:06:07,360 --> 01:06:09,200
that workflow works for simple things,

1888
01:06:09,200 --> 01:06:11,120
like asking what time a meeting starts.

1889
01:06:11,120 --> 01:06:13,440
But it breaks the moment you need to make a decision

1890
01:06:13,440 --> 01:06:15,360
or finish a multi-step task.

1891
01:06:15,360 --> 01:06:17,280
The technology to fix this isn't a dream.

1892
01:06:17,280 --> 01:06:18,240
It exists right now.

1893
01:06:18,240 --> 01:06:21,200
We have interactive components living inside the co-pilot canvas.

1894
01:06:21,200 --> 01:06:24,080
We have SPFX rendering directly inside agents.

1895
01:06:24,080 --> 01:06:26,960
We have MCP servers that can expose tools and UI

1896
01:06:26,960 --> 01:06:28,400
at the exact same time.

1897
01:06:28,400 --> 01:06:29,920
These aren't ideas for the future.

1898
01:06:29,920 --> 01:06:31,280
They're in preview today.

1899
01:06:31,280 --> 01:06:33,600
And they'll be everywhere within the next six months.

1900
01:06:33,600 --> 01:06:35,280
When you have the tech to remove friction,

1901
01:06:35,280 --> 01:06:36,480
economics takes over.

1902
01:06:36,480 --> 01:06:38,800
Organizations using these tools move faster.

1903
01:06:38,800 --> 01:06:41,520
They make better decisions because their data is actually useful.

1904
01:06:41,520 --> 01:06:42,880
They get more done in less time.

1905
01:06:42,880 --> 01:06:44,880
They also lower their risk because their governance

1906
01:06:44,880 --> 01:06:46,640
is built in and easy to audit.

1907
01:06:46,640 --> 01:06:50,000
In a competitive market, that speed becomes a massive advantage.

1908
01:06:50,000 --> 01:06:51,360
Some companies will grab it early.

1909
01:06:51,360 --> 01:06:54,160
The rest will be forced to play catch-up just to stay alive.

1910
01:06:54,160 --> 01:06:55,440
The timeline is already set.

1911
01:06:55,440 --> 01:06:59,120
In July of 2026, licensing changes will turn embedded co-pilot

1912
01:06:59,120 --> 01:07:00,880
in office into a paid feature.

1913
01:07:00,880 --> 01:07:05,680
By late 2026, SPFX 1.24 and SharePoint co-pilot apps

1914
01:07:05,680 --> 01:07:07,760
will be fully available to everyone.

1915
01:07:07,760 --> 01:07:11,280
By early 2027, the companies that invested in their architecture

1916
01:07:11,280 --> 01:07:12,560
won't be testing anymore.

1917
01:07:12,560 --> 01:07:13,600
They'll be operating.

1918
01:07:13,600 --> 01:07:15,920
They'll be running real workflows through the agent fabric.

1919
01:07:15,920 --> 01:07:17,440
They'll be making decisions in minutes

1920
01:07:17,440 --> 01:07:19,280
that used to take your team hours.

1921
01:07:19,280 --> 01:07:21,920
This shift changes what we consider normal.

1922
01:07:21,920 --> 01:07:23,680
New companies entering the market

1923
01:07:23,680 --> 01:07:25,200
won't have to learn this model.

1924
01:07:25,200 --> 01:07:27,600
They'll just adopt it as the standard way of doing business.

1925
01:07:27,600 --> 01:07:30,000
The pioneers won't just have a head start on speed.

1926
01:07:30,000 --> 01:07:32,080
They'll be the ones who wrote the rules on governance

1927
01:07:32,080 --> 01:07:34,240
and architecture that everyone else has to copy.

1928
01:07:34,240 --> 01:07:36,880
The impact ripples through every role in the company.

1929
01:07:36,880 --> 01:07:40,080
Jobs built around just finding data are going away.

1930
01:07:40,080 --> 01:07:42,240
Jobs that require real-time decision making

1931
01:07:42,240 --> 01:07:44,320
are becoming the most important roles you have.

1932
01:07:44,320 --> 01:07:46,320
The developer market is shifting from building pages

1933
01:07:46,320 --> 01:07:47,920
to architecting orchestration.

1934
01:07:47,920 --> 01:07:49,600
IT is moving from watching platforms

1935
01:07:49,600 --> 01:07:50,800
to engineering governance.

1936
01:07:50,800 --> 01:07:52,160
These aren't small tweaks.

1937
01:07:52,160 --> 01:07:54,160
This is role extinction and role creation

1938
01:07:54,160 --> 01:07:55,520
happening at the same time.

1939
01:07:55,520 --> 01:07:57,680
The governance problem is where this hits the hardest.

1940
01:07:57,680 --> 01:07:59,040
If you don't invest now,

1941
01:07:59,040 --> 01:08:01,200
you'll face a brutal choice in 18 months.

1942
01:08:01,200 --> 01:08:03,920
You can spend months doing expensive governance work then,

1943
01:08:03,920 --> 01:08:05,680
or you can pay for massive remediation

1944
01:08:05,680 --> 01:08:07,520
under pressure when things inevitably break.

1945
01:08:07,520 --> 01:08:09,520
The cost of waiting isn't just a slow rollout.

1946
01:08:09,520 --> 01:08:11,760
It's the compounding price of fixing a broken system

1947
01:08:11,760 --> 01:08:13,040
after an operational failure.

1948
01:08:13,040 --> 01:08:14,480
But here's what actually matters.

1949
01:08:14,480 --> 01:08:16,560
The first move will set the standard for what works.

1950
01:08:16,560 --> 01:08:20,000
By the time SPFX 1.24 is the default way to build apps,

1951
01:08:20,000 --> 01:08:22,240
the earlier adopters will have months of proven patterns

1952
01:08:22,240 --> 01:08:23,840
already baked into their culture.

1953
01:08:23,840 --> 01:08:25,360
They'll know exactly what works.

1954
01:08:25,360 --> 01:08:27,760
Competitors who wait will just be copying old home work.

1955
01:08:27,760 --> 01:08:28,800
They won't be innovating.

1956
01:08:28,800 --> 01:08:29,680
They'll just be following.

1957
01:08:29,680 --> 01:08:31,280
The business reality is simple.

1958
01:08:31,280 --> 01:08:33,520
At the turning point in late 2026,

1959
01:08:33,520 --> 01:08:36,480
the market stops asking if the agent fabric is possible.

1960
01:08:36,480 --> 01:08:38,240
It starts assuming it's the standard.

1961
01:08:38,240 --> 01:08:40,160
Organizations caught in the middle will lose.

1962
01:08:40,160 --> 01:08:41,600
They'll be paying for new technology

1963
01:08:41,600 --> 01:08:43,360
without the governance to use it safely.

1964
01:08:43,360 --> 01:08:44,560
They'll be stuck in old processes

1965
01:08:44,560 --> 01:08:46,160
while everyone else races past them.

1966
01:08:46,160 --> 01:08:49,600
Your position in 2028 is being decided by what you do right now.

1967
01:08:49,600 --> 01:08:50,720
It's not about the tech.

1968
01:08:50,720 --> 01:08:51,600
The tech is solved.

1969
01:08:51,600 --> 01:08:52,880
It's about your governance.

1970
01:08:52,880 --> 01:08:54,800
It's about whether you build the foundation

1971
01:08:54,800 --> 01:08:56,560
that makes this whole architecture possible.

1972
01:08:56,560 --> 01:08:58,480
The path forward.

1973
01:08:58,480 --> 01:08:59,760
The choice is actually simple.

1974
01:08:59,760 --> 01:09:01,200
You can invest in governance now.

1975
01:09:01,200 --> 01:09:02,720
Or you can accept a tiny return

1976
01:09:02,720 --> 01:09:05,200
on your co-pilot investment while your competitors pull away.

1977
01:09:05,200 --> 01:09:06,400
The window is closing fast.

1978
01:09:06,400 --> 01:09:07,840
We have the July 1st pricing.

1979
01:09:07,840 --> 01:09:09,840
We have the July 2026 preview.

1980
01:09:09,840 --> 01:09:12,480
We have the general release in the autumn of 2026

1981
01:09:12,480 --> 01:09:14,960
by the time you're hearing this month's have already slipped by.

1982
01:09:14,960 --> 01:09:16,000
So start here.

1983
01:09:16,000 --> 01:09:17,200
Run a governance audit.

1984
01:09:17,200 --> 01:09:18,320
Classify your data.

1985
01:09:18,320 --> 01:09:19,840
Set up your DLP policies.

1986
01:09:19,840 --> 01:09:22,640
Get your IT security and business teams on the same page.

1987
01:09:22,640 --> 01:09:25,520
Then build your agent fabric on top of that foundation.

1988
01:09:25,520 --> 01:09:28,160
By 2027, you'll be running the new model

1989
01:09:28,160 --> 01:09:30,400
while your competitors are still fighting with the old one.

1990
01:09:30,400 --> 01:09:31,680
That isn't just a small win.

1991
01:09:31,680 --> 01:09:33,840
It's a total shift in how your enterprise operates.

1992
01:09:33,840 --> 01:09:35,280
The technology is just the tool.

1993
01:09:35,280 --> 01:09:36,560
The change is structural.

1994
01:09:36,560 --> 01:09:37,920
Subscribe for the next episode

1995
01:09:37,920 --> 01:09:41,760
where we'll look at the specific governance patterns that actually scale.

1996
01:09:41,760 --> 01:09:43,760
And if you're dealing with these challenges right now,

1997
01:09:43,760 --> 01:09:44,960
connect with me, Mirko Peters.

1998
01:09:44,960 --> 01:09:46,960
On LinkedIn, let's figure this out together.

