Skip to content
Rush Commerce
AI & Automation3 min read

Copilot Studio Hooks: run your rules on every agent tool call

Copilot Studio Hooks (preview) run a workflow on every session start, prompt, tool call, or error. Use them for audit logs and policy checks, not as a lock.

Microsoft is previewing Hooks in Copilot Studio: a way to run one of your workflows automatically at fixed points in an agent's life, whether the agent thinks it is relevant or not. A tool runs when the model decides to call it. A hook runs every time its event fires. That is the difference between "the agent usually logs the refund" and "every refund gets logged."

What actually happened

Per Microsoft's Copilot Studio hooks documentation, updated September 29 and reported by Cloud Wars on October 6:

  • Six events. Session start, user prompt submitted, error, pre tool use, post tool use, and after tool failure.
  • The action is always a workflow. Copilot Studio passes the event details plus metadata (the user's Entra ID, channel, agent name, conversation ID) and reads the workflow's response back into the conversation.
  • Only "pre tool use" can block. It can return deny with a reason, or rewrite the parameters before the tool runs. The other events can add context, rewrite a prompt, redact a result, or pick retry, skip, or abort on an error.
  • Scoped per tool. Tool hooks apply to all tools by default, or only to the ones you pick.
  • Preview, metered. Hooks are for agents on the GitHub Copilot harness, and Microsoft says building, testing, and running them can consume Copilot Credits.

The caveat that matters most is in Microsoft's own docs: if a hook workflow fails, times out, or returns something unreadable, the agent keeps going as if the hook returned nothing. Microsoft tells you not to use a hook as your only safeguard for a business-critical rule.

Why it matters for your business

This is the right primitive. Claude Code and Gemini agents already have hooks, and now the Microsoft 365 crowd gets the same lifecycle control without writing code. If you run a support or ops agent in Teams, three hooks pay for themselves fast:

  1. Post tool use → audit log. Every tool call, with the user's Entra ID, written to a SharePoint list or a database. That is your record when a customer disputes what the agent did.
  2. Pre tool use → policy gate. Deny refunds over a dollar limit, or deny writes outside business hours. Scope it to the one tool that moves money.
  3. Session start → context. Pull the customer's open tickets so the agent does not ask questions you already have answers to.

Then put the hard limit somewhere a failed workflow cannot skip it: the API itself, a scoped service account, or a permission the agent simply does not hold. A hook that fails open is a convenience, not a control.

Key takeaways

  • Copilot Studio Hooks run a workflow on six lifecycle events, every time, not when the model chooses
  • Only the pre tool use hook can block a call or rewrite its parameters
  • Hooks fail open: a broken workflow lets the agent continue
  • Usage can draw Copilot Credits, so meter your hook-heavy agents
  • Use hooks for logging and policy checks; enforce money and data limits at the API

Agents need rules that hold when the workflow breaks. We build audit logs, scoped service accounts, and API-level limits around your AI agents, on Microsoft or anything else. See what we build or tell us what your agent touches.

Sources: Microsoft Learn, Cloud Wars.

  • #copilot-studio
  • #ai-agents
  • #agent-hooks
  • #microsoft
  • #agent-governance
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.