Agents are appearing across Microsoft 365 faster than most teams can keep track of, and the access questions underneath them haven't gone anywhere. This quarter's Orchestry releases put both in view: a new AI & Agents area for the agents themselves, one place to see who can reach a workspace, and workspace reviews that cover more of your SharePoint estate.
Here's what shipped in Q3 2026. Watch the full walkthrough with David Francoeur, Orchestry's Head of Product Strategy and Innovation, then dig into the details below.
AI & Agents launched this quarter and is rolling out to Orchestry Enterprise customers. As people create agents in Copilot Studio, through Agent Builder, and as SharePoint agents sitting right alongside your content, keeping up gets harder every week. AI & Agents brings those three types into a single inventory.
The dashboard shows how that inventory is growing, who's creating agents, and how risk is distributed across everything Orchestry has discovered. If one team is creating far more agents than the rest, the creator view is where you'd spot it and start working out why.
Like everything else in Orchestry, the inventory is collected through the daily crawl, and insights are calculated after it runs.
The Agents report lists every agent Orchestry has found with its type, owner, risk rating and insights. Filter by status, by agent type, or by specific Orchestry insights to go after one problem at a time, like agents with anonymous access turned on or solutions that are unmanaged.
Each row shows when the agent was created, and you can export the report when you need to work through the list with someone else. That matters here more than most places, because Power Platform responsibilities tend to be spread across several teams.
Open an agent and the detail sits behind three tabs: Overview for its properties and insights, Sources for its knowledge sources and connectors, and Access for how far it's been shared. That gives you a concrete starting point for a conversation with the owner about whether the sharing scope is intentional, whether those are the sources they expected, and whether the connectors are right.
This first release focuses on inventory and governance. It doesn't yet show how often an agent is used or whether it's delivering a return, and those are the areas Orchestry is focused on in the coming months.
There's a delete action for all three agent types, so administrators can clean up agents that obviously shouldn't be there and work through the rest with their owners.
AI & Agents also ships with a dedicated role inside Orchestry's existing access control, alongside the other roles. It lets you delegate this area to the right people without handing them the rest of Orchestry.
Read more: Introducing AI & Agents: see your agents across platforms in one roster
The first release reports on more than agents. It also brings in Power Platform environments, DLP policies, custom connectors and solutions, with more to come.
Use it to see which environments your agents are housed in, or to review the DLP policies that exist and what they're doing. It's the Power Platform context that sits right next to agent creation, in the same place you're already looking at the agents.
Read more: The Power Platform your agents are running on
If you've used the AI readiness dashboard before, this will be familiar. It's now part of the broader AI & Agents experience, and it's available on every Orchestry plan.
The score looks at the content and governance underneath your AI, using signals around oversharing, governance, and the safeguards you've put in place. Drill into the areas contributing to the score to decide whether changes are needed and where to focus first.
Read more: Microsoft 365 Copilot and storage readiness: checklist for IT teams
Working out who has access to a workspace used to mean moving between the membership, sharing links and broken inheritance tabs in Orchestry. The new Sharing & Permissions tab in workspace details brings them together, on every Orchestry plan.
It opens on a summary. Sharing links are broken down by type, so an Anyone link is easy to tell apart from one shared with specific people, alongside broken inheritance and unique permissions, counts of the users and groups with access, and whether Everyone Except External Users (EEEU) is present. These stats refresh every night.
To decide where to start, go to reports first. The sharing links report lets you sort workspaces by how many links they hold, then drill into the worst ones through the sharing links pane or the summary view.
On Orchestry Enterprise, the Permission Browser shows a workspace's permissions as one tree, broken out by each layer where access was granted. See site collection administrators, plus Entra groups and SharePoint groups (including the hidden limited access groups Microsoft creates) that you can expand to see who belongs, alongside people with direct access and the role each one holds, down to custom roles like ContributeWithoutDelete.
It goes below the site too. Open a library with broken inheritance to see who has access, then drill into everything shared at item level; in the walkthrough, one library alone holds 431 sharing links. If you've always wanted a technical view of exactly where access stems from, this is it.
Read more: How to find and fix broken SharePoint permission inheritance at scale
Workspace reviews in Orchestry have been run hundreds of thousands of times, and one thing customers have asked for is support for non-group-connected sites. Orchestry already reported on team sites and communication sites that aren't connected to a Microsoft 365 group, and now you can run workspace reviews on them too, through the same review process your owners already know.
The sharing links step got an upgrade as well. Reviews originally shipped with a simplified view, built so owners could act quickly on common use cases that administrators could switch on, but a significant group of customers told us they wanted the detailed view.
That detailed view is now on in both workspace reviews and OneDrive reviews. Reviewers can go through the full catalog of sharing links, see who each one is shared with across every link type, and act on them line by line.
Read more: Orchestry automation and delegation, including workspace reviews
There's more on the way, and the next roundup will cover it. If you're on Orchestry Enterprise, AI & Agents is rolling out to you now, and your customer success manager can help you get the Permission Browser switched on.
Want to put any of this to work in your own tenant? Watch the walkthrough above, or book a demo.