Copilot Studio computer-use allow list: what it blocks, and spend
The access-control list stops actions on other sites but not opening them. It is not a spend control either, so put a cap on the Sume call itself.

Copilot Studio's computer use access control only prevents the model from taking actions on websites or applications that are not on the allow list. It does not stop the model from opening them: Microsoft's example is an agent limited to microsoft.com that can still use the browser's search bar to open Bing, after which any attempt to act on Bing fails. It also says nothing about money. If the agent can reach a paid API, bound that API with its own cap, because the screen-level list was never designed to limit spend.
Details are from Microsoft's computer use page, read on 2026-10-03; Sume's gates are in MCP tools and gates and Agent Completions.
What controls does Copilot Studio give you?
The access control list covers websites and applications, and an Enforce HTTPS option is available. The best-practice guidance adds dedicated machines and least-privilege accounts. None of these is a spend setting.
| Control | Limits | Does not limit |
|---|---|---|
| Access control list | Actions on sites and apps | Opening a site |
| Enforce HTTPS | Interaction with HTTP sites | Which HTTPS sites |
| Dedicated machine | What else is installed | Calls made to external APIs |
| Human supervision | Requests for a person to step in; they expire and stop the run | Normal-looking spend |
Where does spend get bounded instead?
On the Sume side, per call. Hosted MCP paid tools need an idempotency_key, accept dry_run=true to preview cost without submitting, and enforce max_spend_usd only when it is sent. Agent Completions go further and refuse a request without generation_spend_cap_usd. OAuth sessions can be kept read-only with mcp:read, in which case paid calls return insufficient_scope.
None of those depend on what site the agent is looking at, which is the point: a hijacked page can talk an agent into a paid call from an allowed origin, and the cap still holds.
What should the setup look like?
- Allow only the sites the task needs, and add
https://www.sume.comonly if a person-visible dashboard step is genuinely part of the job. - Prefer an API tool for generation, with a key limited to the scopes it needs, over clicking through a dashboard.
- Pass
max_spend_usdorgeneration_spend_cap_usdon every paid call, and usedry_runfirst on anything large. - Treat Human supervision as a way to catch odd instructions, not as a budget.
What if the agent must download a result?
Sume returns durable media.sume.com HTTPS URLs for generated files. Add that host to the allow list if the agent opens the file in a browser, and have the API call return the URL instead of making the agent hunt for it.
Sources
Related posts
More in Agents
- Can I create a Sume scheduled agent by API? Read and run, not create
The Sume API can list, read, run and monitor scheduled agents, but not create, edit or delete them. Authoring is the dashboard or the Agent chat.
- Cursor Automations webhook: start a Sume agent run with a spend cap
A Cursor Automation can call Sume Agent Completions from a webhook-triggered run. Send generation_spend_cap_usd and an Idempotency-Key on every call.
- Fire a cron schedule on demand: api_trigger_enabled, cron kept
A Sume cron schedule can also accept API runs. Turn on api_trigger_enabled and your service can start it now without touching the cadence.
- Hermes Agent cron job that starts a Sume Format run
A Hermes cron job begins with no memory of last week. Write the prompt, idempotency key, spend cap and SILENT or CRON_FAILURE reply so a Sume run starts once.
Written by Sume