Copilot Studio computer-use allow list: what it blocks, and spend

The access-control list stops actions on other sites but not opening them. It is not a spend control either, so put a cap on the Sume call itself.

5 min readSume
All posts

Copilot Studio's computer use access control only prevents the model from taking actions on websites or applications that are not on the allow list. It does not stop the model from opening them: Microsoft's example is an agent limited to microsoft.com that can still use the browser's search bar to open Bing, after which any attempt to act on Bing fails. It also says nothing about money. If the agent can reach a paid API, bound that API with its own cap, because the screen-level list was never designed to limit spend.

Details are from Microsoft's computer use page, read on 2026-10-03; Sume's gates are in MCP tools and gates and Agent Completions.

What controls does Copilot Studio give you?

The access control list covers websites and applications, and an Enforce HTTPS option is available. The best-practice guidance adds dedicated machines and least-privilege accounts. None of these is a spend setting.

Computer-use controls and what each limits (read 2026-10-03)
ControlLimitsDoes not limit
Access control listActions on sites and appsOpening a site
Enforce HTTPSInteraction with HTTP sitesWhich HTTPS sites
Dedicated machineWhat else is installedCalls made to external APIs
Human supervisionRequests for a person to step in; they expire and stop the runNormal-looking spend

Where does spend get bounded instead?

On the Sume side, per call. Hosted MCP paid tools need an idempotency_key, accept dry_run=true to preview cost without submitting, and enforce max_spend_usd only when it is sent. Agent Completions go further and refuse a request without generation_spend_cap_usd. OAuth sessions can be kept read-only with mcp:read, in which case paid calls return insufficient_scope.

None of those depend on what site the agent is looking at, which is the point: a hijacked page can talk an agent into a paid call from an allowed origin, and the cap still holds.

What should the setup look like?

  • Allow only the sites the task needs, and add https://www.sume.com only if a person-visible dashboard step is genuinely part of the job.
  • Prefer an API tool for generation, with a key limited to the scopes it needs, over clicking through a dashboard.
  • Pass max_spend_usd or generation_spend_cap_usd on every paid call, and use dry_run first on anything large.
  • Treat Human supervision as a way to catch odd instructions, not as a budget.

What if the agent must download a result?

Sume returns durable media.sume.com HTTPS URLs for generated files. Add that host to the allow list if the agent opens the file in a browser, and have the API call return the URL instead of making the agent hunt for it.

Sources

Related posts

More in Agents

All Agents posts

Written by Sume