Copilot Studio shared agent acts as its maker: scope the Sume key

The default computer-use credentials are the maker's. A shared agent then acts with that access on the machine. Give any Sume key it holds the narrowest scope.

5 min readSume
All posts

In Copilot Studio, computer use defaults to maker-provided credentials, and Microsoft's page warns that if you share an agent with that setting, anyone using it can act with the original author's access on the configured machine. Treat every secret the agent can reach the same way. If it also calls Sume, give it a dedicated Sume API key with only the scopes it needs, and cap each run, because the people using the shared agent inherit whatever that key can spend.

The credential behavior is from Microsoft's computer use documentation, read on 2026-10-03; Sume's scopes and caps are in MCP OAuth and API keys and Agent Completions.

What are the two credential modes?

Maker-provided credentials are the default and, per the page, suit autonomous agents. End user credentials use the person interacting with the agent, and each user needs access credentials for the machine. The page also recommends dedicated machines with least-privilege accounts.

Computer-use credential modes (read 2026-10-03)
ModeActs asFits
Maker-provided (default)The author, on the configured machineAutonomous agents
End user credentialsThe person chatting with the agentConversational agents; each user needs machine access

What does a Sume key add to the picture?

A Sume API key sees the full hosted tool set and spend is wallet and admission based; paid tools need an idempotency_key, and max_spend_usd is enforced only when someone sends it. Those are habits of the caller, not walls. The walls are the key's scopes and the per-run cap you set in your own request.

Agent Completions need a key carrying agent_completions:write and, to read results, agent_completions:read. Completions are user-owned runs, and service-account keys are rejected with 403 insufficient_scope, so the key behind a shared agent is a user's key. Create one for the agent alone and name it for the agent so revoking it affects nothing else.

What should I set before sharing the agent?

  • Create a separate Sume key, with only the scopes the tool needs, and put it in the tool's connection rather than in instructions.
  • Send generation_spend_cap_usd on every Agent Completion from the tool, at the most you would accept a single run to cost.
  • Prefer end user credentials when users should act as themselves on the machine.
  • Keep the machine dedicated and the account least-privileged, as Microsoft recommends.
  • If the key leaks, create a new key first and then revoke the old one from the dashboard.

What is the remaining risk?

A shared agent with a capped key can still be asked to spend the cap repeatedly. Cap per run limits one run; it does not limit how many runs people start. Watch the usage record for the key, and pair the cap with a plan whose concurrency you can live with.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume