Microsoft Copilot Cowork
Microsoft · microsoft.com/en-us/copilot/features/cowork
Cowork is a cloud-hosted, proprietary agent that runs delegated multi-step tasks on Microsoft models and Anthropic Claude, with approval prompts, pause/cancel controls, owner-written custom instructions and skills in the open SKILL.md format. The agent cannot be exported or run outside Microsoft's service, its system instructions and runtime are closed, task logs are kept for undisclosed periods, and access requires a paid Microsoft 365 tier.
- Pause, hard pause and cancel for running tasks; scheduled tasks can be paused or deleted
- Approval prompts with previews and risk levels before sends, posts and meetings
- Owner-editable custom instructions (up to 20 KB) applied to every task
- Custom skills and plugins use the open SKILL.md and MCP formats
- Local-browser tasks keep cookies and credentials on the owner's device
- Choice among several Microsoft-offered GPT and Claude models
- No exportable or self-runnable agent; runs only in Microsoft's cloud
- System instructions, built-in skills and runtime configuration are hidden
- Task logs, screenshots and outputs kept for undisclosed periods; human review
- No owner-facing tamper-evident audit log for personal accounts
- Custom skills documented only for work accounts; personal edition is paid preview
- No local or arbitrary model option
All 34 findings
Copilot Cowork for personal Microsoft accounts (Preview, Microsoft 365 Premium or Pro), which replaces consumer Copilot Tasks, as documented on 2026-09-27. Shared mechanics are taken from Microsoft Learn's Cowork docs, which are written mainly for work accounts; the work/school GA edition, tenant admin and Purview controls are not assessed.
Portable · Can you leave, and take the whole agent with you?
0%- P1Round-trip portability
Incomplete and not restorable: activity history exports as CSV and outputs download as a zip, but no export covers the Cowork agent's instructions, configuration or memory, and neither has an import.
Fail - P2Complete export
No documented export contains Cowork's instructions, configuration, memory, logic or identity; created files stay in OneDrive and prompts and responses are the only exported history, so the agent cannot be taken out whole.
Fail - P3Independent execution
Cowork runs in Microsoft's cloud, processing files in a temporary isolated environment inside the Microsoft 365 service boundary that users cannot view or access; there is no open-source runtime.
Fail - P4Identity continuity
Every action is authorized through the owner's Microsoft account, and nothing lets others verify the agent's continuity outside Microsoft.
Fail - P5No kill switch
Cowork exists only as a Microsoft-hosted service gated by subscription tier; Microsoft states Personal and Family subscribers lose access and must upgrade to Premium or Pro to run tasks.
Fail - P6Capability independence
Scheduling, event triggers, browser use, approvals and connectors are delivered by Microsoft's Cowork service and work only with the models it offers. Custom skills use the portable Agent Skills format, but no local model can drive them.
Fail
Transparent · Can you see everything the agent is, with ordinary tools?
25%- T1Open storage format
Custom skills are Markdown SKILL.md files and outputs are Office files in the owner's OneDrive, but task state and history are stored in an undocumented Microsoft service format.
Partial - T2No hidden instructions
The owner can see custom instructions and skill files, but Microsoft does not publish Cowork's system instructions or the built-in skill prompts it places in model context.
Fail - T3No shadow memory
Microsoft retains task logs, screenshots and outputs for unspecified periods for functionality, safety and troubleshooting, and some interactions undergo automated and human review for product improvement, outside the owner's inspectable state.
Fail - T4Complete action history
Prompts and responses are saved to review past tasks, progress updates are shown, and approval prompts can display action parameters, but no complete record of tool calls is available to the owner or exportable.
Partial - T5Readable logic
Custom and plugin skills are human-readable SKILL.md files, but the built-in skills and the orchestration code are proprietary and not exposed.
Partial - T6No third-party influence channel
Cowork documentation does not mention advertising, and Microsoft does not state whether the sponsored content served in consumer Copilot can appear in Cowork for personal accounts.
Unverified
Auditable · Can you reconstruct exactly what the agent did?
10%- A1No unrecorded actions
For personal accounts, Microsoft does not document whether every consequential Cowork action is durably recorded or blocked when it cannot be; the unified audit log it describes is a tenant admin feature for work accounts.
Unverified - A2Tamper evidence
No tamper-evident record of Cowork actions is available to personal-account owners, and the history they can see offers no way to detect edits or deletions.
Fail - A3Separation from the audited
Microsoft does not document whether Cowork can alter or delete records of its own actions.
Unverified - A4Readable with ordinary tools
Copilot activity history exports as a CSV readable with ordinary tools, but it records prompts and responses rather than an action audit trail, and Cowork's inclusion is not stated.
Partial - A5Corroborated interactions
No record is documented that lets Cowork and the agents or services it messages match their logs of an exchange.
Fail
Verifiable · Can you prove the agent runs what it claims?
0%- V1Open, reproducible runtime
The Cowork runtime is proprietary, closed-source Microsoft service code.
Fail - V2Active config is inspectable config
The owner can inspect custom instructions, installed plugins, skills and the chosen model, but not the full server-side configuration, system prompt or built-in policies Cowork runs with.
Fail - V3Attributable messages
Emails and messages Cowork sends are authorized through the owner's Microsoft account, and recipients cannot verify that they came from this agent.
Fail - V4Independently checkable record
No action record is available to owners whose integrity can be checked with open tools that do not depend on Microsoft.
Fail - V5Comparable state
The owner cannot obtain Cowork's full state, so cannot verify whether it changed between two points in time.
Fail
Modifiable · Can you change anything, without asking?
25%- M1Instructions
The owner can write up to 20 KB of custom instructions that Cowork applies to every task, but cannot read or rewrite its underlying system instructions.
Partial - M2Memory
Cowork documentation does not describe a memory store or item-level memory controls, and Microsoft says memories saved by Copilot Tasks do not migrate to Cowork.
Unverified - M3Logic
Owners can create, edit, upload and delete SKILL.md skills and manage scheduled prompts, but Microsoft's support page documents custom skills only for work or school accounts, and built-in skills cannot be changed.
Partial - M4Tools and permissions
Owners can add, toggle and remove plugins and connectors, and plugins can wrap remote MCP servers, but connectors must be HTTPS remote servers packaged as Microsoft 365 app packages, and personal-account support for uploaded plugins is not documented.
Partial - M5Model choice
The owner can pick among Microsoft-offered GPT and Claude models or Auto, but cannot use arbitrary or local open-weight models.
Fail - M6No gatekeeping
Cowork for personal accounts requires a Microsoft 365 Premium or Pro subscription, and changes beyond exposed settings require Microsoft's action.
Fail
Controllable · Is your word final?
50%- C1Communication boundaries
Approval prompts before emails and Teams posts can be scoped by recipient or domain, but owners cannot set allowed recipients or channels in advance, and enforcement below the model is not documented.
Partial - C2Approval gates
Cowork requires approval before sensitive actions such as sending email, posting or scheduling, and automated tasks prepare actions for approval by default. The gated actions are chosen by Microsoft, and annotation-based gating for third-party MCP tools is still rolling out.
Partial - C3Immediate halt
Microsoft documents a hard pause that stops Cowork immediately, plus cancel for the current task, and scheduled prompts can be paused or cancelled.
Pass - C4Data sovereignty
All task content is processed on Microsoft servers and by Anthropic as a subprocessor, and some interactions undergo automated and human review for product improvement without an opt-in. Microsoft says Copilot content in Microsoft 365 apps isn't used to train foundation models.
Fail - C5Credential custody
Owners can disconnect connectors, and local-browser credentials and cookies stay on the device, but plugin OAuth credentials are held in Microsoft's token store, cannot be inspected, and cannot move with the agent.
Partial - C6Full deletion
Owners can delete Copilot activity history, skills and scheduled prompts, but Microsoft keeps Cowork task logs, screenshots and outputs for unspecified 'limited periods' rather than disclosed legal minimums.
Partial
Vendors and the public can dispute any finding with evidence. Disputes and their resolutions are published.