# Govern Copilot Studio agents

> Connect a Microsoft Copilot Studio agent to the Immiscible MCP server, or import our Power Platform custom connector, so it asks before it pays, shares data or acts.

Source: https://immiscible.fly.dev/docs/guides/copilot-studio

Copilot Studio can reach Immiscible two ways. The MCP server is the shorter path; the custom connector suits organisations that manage everything as Power Platform connectors. Either way the agent acts as one Immiscible agent, and every decision is recorded against it.

> **Note**
> Microsoft does not endorse or partner with Immiscible. This page describes how its documented features work with ours.

## Connect by MCP

Copilot Studio connects to MCP servers over Streamable HTTP, which is what `https://immiscible.fly.dev/mcp` speaks. Generative orchestration must be on for the agent.

1. In the agent, open **Tools**, **Add a tool**, **New tool**, **Model Context Protocol**.
2. Name it (for example "Ask Immiscible") and give the server URL `https://immiscible.fly.dev/mcp`.
3. Choose the authentication:
   - **OAuth 2.0, dynamic discovery.** Copilot Studio finds our authorisation server from `/.well-known/oauth-protected-resource`, registers itself, and the first person to use it signs in to Immiscible and chooses which agent it acts as.
   - **API key**, in a header named `x-api-key`, with an agent key (**Agents**, **Add an agent**, then **Collect the agent's key** on its setup page). Simpler, but everyone using the Copilot Studio agent shares one key.
4. Create the connection and add the tool. The tools appear: `authorize_action`, `request_payment`, `request_personal_data`, `check_action_status`, `explain_decision` and `settle_action`.
5. In the agent's instructions, say: before any payment, sending email, changing a record or sharing personal data, call `authorize_action` and follow the decision.

Your Power Platform data policies apply to the MCP connector like any other.

## Import our connector

A Power Platform custom connector imports OpenAPI 2.0 only, so we publish the decision API in that form as well as 3.1.

1. Download `https://immiscible.fly.dev/downloads/immiscible-power-platform.swagger.json`.
2. In Power Apps or Power Automate, open **Custom connectors**, **New custom connector**, **Import an OpenAPI file**, and choose it. The host, the operations and the security (an API key in the `x-api-key` header) come from the file.
3. Create the connector, then a connection with an agent key.
4. In Copilot Studio, add the connector's actions to the agent as tools: **Ask Immiscible before acting** (`requestDecision`), **Check a decision** and **Record what happened**.

The file is regenerated from [/openapi.json](https://immiscible.fly.dev/docs/guides/openapi-actions.md#the-files) on every download, so a new field arrives when you update the connector.

## When a person has to decide

`requestDecision` can answer `approval_required`. The approver is asked in Immiscible (console, email, Slack or Teams). The agent can tell the user it is waiting and call **Check a decision** later; a Power Automate flow can instead register a callback and continue when it arrives. See [waiting for a person](https://immiscible.fly.dev/docs/guides/openapi-actions.md#waiting-for-a-person).
