Skip to content

Microsoft Copilot Studio — minimum Dataverse security role

Trust3 discovers Copilot Studio agents through Dataverse with read-only access. You can assign the built-in Service Reader role to the application user, or create a narrower custom role with only the table privileges Trust3 needs.

Use Service Reader when you want the fastest setup. Use the custom role below when you want least privilege.

For Entra app registration, client secret, and application user setup, see Microsoft Copilot Studio Prerequisites.


Create the custom role

  1. Open the Power Platform admin center.
  2. Go to Manage > Environments and select the target environment.
  3. Open Settings > Users + permissions > Security roles.
  4. Select New role.
  5. In the Create New Role dialog, fill in the required fields, for example:

    Field Example value
    Role Name Trust3 Copilot Inventory Reader
    Business unit Same business unit as your environment
    Description Read-only Dataverse access for Trust3 Copilot inventory
    Applies To Trust3 AI Assets Collector
    Summary of Core Table Privileges Read Organization on Team, User, Agent (bot), and Agent component (botcomponent)
  6. Leave Member's privilege inheritance at the default (Direct User (Basic) access level and Team privileges) unless your organization requires a different setting.

  7. You can clear Include App Opener privileges for running Model-Driven apps — Trust3 does not need Model-Driven app access.
  8. Select Save.

Add the table privileges

  1. Open the new role.
  2. In the tables view, open the filter dropdown and select Show all tables.
  3. Search for each of these tables and set Read to Organization. Leave Create, Write, Delete, and other privileges as None.

    Table (UI name) System name
    Team team
    User systemuser
    Agent bot
    Agent component botcomponent

    UI names

    In Power Platform, Copilot Studio bots appear as Agent and Agent component. Older docs may still say Bot / Bot Component; the system names remain bot and botcomponent.

  4. Select Save.

New roles can include other default privileges. Remove any privileges that are not in the required list so the role stays limited to Team, User, Agent, and Agent component.

Optional: After cleanup, select Show only assigned tables to verify that only the four assigned tables are displayed.


Assign the role to the application user

  1. In the same environment, open Settings > Users + permissions > Application users.
  2. Open the Trust3 application user (or create it by following Microsoft Copilot Studio Prerequisites).
  3. Edit security roles.
  4. Assign either:
    • Service Reader, or
    • your custom role (for example Trust3 Copilot Inventory Reader)
  5. Save the application user.

After role changes, wait 5–10 minutes for Power Platform permissions to propagate, then rerun collection.


Summary

Option When to use
Service Reader Quick setup; broader built-in read access than Trust3 requires
Custom role (Team, User, Agent, Agent component — Read / Organization only) Least privilege for Copilot Studio inventory