Product1 publisher3 min readPublished
Microsoft widens the preview of Autopilot, an agent that works without waiting for a prompt
Microsoft is widening the private preview of Autopilot, an OpenClaw-based agent with its own identity that it pictures businesses running by the hundreds. Each one acts on standing instructions, so whoever grants its permissions answers for its work.
The Product Desk · Product desk

What happened
- Microsoft is expanding its Autopilot business agent beyond the select enterprise customers who got it in June, though it remains a private preview.
- Autopilot is built on OpenClaw, an open-source autonomous agent that people can install locally on a PC to carry out tasks.
- Unlike a local OpenClaw install, Autopilot is designed to run from a cloud-hosted server.
- Microsoft has retired the Scout name it gave its first Autopilot agent at Build in June and is sticking with Autopilot.
- The agent will appear in Teams, Outlook, chats, channels and documents, where staff can @mention it like a colleague.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- decision Approval moves from the individual task to the setup screen, so IT has to settle what an agent may do on its own before anyone asks it for anything.
- exposure Each Autopilot is another identity holding access to company apps and data, and a business running the hundreds Microsoft pictures has that many new actors to scope and review.
- precedent If Copilot becomes the work OS Nadella describes, agent permissions become a standing admin duty alongside user permissions.
In Microsoft's demo, a retail business is trying to keep Black Friday on track. The agent does the chasing: it flags overdue orders and checks that every store has enough inventory [12]. In Microsoft's telling, nobody had to type a request. The company describes the job as "watching channels, following up on threads, running recurring work, and picking a project back up days later, without waiting for a prompt" [6].
The pitch around that demo is big. Microsoft CEO Satya Nadella framed Autopilot as a key component to "building Copilot as a new OS for work," according to PCMag [14]. The company pictures "hundreds" of Autopilots working inside a single business's IT environment alongside human staff [13]. What is on offer today is narrower: a preview, and a bet that the agent can do useful work in HR, sales, finance and other business processes [11].
Microsoft's own definition from Build contains the problem an IT lead will have to solve. Autopilots are "always-on agents that work autonomously, with their own identity, and act on your behalf," Microsoft said [2]. If one of them nudges a supplier overnight, the agent acted under its own name, and a person will still be asked why. Microsoft's answer is a split of duties: "You set the objective and boundaries; Autopilot handles the rest while keeping you informed and in control," the company said [17].
Teams assume users will take that sentence at its word, writing careful boundaries on day one and then reading every update. Whether users behave that way is still open. PCMag's report does not include usage figures from the June customers or a description of the guardrails Microsoft said in a briefing it has been building for enterprise use [10].
An agent needs access to a user's computer, apps or online accounts to be useful. PCMag points out that a mistake with that access can mean deleted data, ruined projects and exposed privacy [16]. Anyone tempted to skip the managed version and run the open-source base directly should know that PCMag found the OpenClaw Windows app far from user-friendly in its testing [15].
I'd start Autopilot where its unprompted actions are flags and reminders, and hold back anything that changes a record or sends anything outside the company. That limits the agent to the easy half of Microsoft's own demo [12]: flagging an overdue order is cheap to allow, and fixing a store's inventory gap is where the value sits.
To decide the rest, sort each permission on two axes. The first is whether a person asked for that specific action. The second is whether the action can be undone within a day.
Prompted and reversible is ordinary chatbot use, and existing policy already covers it. Prompted and irreversible has a human approval built in, because someone asked. Unprompted and reversible (follow-ups, flags, drafts) is where Autopilot fits; log it and review the log weekly. Unprompted and irreversible covers deletions, payments and a message sent to a customer. Before an agent gets a permission in that last box, one named employee signs for it. If nobody will sign, the agent goes without.
What to watch
- Whether Microsoft publishes how Autopilot's permissions, audit and governance controls work before the preview widens further.
- Pricing and licensing for Autopilot, including whether an agent with its own identity is billed like a user seat.
- Usage or retention figures from the June preview customers, the first evidence of whether teams keep agents running after setup.