An agent picks its tools based on a name and a description. Most of the time that works fine. When the tool is "write the audit record," most of the time isn't good enough.

Microsoft just put Hooks in preview in Copilot Studio to fix that. A hook runs a workflow every time a specific event fires in the agent's lifecycle. The agent doesn't get a vote. Cloud Wars covered it this week.

Each hook has two parts, an event and a workflow. The events are session start, user prompt submitted, error, pre tool use, post tool use and after tool failure. Copilot Studio hands your workflow the details of what just happened, then reads the workflow's answer back into the conversation.

A tool runs when the agent decides it's relevant, and its output is information the agent might use. A hook runs every time, and its output changes what the agent does next. The same workflow can be both.

Pre tool use is the one to learn first. It sees the tool name and the arguments before anything runs, and it's the only event that can block an action. Say your agent has a refund tool. A hook can check the amount against a limit and return deny with a reason, or swap in corrected parameters.

Post tool use works on the way back. You can strip account numbers out of a result before the model reads it, or write an audit record that names both the user (by Entra object ID) and the agent. The error and start events cover retry, skip or abort decisions, and background context like the user's region or open cases.

Now the catch. Hooks fail open. The docs say that if a workflow fails, times out or returns something the agent can't read, the agent carries on as though the hook returned nothing. So your "no refunds over $500" hook quietly stops working the day its workflow errors out. Microsoft says plainly not to make a hook your only safeguard for a business-critical rule.

I'd put the real limit in the backend system and treat the hook as the first line of defense. Belt and suspenders.

A few smaller things to know:

  • It's prerelease, so the docs say it's subject to change.

  • It applies to agents powered by GitHub Copilot in Copilot Studio, and usage-based billing applies (Copilot Credits).

  • The workflow has to be published, and so does the agent. A saved but unpublished workflow does nothing, which is an easy one to miss.

  • Prompts, tool results and error messages are untrusted input. Validate them inside the workflow.

Leave Granola and get up to 12 months free of Wispr Flow Notetaker + Dictation

If you have paid time left on an individual Granola plan, we'll match it with a Wispr Flow subscription that includes Notetaker and dictation, and add bonus time, up to 12 months total. Sign in or create a Wispr account and submit proof of your plan to check eligibility.

Last Wednesday I wrote about Foundry Routines, which let Azure agents start on their own. Hooks cover what happens once they're running. Microsoft is building both halves, and I think the second half is the one security teams will ask about first.

If you're studying for a Microsoft AI cert, put the idea of deterministic controls around a nondeterministic agent in your notes. It tends to show up as a scenario question about enforcing a policy every time.

And if you build in Copilot Studio, add one pre tool use hook to your most sensitive tool this week. Log the payload and see what your agent actually sends.

Keep Learning and Building.