Most enterprises now have two places to build AI agents: Rovo Studio inside Atlassian and Copilot Studio inside Microsoft. Both reached general availability for agentic workflows in 2026, both ship inventories and permissions, and both are already being used by teams whether or not IT has a policy. Here is how to decide where the first governed agent should live, and how to govern both.
What each platform is good at
| Rovo Studio (Atlassian) | Copilot Studio (Microsoft) | |
|---|---|---|
| Native data | Jira, Confluence, JSM, Bitbucket, and the Teamwork Graph, plus connectors | Microsoft 365 content, Dataverse, Dynamics 365, and Microsoft Graph, plus connectors |
| Best first use cases | Backlog grooming, ticket triage and Level 1 support (Rovo Service), release notes, PI planning prep, knowledge answers from Confluence | Employee self-service on HR and IT policy, document drafting, meeting follow-ups, process automation with Power Automate |
| Agent controls | Roles, approvals, versioning, audit logging, org-wide agent inventory, separate permissions for using AI vs. building agents, agent accounts in early access | Lifecycle and evaluation controls, multi-agent orchestration, MCP connectors, Agent 365 inventory and cost visibility, multi-tenant management |
| Where it runs | Inside Jira, Confluence, and JSM; Rovo Desktop in beta | Inside Teams, Microsoft 365 apps, and web; Windows agent runtime from Build 2026 |
| Who builds | Jira and Confluence admins, delivery leads | Power Platform makers, IT, business analysts |
Pick the first agent by the workflow, not the vendor
If the workflow lives in tickets and pages, build in Rovo. If it lives in documents, email, and Teams, build in Copilot Studio. The first governed agent should be one with a clear owner, a bounded data set, a human approval step, and a measurable outcome. A JSM Level 1 deflection agent and an HR policy assistant are the two most common starting points, one on each platform.
Govern both with one model
- One inventory. Every agent, on either platform, is registered with an owner, a purpose, a data scope, and a risk tier. Both platforms now expose agent inventories; the governance record sits above them.
- One set of decision rights. Who may build, who approves data access, who supervises autonomous actions, and who can retire an agent. Document it as a RACI and enforce it in platform permissions.
- One control map. NIST AI RMF functions (Govern, Map, Measure, Manage) mapped to platform controls and to the regulations you already answer to: HIPAA, model-risk guidance, state AI laws.
- One measurement. Adoption, quality (sampled accuracy and escalation rate), and control metrics (agents without owners, agents touching sensitive data) reported monthly.
- One change program. Roles change when agents take work. Training, communication, and support are the same program regardless of where the agent runs.
Where the platforms meet
Rovo can read Microsoft 365 content through connectors, and Copilot Studio can call Jira through connectors and MCP. The integration question is less about data access and more about which system of record owns the action. Decide that per workflow: an incident is owned in JSM; an approval memo is owned in SharePoint. Agents can cross the boundary, but the record should not.
Rovo capabilities are included in Atlassian’s Cloud Standard, Premium, and Enterprise plans, with usage-based pricing for AI credits announced in 2026. Check your plan and credit allocation before scaling agents.
Yes, and it should. A single AI governance function with one inventory, one control map, and one change program avoids two competing policies.
NIST AI RMF and ISO/IEC 42001 are the common baselines, mapped to industry regulation.
Talk to a practitioner
VTPMO builds one AI governance model across Rovo and Copilot for regulated organizations.
