Add a tool for an enterprise action

Completed

After you choose a tool type, you add the tool to your agent and set it up for the lookups and actions that your help agent needs. In this unit, you learn how to add an existing tool and configure its connection, actions, and inputs, using a SharePoint connector that handles both a status lookup and a new request as the worked example.

Distinguish a connector action from its connection

A connector wraps a service's API and exposes the operations it supports as actions. Each action does one job. The SharePoint connector, for example, includes Get items and Get item for reading list items, and Create item for adding one. When you add a connector as a tool, the actions you make available are the ones the orchestrator can call.

A connection is the authenticated link that the tool uses to reach the service. The action defines what the tool does, and the connection lets the tool reach the service to do it. When a tool needs a connection, you sign in or provide credentials as part of setting it up.

Keep the two ideas separate as you configure a tool. A missing or expired connection prevents actions that depend on it from running. A poorly chosen set of actions gives the orchestrator the wrong options.

Add an existing tool from the Build tab

The following steps show the common path for adding an existing tool. The path is the same for every tool type until you pick a tool:

  1. Sign in to Copilot Studio and open your agent.
  2. In the agent navigation bar, select the Build tab.
  3. In the components panel, select the Tools button.
  4. In the Add a tool dialog, browse or search for a tool. To filter by tool type, use the Featured, Model Context Protocol (MCP), Connectors, or Workflows tab.
  5. Select a tool to view its details, including a description and the actions it provides.
  6. Select Add.

For the help agent, you switch to the Connectors tab in step 4 or search for SharePoint, and then select the SharePoint connector. Step 5 is a useful checkpoint. Before you select Add, compare the actions that the tool lists with the lookup and the action that you identified for the requirement. If none of the listed actions fits the requirement, look for a different tool before you add this one.

Learn more in Add a tool to an agent.

Handle a tool that your organization blocks

Your organization's governance policies, such as data policies, can restrict which tools and connectors are available. This behavior is currently in preview. A blocked tool appears disabled in the Add a tool dialog, and you can't select it. To find out why, hover over the cross icon next to the tool. The message identifies the policy restriction that applies.

You can't change a policy restriction from within your agent. Contact your administrator to ask whether the tool can be allowed or whether an approved alternative exists.

Environments don't all allow the same connectors. If the SharePoint connector isn't available to you, practice with a connector that your organization allows and that offers a similar pair of actions: one that reads a record and one that creates a record. The configuration decisions in the rest of this unit apply the same way.

Configure the tool after you add it

After you add a tool, complete its setup before the agent relies on it:

  • Authenticate: Some tools require you to sign in or provide credentials before they can be used. Follow the authentication prompts.
  • Select actions: For connectors that provide multiple actions, select which specific actions to make available to your agent.
  • Review the description: Check that the description accurately reflects what the tool does. The orchestration runtime uses the description to determine when to invoke the tool.

Choose actions deliberately. The help agent needs a read action from the SharePoint connector for the status lookup and Create item for new requests. If the request number is the item's SharePoint ID, Get item retrieves it by ID. If the request number is stored in another column, Get items needs a filter that identifies that record. Make only the read action that matches your list and Create item available. This limits the operations the agent can perform on the list. An action that you leave out is one the agent can't call.

Configure inputs for the tool

On the Build tab, your agent's tools appear in the components panel, below the Tools button. Select a tool to open the Tool details dialog, where you work in the following panels:

  • Details: Update the name and description to improve how the agent decides when to use the tool. You can also update the authentication credentials if they expire.
  • Inputs: Configure the values passed to the tool when it's invoked. For connectors with multiple actions, add or remove specific actions.
  • Outputs: View the outputs that the tool returns in the planner.

After you make changes, select Save.

In the Inputs panel, sort each input value into one of two groups. Some values stay the same on every call. For the help agent, the SharePoint site and the list that tracks requests are the same for every employee. Other values come from the request itself, such as the item's ID for Get item, a filter for Get items, or the details of a new request. For each action, decide which group each input belongs to, and check that the configuration matches that decision. A lookup that searches the wrong list, or a create action that expects the employee to supply the site, is a configuration problem that testing exposes later.

The Outputs panel shows what the tool gives back. Know what each action returns so that you can check results later. For the status lookup, the value you care about is the item's status, which you compare with the item in the list when you test the tool.

If you remove a tool later, select the X next to the tool, and then select Remove. Removing a tool deletes only its association with the agent. The underlying connector, MCP server, or API configuration stays in place.

Learn more in Manage and delete tools in an agent.

Confirm whose access the connection uses

The connection determines which account reaches the service, and that account's permissions limit what the tool can read or change. Before other employees rely on the tool, confirm whose connection runs each action instead of assuming it uses the maker's or the employee's account. Test access as an intended user. For the help agent, verify that a status lookup can't reveal another employee's request merely because someone knows its number. An instruction to ask for a request number doesn't enforce access control.

If the tool reports a connection error, check that the credentials are current and that the service is available. You can update expired credentials in the Details panel of the Tool details dialog.

Reflect: Pick one action that an agent you're planning or building needs. Which of its inputs should stay the same on every call, and which should come from what the user asks?

Later in this module, you explore how to refine the tool's name and description so that the agent calls it for the right requests, and how to test the tool in Preview to confirm that it runs with the right inputs and result.