Skip to content
Release: Australia · Updated: 2026-07-03 · Official documentation · View source

Create a Copilot Studio Dataverse custom role

Create a Copilot Studio Dataverse custom role.

Before you begin

Role required: User Security role

Procedure

  1. Navigate to Power Platform Admin Center > Environments > Pick the environment > Settings > Users + Permissions. > Security roles.

  2. Click New role and give it a name like SGC-Copilot Discovery (Read only).

    Note: Start empty rather than copying, so you don't inherit stray privileges.

  3. In the role editor, find each of the three tables and set only the Read privilege.

    Note: Leave Create/Write/Delete/Append/Append To/Assign/Share at None.

  4. Set the Read access level to the scope your discovery needs.

    For tenant/environment‑wide cataloging via a service principal, set Read to Organization (the filled full circle) on all three tables. Anything lower (User/BU) will silently hide records the app user doesn't "own."

  5. Save.

    Note:

    The three targets:

    • Bot — the agents/copilots themselves.
    • Bot component — topics, entities, and other authored components.
    • Conversationtranscript— the transcript records; the transcript body lives in the Content column, which comes back with the row's Read privilege (no separate file/attachment privilege needed for this table).