Knowledge | Macaw

Power Apps & Governance: How to Build a Robust and Secure Power Platform

Written by Michel Heijman | Aug 20, 2026, 12:33:29 PM

The Power Platform enables employees to build their own business apps, also known as PowerApps. But what about governance and compliance? In this blog, we explain how to set up a PowerApps environment in a secure and controlled manner.

IT departments are still juggling a lot of tasks. Technology is penetrating deeper into every department, and the demand for new applications continues to grow. In 2019, this was already creating significant pressure; digital transformation often proceeded more slowly than hoped because the IT department became overburdened. At the time, the Microsoft Power Platform offered a solution: an accessible platform that allowed employees from departments such as HR, Marketing, and Sales to build their own business apps and automations. Back then, however, very few organizations were using it. By 2025, the Power Platform has been widely adopted and has become a crucial component of digital innovations. At the same time, the platform’s capabilities have expanded significantly, particularly through additions such as AI Builder and the brand-new Copilot Studio for AI agents (virtual assistants). These developments bring enormous opportunities for productivity, but also raise new considerations regarding governance. Setting up the Power Platform must therefore still be done with great care: it involves working with business-critical (and now also AI-generated) data that must remain secure, and uncontrolled growth can pose risks. In this article, you’ll learn how to set up a secure and controlled Power Platform environment in 2025, with a focus on the latest trends and capabilities.

Adoption and Citizen Development

To get the most out of the Power Platform, you need to create a supportive environment where citizen developers— non-technical colleagues—can innovate safely. This means giving employees the freedom to build their own apps, flows, or agents within agreed-upon parameters. Organizations generally approach this in three ways, depending on their culture:

  • Bottom-up: The business is given a great deal of freedom and responsibility. IT merely facilitates (sets up the platform) and otherwise stays in the background.
  • Blended: The business builds its own solutions, but within limits defined by IT and under its supervision. This fosters controlled growth.
  • Top-down: Only IT builds and publishes apps and flows; the business uses what is made available. This is the safest approach in terms of control, but it goes against the self-service principle and places the entire burden on IT.

Whichever approach you choose, it’s essential to establish an appropriate governance structure. That structure provides the rules and safeguards within which citizen developers can operate. In other words: grant freedom where possible, but set clear boundaries where necessary.

Governance in 2026: Where Do You Start?

The next question is how to approach governance now that the platform is already (somewhat) in use within your organization. After all, unlike in 2019, you’re no longer starting from scratch—Power Apps have likely already been built and flows are already in use. That’s why we now invariably begin a governance initiative with an assessment of the current Power Platform landscape. Using a combination of our own Macaw analysis method and Microsoft’s Center of Excellence (CoE) Starter Kit, we map out which solutions exist, who the creators and users are, and how the platform settings are configured. This inventory (or baseline assessment) highlights any risks and pain points. For example, you can see whether a Data Loss Prevention policy is missing or if many creators are active in the uncontrolled Default environment. Such a scan is also useful for organizations that established governance agreements a few years ago: it provides an up-to-date picture and shows whether adjustments are needed now that the platform has grown further.

Armed with the insights from the assessment, the next step is to design a governance framework tailored to your organization. We often organize a“Governance in a Dayworkshopfor this purpose, bringing together both IT and business stakeholders. Together, we discuss the goals and requirements for using the Power Platform—from which data can be safely shared to what support citizen developers need. Instead of a traditional paper-based solution, we opt for an interactive approach: the outcome of such a session isn’t a voluminous High-Level Design document, but a pragmatic governance blueprint. This is a central “blueprint” that sets out all key decisions and guidelines, ready to be used immediately as a guide for implementation. The major difference from the past is that this blueprint is created in collaboration with the business, is dynamic, and can be adapted as new insights or technologies (such as AI) emerge. With a governance blueprint as your compass, you can then get to work setting up and securing the Power Platform environment in accordance with the agreed-upon guidelines.

Governance: Getting Started Safely and in a Controlled Manner

One of the first topics in the blueprint is the organization of environments. Here, we determine how Power Platform environments should be set up to ensure development proceeds smoothly. Whereas a single environment used to suffice for a handful of experiments, most organizations now opt for a multi-environment model. Think of separate environments for experiments, testing, and production, or by department. This provides structure and ensures that developers can only access the data relevant to them. Microsoft has also simplified the management of this with Managed Environments, an optional set of management features that you can enable per environment to more easily enforce governance (such as usage insights, automatic cleanup of unused apps, etc.). A good environment strategy prevents chaos: it is the foundation upon which further governance measures are built.

Monitoring security and data protection is at least as important. Fortunately, as a cloud service, the Power Platform complies with the most important standards (such as HIPAA, EU Model Clauses, ISO, SOC), but additional policies are needed to prevent data breaches. Data Loss Prevention (DLP) policies are a crucial tool for this. With DLP, you determine which data may and may not be combined within an environment. For example, you can prevent someone from creating a flow that sends HR data to a Twitter account. By establishing clear DLP rules from the start, you can shield sensitive information and reduce the risk of unintended data leaks.

In addition to technology, human oversight is also necessary. We recommend setting up a Center of Excellence (CoE): a small team (often a mix of IT and business professionals) responsible for the adoption and oversight of the platform. This team handles training, provides support for creators, and monitors what is being built. Microsoft’s CoE Starter Kit helps with this by providing dashboards and alerts, so you can continuously see how many apps there are, where they’re running, and whether there are any anomalies. It’s important to view governance as an ongoing process: regular checks (e.g., a monthly report from the CoE dashboard) and policy adjustments are just as much a part of it as that initial workshop. This ensures your Power Platform remains airtight as it continues to grow.

AI-Driven Automation: A New Dimension in Governance

In recent years, a new dimension has emerged: AI has made its way into the Power Platform. AI Builder has now matured into a robust toolset for integrating AI models into your apps and processes. And Microsoft’s new Copilot Studio (formerly Power Virtual Agents and part of the broader Copilot vision) makes it possible to build advanced AI agents that execute commands and communicate with users in natural language. These innovations greatly increase the productivity and agility of citizen developers, but they also require extra attention in your governance approach. After all, how do you ensure that AI is used responsibly?

The good news is that the core principles of governance remain the same. You can reuse many of the lessons and measures you apply to “regular” Power Apps for AI applications. Microsoft has since added specific controls to manage AI functionality. AI Builder integrates AI models (e.g., for reading invoices, predicting trends, or classifying images) into Power Apps and Power Automate. As part of the Power Platform, AI Builder falls under the same management environment: you can configure per environment who is allowed to create and publish AI models and track how many AI credits are being used. It’s wise to allow AI Builder models only in specific environments and to thoroughly train and test them before deploying them company-wide—similar to how you would take an app through development and testing phases. Furthermore, data quality remains a key consideration: an AI model is only as good as the data it’s trained on, so ensure this is safeguarded (for example, by involving data science experts with creators who want to use AI Builder).

Copilot Studio is a newer offering and introduces the ability to build custom AI assistants (Agents) that can perform entire tasks and engage in conversation. Think, for example, of a virtual help desk agent or an agent that autonomously generates reports based on chat commands. Due to the nature of these agents (they can access a wide range of systems and take action), strict control is essential here. Fortunately, Copilot Studio allows you to manage access at multiple levels:

  • Tenant level: As an administrator, you can, for example, disable or restrict generative AI in agents organization-wide, or grant permission to build agents only to specific groups. You can also configure whether AI in Copilot Studio has access to certain business data or not (via custom policy rules similar to DLP).
  • Environment level: Settings for AI functionality can be configured per environment; for example, you can determine whether creators in a specific environment are allowed to share agents with colleagues or whether an agent is permitted to use internet sources (such as Bing Search). Auditing (logging) of AI activities can also be enforced per environment, especially in production environments.
  • Agent level: When creating an individual agent, you as the creator can configure certain security options, such as whether the agent is accessible only with Microsoft Entra ID (formerly Azure AD) accounts, which channels (Teams, website, etc.) it is allowed to use, and whether it can call external APIs. This allows you, for example, to prevent an agent from being unleashed unmanaged on public channels or data.

Another important aspect of AI governance is monitoring. Whereas a traditional app operates deterministically (you know exactly which steps occur), an AI agent can sometimes produce unpredictable output. That’s why insight into AI behavior is essential. Copilot Studio provides comprehensive audit logs by default: all actions taken by creators and users related to a Copilot agent are automatically logged and can be viewed through the Microsoft Purview Compliance Center. For example, you can see retrospectively who created or modified an agent, how often an agent was queried, and what the outcome was. You cannot disable these logs (though you can adjust the retention period), which is reassuring from a governance perspective. There’s always a paper trail. Additionally, you can optionally enable integrations with tools like Azure Application Insights for even more detailed telemetry about your agents (performance, errors, etc.). We recommend periodically reviewing AI activities. For example, review the chat transcripts of critical AI conversations—perhaps on a random basis—to verify that the agent is performing as intended and not providing inappropriate responses. This keeps the “human in the loop” and prevents AI from making uncontrolled decisions without supervision.

The key is to apply familiar governance tools intelligently to new AI capabilities; role-based permissions, clear environmental segregation, and DLP policies remain the cornerstones, now supplemented with AI-specific settings and logging. By explicitly making AI Builder and Copilot Studio part of your governance agreements (for example, by including them in your blueprint and CoE methodology), you can embrace AI-driven automation without losing control.

Conclusion

In this updated blog post, we’ve explored how to build a watertight and secure Power Platform in 2025. Much has changed since 2019: the platform has matured, and AI adds a new layer of intelligence to low-code development. Still, the basic principles remain the same. Ensure a solid foundation, start by understanding your current situation, draw up a practical governance blueprint together with business and IT, and implement the appropriate settings and policies step by step. Take the latest developments—such as AI Builder and Copilot Studio—into account by establishing guidelines for them as well. This way, you maintain the right balance between freedom for users and control for the organization.

Does your organization:

  • Not yet implemented the Power Platform and looking for help to get it right from the start?
  • Already implemented the Power Platform and looking for a health check?
  • Mastered Power Platform governance but need guidance on all the new developments (Copilot Studio, AI Builder, etc.)?

If so, please contact us. We have a standardized approach (based on 25+ organizations where we’ve carried out similar activities, including HEINEKEN and FrieslandCampina) and tailor it as needed to fit your specific situation.