Craig Stanley

Risk · 12

Someone has to be able to switch the app off

Abstract print on warm paper.

Microsoft's 10 September 2026 app-building note shows a field-service app that retrieves third-party product detail and writes a result back to a connected system. The value is the write-back. The risk is the write-back. Managed Runtime, in public preview from 25 September, is how Microsoft says that code is hosted inside the tenant, where an administrator can enable or disable the app.

Promotion is a decision

A prototype that only the maker can see is a sketch. An app with an audience, a connection and a health signal is an internal tool.

Read before write

The same September note's onboarding example, progress, learning resources, updates to onboarding records, is also an illustration, not an outcome. A read-heavy version tells you whether the data access is sane. A write tells you whether you trust the maker's instructions with a record a person will later rely on.

Fiction keeps a rollback owner

The FrontierOrg method, explicitly fictional, will not scale a pilot without a rollback owner and a human sign-off for a consequential customer or HR action. There is no FrontierOrg tenant to copy. There is a gate you can put on your own list before the first write-back.

Monday

For any Copilot-built app already shared beyond its maker, write the name of the person who can disable it today. If the name is the maker alone, the app is not ready for a second team.

What is the first record you are willing to let a Copilot-built app change, and who reverses it if the change is wrong?

Sources: Microsoft, 10 September 2026, Build business apps with Copilot Cowork and Copilot Studio (opens in a new tab). Microsoft Copilot Blog, Managed Runtime, public preview 25 September 2026 (opens in a new tab).

Where this note mentions FrontierOrg, that is a fictional method for rehearsing a decision. It is not a company, not a client, and not a case study.

Back to Risk