Governance

Power Platform Governance Maturity Model: From Ungoverned to Enterprise-Ready

14 May 20265 min readGovernance

A five-level governance maturity model for Microsoft Power Platform, covering DLP policies, environment strategy, maker journeys, and the CoE Starter Kit. Assess where your organisation sits and what to do next.

Power Platform governance is the difference between a platform that compounds in value over time and one that accumulates security debt, licence waste, and shadow IT. Most UK organisations sit at Level 1 or Level 2 of this maturity model, and most do not realise it until a compliance audit, a data loss event, or a licence renewal bill forces the issue.

Why Governance Matters More in 2026 Than It Did in 2023

The Power Platform of 2026 is an AI platform: agents that take autonomous actions, connections to sensitive business systems, and AI-generated content that flows through business processes without a human reviewing every step. The governance stakes have risen proportionally.

An ungoverned Power Platform in 2026 means ungoverned AI agents with access to production data, ungoverned data flows between systems that should not be connected, and ungoverned licence assignment that is costing organisations thousands of pounds per month in unused capacity.

The Governance Debt Compound Effect: Every month without governance controls is a month of ungoverned app creation, connector usage, and environment proliferation. Remediating 18 months of governance debt takes significantly more effort than establishing controls from the start.

The Five-Level Governance Maturity Model

Level 1: Ungoverned

Signs you are here:

  • No formal environment strategy, developers building in the default environment
  • No DLP policies, any connector can connect to any data source
  • No maker journey, anyone with a Power Platform licence can build anything
  • No visibility into what has been built, no inventory of apps, flows, or agents
  • Licences assigned reactively, often over-provisioned

Next action: The priority at Level 1 is containment: implement a baseline DLP policy that blocks the most sensitive connectors from the default environment, audit the existing app and flow inventory using the CoE Starter Kit, and assign a single named governance owner.

Level 2: Reactive

Signs you are here:

  • Basic DLP policies exist but are not consistently applied across all environments
  • Some environments have been created but without a formal naming convention or lifecycle policy
  • Governance responds to incidents rather than preventing them
  • CoE Starter Kit may be installed but is not actively maintained
  • Licence reviews happen annually rather than continuously

Next action: At Level 2, the focus is formalisation: document the environment strategy, enforce DLP consistently across all environments, and establish a monthly governance review cadence.

Level 3: Defined

Signs you are here:

  • Documented environment strategy with personal, development, test, and production environments
  • DLP policies applied consistently with documented exceptions process
  • Maker journey in place, training, support, and approval process for new development
  • App and flow inventory maintained and reviewed regularly
  • Licence assignment based on actual usage data from the CoE Starter Kit

Next action: Level 3 organisations should focus on automation: automate the environment provisioning process, automate stale resource cleanup, and implement automated alerts for policy violations.

Level 4: Managed

Signs you are here:

  • Governance metrics are tracked and reviewed by leadership, not just IT
  • Automated policies enforce standards without requiring manual intervention
  • AI agent governance framework in place, agent inventory, human-in-the-loop requirements, sensitive data access controls
  • Managed Environments configured for production workloads
  • Solution lifecycle management, ALM pipelines for promoting solutions through environments

Next action: At Level 4, governance becomes a strategic capability. Expand the CoE to cover AI agents explicitly, implement solution checker as a mandatory gate in the ALM pipeline, and begin reporting governance health to the business alongside platform value metrics.

Level 5: Optimising

Signs you are here:

  • Governance is proactive, risks are identified and remediated before they materialise
  • Agentic AI governance framework covers autonomous agent actions, fallback policies, and audit trails
  • The platform CoE is a recognised internal capability with dedicated resource and executive sponsorship
  • Cross-environment data governance aligned with GDPR, FCA, and sector-specific compliance requirements
  • Continuous licence optimisation delivers measurable cost savings each quarter

Next action: Level 5 organisations should focus on innovation: use the governance foundation to safely accelerate agentic AI adoption, expand the maker ecosystem with confidence, and measure the platform's contribution to strategic business outcomes.

The CoE Starter Kit: Your Governance Foundation

Microsoft's Power Platform Centre of Excellence Starter Kit is a free collection of Power Apps, Power Automate flows, and Power BI dashboards that provide visibility and governance tooling for your tenant.

  • Inventory tracking: The CoE dashboard provides a complete inventory of apps, flows, connectors, and (from 2026) AI agents across your entire tenant, with usage metrics and owner information.
  • Compliance automation: Automated policies can quarantine apps that have not been used in 90 days, notify makers of stale resources, and enforce naming conventions.
  • Maker journey scaffolding: The CoE Starter Kit includes a maker onboarding app, a training completion tracker, and an environment request workflow.
  • Licence optimisation: Usage data from the CoE feeds directly into licence review decisions, identifying which users have unused Power Apps licences that can be reassigned or released.

The 2026 AI Governance Addition: What Agentic Platforms Require

The standard CoE governance framework predates agentic AI and does not cover the specific risks that autonomous agents introduce. UK organisations deploying Copilot Studio agents in 2026 need an extended governance layer covering:

  • Agent inventory, a register of all deployed agents, their purpose, their data access scope, and their action permissions
  • Human-in-the-loop requirements, defined criteria for which agent actions require human approval before execution
  • Sensitive data access controls, DLP-equivalent policies for which data sources agents are permitted to read from and write to
  • Agent audit trails, logging of agent actions at a level of detail that satisfies internal audit and regulatory requirements
  • Incident response procedure for agent misbehaviour, what happens when an agent takes an unintended action, and how to contain and remediate it

Work With Us

Ready to Put These Insights Into Action?

Book a free consultation with our Microsoft-certified experts and get a tailored Power Platform assessment for your organisation.