Microsoft 365 Copilot · Copilot Studio · Foundry

Copilot does the work.
A person signs it off.

Deliverd is the human layer for the agents your organisation builds on Microsoft. When an agent in Copilot Chat, Copilot Studio or Foundry needs an approval, a review, an answer or a decision, Deliverd asks the right person — in Teams, by email or on their phone — and hands the answer back, with a record of who decided what and why.

One MCP server for every Microsoft agent surface · Approvals in Teams · Free to start

Where it fits

Every place your organisation builds agents on Microsoft

One Deliverd organisation, one set of approvers and one record, whichever of these an agent runs in.

MicrosoftDeliverd
Microsoft 365 Copilot ChatThe Deliverd agent, in the Microsoft 365 app package. Ask it to get something approved or to check on a request: it signs you in to Deliverd once, and Copilot runs the read-only tools straight away and asks you before anything that changes something.
Copilot CoworkThe same package adds Deliverd's tools to Cowork as a connector, with the approval, ethics, artifact and tasks skills that teach an agent when to stop and ask a person.
Microsoft TeamsEach approver gets the request as a direct message with Approve and Decline, and every copy updates once it is decided. Organisations that require single sign-on through Microsoft Entra ID over OpenID Connect decide in Teams too.
Copilot StudioAdd Deliverd as a Model Context Protocol tool, signed in with OAuth or an agent key. The server speaks Streamable HTTP, the transport Copilot Studio connects over.
Microsoft FoundryAdd the MCP tool with an agent key. When Foundry pauses a call for approval, the Python SDK's Foundry adapter puts it in front of a named person and answers Foundry with their decision.
Microsoft Agent FrameworkThe Python SDK's Agent Framework adapter turns a tool-approval request into a Deliverd approval, so a person — not the code — decides whether the call runs.
Microsoft Entra IDSingle sign-on over SAML or OpenID Connect on Team, Business and Enterprise, and Directory Sync over SCIM 2.0, with groups mapped to teams and roles, on Business and Enterprise.
SharePointA published report can sit in a SharePoint page. One anybody may read renders in place; a private one shows a card that opens it, so access is still checked every time.

How it runs

One approval, from Copilot to the record

  1. 1

    The agent asks

    It calls request_approval with what it wants to do and who should decide. Copilot asks you to confirm first, because the call changes something; reading the answer back never needs a confirmation.

  2. 2

    A person decides where they are

    The approver gets a Teams message, an email and, if they turned them on, a push notification. They can approve, approve with changes, decline with a reason, or ask the agent a question.

  3. 3

    The agent carries on

    The call returns at once, so it never runs into Copilot's time limits. The agent checks back with get_approval and acts only on a yes.

  4. 4

    The record stays

    Who asked, who decided, what changed and why, in an audit log nothing can edit — and in an evidence pack when the work is governed under Compliance Mode.

Built for Microsoft's rules

The details that decide whether an agent loads at all

Microsoft's agent clients are stricter than most, and each refusal costs the whole server rather than one tool. These are met in the code, not in a workaround.

Every tool says whether it only reads

Microsoft 365 Copilot asks before calling any tool not marked read-only, and treats an unmarked one as destructive. Every Deliverd tool is marked, so looking something up runs straight away and changing something asks first.

No call holds the line

Microsoft limits how long a tool call may take. Every request returns at once and is checked back on, rather than holding the call open until somebody answers.

A tool list Foundry accepts

Foundry refuses a whole server if one tool's schema uses anyOf or allOf. The list we serve has neither, and a test that reads it from the live route fails our build if one appears.

Sign-in Microsoft's token stores accept

OAuth 2.1 with PKCE, a client secret issued at registration as Microsoft 365 Copilot requires, and that secret accepted in the header or the form.

Setup

Connect Copilot

Every Microsoft surface reaches the same server. People sign in to Deliverd with OAuth; Foundry, which calls from Azure, uses an agent key.

Microsoft 365 Copilot, Cowork and Teams

An administrator downloads the app package from Admin → Integrations in Deliverd and uploads it in the Teams admin centre or the Microsoft 365 admin centre. Each approver then adds the app in Teams, so it can message them.

Copilot Studio

Tools → Add a tool → Model Context Protocol, with this address:

https://deliverd.dev/api/mcp

Microsoft Foundry

Give a Foundry agent Deliverd's tools, and send the calls you gate to a named person instead of answering them in code.

  1. 1

    Issue a key for the agent

    Admin → Agents → the agent → Credentials → Issue new key. Its requests are then the agent's, under the permissions you gave it. Agent identities are on Team and above.

  2. 2

    Keep it in a key-based connection in your Foundry project

    Authorization: Bearer dlv_…

    One key named Authorization whose value is the word Bearer, a space, and the key. Foundry sends it as a header on every call to the server.

  3. 3

    Add the MCP tool to the agent

    from azure.ai.projects.models import MCPTool
    
    MCPTool(
        server_label="deliverd",
        server_url="https://deliverd.dev/api/mcp",
        require_approval="always",
        project_connection_id=connection.id,
    )

    With require_approval "always", Foundry pauses before each call with an mcp_approval_request. run_with_deliverd_approvals from deliverd.adapters.foundry (the Python SDK, from 0.11.0) asks a person in Deliverd and answers it.

The administrator’s side, step by step, is in the integrations guide; the Python adapters for Foundry and Agent Framework are in the SDK documentation.

Microsoft partners

Building Copilot agents for clients?

The question that stops a client’s agent at the risk review is who says yes before it acts, and where that is written down. Deliverd is the answer you can build in: approvals in Teams, evidence the client keeps, and one sign-in for your people across every client you run.

Questions

Microsoft and Deliverd.

Is Deliverd in the Teams store or Microsoft's commercial marketplace?

Not yet. An administrator adds Deliverd to a tenant by downloading the app package from Admin → Integrations and uploading it in the Teams admin centre or the Microsoft 365 admin centre.

Why does Copilot ask me to confirm before Deliverd does something?

Microsoft 365 Copilot asks before any tool call not marked read-only. Deliverd marks every tool, so looking something up runs straight away, and anything that changes something — asking for an approval, publishing a report — asks you first.

Can approvers decide in Teams if we require single sign-on?

Yes, when your organisation signs in with Microsoft Entra ID over OpenID Connect: Teams then proves the approver is that same Microsoft account. With SAML, they decide in Deliverd itself, from the email or the app.

Does Deliverd read our Microsoft 365 data?

No. The app package asks for no Microsoft Graph permissions, only Teams' permission to know who pressed a button and to message the approver. Deliverd receives what an agent sends in a request and what people do with it.

Which plan do we need?

Asking for approvals, and deciding in Teams, work on every plan, Free included. Agent identities — the agent key Foundry uses — are on Team, Business and Enterprise; Compliance Mode is on Business and Enterprise.

Do we have to use Copilot?

No. Deliverd is neutral to the AI you choose: Copilot agents, ChatGPT, Claude and your own agents can share one organisation, one set of approvers and one record.

Is there a .NET adapter for Agent Framework?

Not yet; the adapters are in the Python SDK. A .NET agent reaches the same requests over MCP or the REST API.

Put a person in front of what Copilot does.

Start free, connect one agent, and send its first request to someone who can say yes.