- Documentation
- Teams agent
What your people see in Teams
What the core product sends to everyone, what the optional agent adds on top, and what neither of them will do.
Audience: ISMS Admin, deciding what your organisation will experience. Also useful to paste to your team.
The short version: the core product tells people things in Teams. The optional agent lets people ask. Acknowledging a policy happens on your SharePoint site either way.
What everyone gets, with no add-on
Section titled “What everyone gets, with no add-on”These need nothing beyond your existing Microsoft 365 subscription. No Power Platform licence, no Copilot licence.
A message when policies are published. When you approve documents, everyone receives one Teams message listing everything newly published since the last run, rather than one message per policy. It links to your Published Policies list.
A daily reminder if something is outstanding. Anyone who still owes an acknowledgement gets a daily nudge. People with nothing outstanding are not messaged.
A daily task summary. The compliance tasks assigned to that person, at the hour you chose during setup.
A daily incident prompt, if you enabled it. A low friction ask about whether there is anything to report. High and critical incidents also email the ISMS administrator.
What the agent adds
Section titled “What the agent adds”The Certaria agent is an optional add-on. Everything above works without it. It puts a conversational assistant into Teams chat, so people can ask rather than wait to be told.
Ask ISO 27001 questions in plain English. “What does A.5.10 actually require?” Answers come from a curated ISO 27001 knowledge base, grounded in the standard rather than the open internet.
Acknowledge a policy in the conversation. An alternative to the SharePoint list, not a replacement for it. Both routes write the same record, and an acknowledgement made either way stops the reminders.
Report an incident. A guided conversation captures what happened and logs it, notifying the administrator for serious cases.
Check where things stand. Open tasks, outstanding acknowledgements, and progress.
Everything the agent records lands in the same registers as the rest of Certaria. There is one compliance record whichever surface it came from.
What neither will do
Section titled “What neither will do”Knowing the boundary is part of trusting the tool.
- Neither gives legal advice, and neither certifies you. Those decisions belong to your auditor and your certification body.
- The agent answers from your ISMS data and its ISO 27001 knowledge base. Anything outside that gets an honest refusal rather than a plausible guess.
- The agent does not act without showing you. Anything it creates or changes is confirmed in the conversation and visible in the hub immediately.
- Certaria does not change your Microsoft 365 configuration. Every Graph permission it holds is read only.
Enabling the agent
Section titled “Enabling the agent”The agent is a separate add-on solution and runs on Microsoft Copilot Studio capacity in your own tenant. It needs Copilot Credits, not a per user Copilot licence, and the difference matters: see Powering the agent and How agent billing works.
Common failure modes
Section titled “Common failure modes”| Symptom | Cause | Fix |
|---|---|---|
| Nobody receives any Teams message | The account that posts messages was left blank during setup | Set it on the wizard’s Step 3 screen |
| One person receives nothing | They have no linked user account, or no email address recorded | Check the people register. Imported people usually have this automatically |
| Reminders arrive an hour later in summer | The hours you set during onboarding are UTC, so they shift against UK time | Expected. Adjust the hour if it matters. Certaria’s own built-in schedules follow the UK clock and do not shift |
| Someone acknowledged but is still being reminded | Acknowledgements are ingested hourly | Wait for the next run. If it persists after an hour, check the person is linked to the right identity |
| A published policy is not in the Published Policies list | Its file is still in Pending Applicability, or the category is excluded | See Publish a policy |
- Publish a policy, which is what starts the loop
- Powering the agent: credits, not licences
- Troubleshooting