Copilot icon

How much do your agents cost? Users cant tell.

The conversation many of us in the legal industry have been having about tools like Copilot Cowork, especially as we get into the 2027 budget planning season, is about how to budget for AI token usage.

Obviously, there may be some interest in using these tools, but one thing that many of us with access to the Copilot Admin tools might not realize, and which I hadn’t thought much about, was shared in this LinkedIn post by Mahmoud Hassan:

While the Microsoft 365 admin center dashboard provides a centralized view of spending patterns, helping administrators identify where credits are used, who consumes them, and how usage trends evolve over time.
End-users are kept in the dark, while many enterprises now implement group or user levels limit for Cowork.

This is a legitimate issue; end-users can’t see how much they are spending on tokens across sessions. They may have no idea that they have used up all of the team’s allocated tokens. This creates an interesting opportunity to gamify token spend in a much more effective way than just listing out who used the most.

We can publicly measure the cost of someone using AI against the output of their work. If the user can’t tell the total cost of their AI work, we can create a dashboard of costs and let the workforce judge themselves openly. Since users can’t tell themselves how much compute they’re using, we make it public and make them prove the value.

It’s not great that Microsoft makes it this difficult to see how much you’re using as an individual, but as an Admin, this can be used to our advantage.

How do you let people know how much they are spending on Copilot tokens?

 

Similar Posts

  • |

    Worth Reading – Is Microsoft 365 Copilot Tracking Your Prompts? The Real Enterprise Answer

    You may read that and think that means your employer can see every prompt you enter in Copilot. To some extent, that is true; in the same way, they can see every email message or Teams chat you type with your work account. It is a work account after all. The key piece missing from that simple statement is that it’s not easy to do, and, by design, there are usually very few people who can collect and review that data. Usually, the effort required to do that isn’t worth it. So, if it has happened to you, it’s likely because someone or something has raised a suspicion that warranted an investigation. Most users never reach this level of scrutiny. 

  • M365 News for March 2026

    This post will be updated throughout the month as new items are added to the tag.

    Be sure to subscribe to my M365 Newsletter for more M365 expertise and news.

  • M365 News for February 2026

    This post will be updated throughout the month as new items are added to the tag.

    Be sure to subscribe to my M365 Newsletter for more M365 expertise and news.

  • Worth Reading – Why Staying Up-to-Date with Microsoft 365 Feels Like Hitting a Wall

    Most are just trying to get through the overwhelming amount of work they need to do. Learning a new tool isn’t on their radar unless it can help them get that work done right this very moment. Meanwhile, we’ve got a bunch of IT leaders spending a ton of time learning these tools or testing the compliance issues involved in using them, which we should do. How much is enough, though? How much time do we dedicate to tools that are going to be used by less than 10% of the workforce? 

  • Copilot Bug is a Big Deal for Confidentiality, But Not That Big

    Here’s why this is such a big problem. Microsoft recommends blocking Copilot from accessing sensitive information in emails, meetings, documents, and related content by assigning a label to those items and creating a DLP policy that defines the block. This bug renders the system unusable for the affected emails. You simply can’t provide a governance tool that doesn’t deliver the governance it claims to provide. It’s a bad look, Microsoft. It doesn’t help build customer trust. 

    No, Copilot did not make these emails public or access private information and make it non-private. It accessed information in response to your prompt that it should ignore. That creates a risk that many users might assume does not exist. That is a significant issue, but it’s not equivalent to a data breach. There is another check in place before data leaks out: the end user. 

Leave a Reply

Your email address will not be published. Required fields are marked *

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)