WORKSPACE.PM turns Microsoft Copilot into the project assistant for your whole organisation. Status, risks, workload and portfolio: ask in the chat and get answers from your real project data, with each person's own permissions, operated in Germany. One AI decision is enough: Copilot stays, WORKSPACE.PM adds the project truth.
Campus North is amber. 2 of 5 milestones done, 3 open risks, of which 1 critical (facade delivery delay). Cost positions: 1.2 million planned, 0.9 million committed.
Open in WORKSPACE.PM
200+project functions Copilot operates for you, from the status question to a new risk
100 %your permissions, never more: every answer with the rights of the person asking
DEoperated in German data centres, no second AI, no second contract
What changes when Copilot knows your projects
Microsoft Copilot is already in your organisation. What it lacks is access to project reality: dates, risks, capacity, costs. WORKSPACE.PM closes exactly that gap.
Answers instead of status meetings
Executives and steering committees ask Copilot for the state of a project or the whole portfolio and get the answer in seconds, with a link to the source. The status round becomes a decision round.
Leaders no longer wait for the report. They ask.
Project work where the conversation happens
A risk surfaces in Teams? Copilot creates it, measure included. A capacity question before a commitment? Copilot checks the assignments. Time entry, Kanban card, lessons learned: done without switching applications.
Fewer context switches, better maintained data, because maintenance happens on the side.
One AI decision is enough
You have approved Copilot, covered it contractually, embedded it in your tenant. WORKSPACE.PM asks for no second decision: no AI provider of its own, no second contract, project data stays in Germany and every person sees only what they are allowed to see.
IT and data protection gain control, not another risk.
Six things your team gets done with Copilot from tomorrow
Real working situations, real answers from WORKSPACE.PM. Every answer links back to the object in the system.
Steering committee
Status without copying from three windows
Prompt
Give me the status of project Campus North: milestones, open risks, cost positions.
Result
Copilot pulls the figures from WORKSPACE.PM and answers with clickable links to the project, its risks and the latest report.
Create a risk in project Campus North: facade delivery delay, likely, high impact, measure: request second supplier.
Result
If the person's role has write access for AI clients, Copilot creates risk and measure. The audit trail records channel MCP and the client name, as for every other change.
Five roles, one platform, one Copilot. Every role gets answers from the same data, within its own permissions.
Executives and steering committees
Portfolio state, critical risks and pending decisions on a single question, with source instead of slide.
PMO
Consistent answers across the organisation: Copilot reads the same data as your reports. Status questions from management answer themselves in the chat.
Project leads
Risks, tasks, time entries and lessons learned are created in the conversation, not in the evening catch-up.
Team
Open checklists, current sprint, own cards: ask instead of search, only from projects the person is a member of.
IT and data protection
Per-person rights, role gate for AI clients, audit trail with channel MCP, operated in Germany. Details further down.
Copilot in Planner, Microsoft Project or WORKSPACE.PM?
Copilot in Microsoft Planner serves Planner tasks. WORKSPACE.PM brings portfolio, risks, resources, costs, OKRs and requirements into the same chat. The detailed comparison is on our Microsoft Project alternative page.
You have made your AI decision. Microsoft Copilot is approved, contractually covered and embedded in your tenant. WORKSPACE.PM does not ask for a second decision: it brings no AI provider of its own and makes your project data available to the assistant you already use.
For your IT at a glance
The facts an IT lead needs before the first conversation. Each line is a statement about the product, not a promise about Microsoft.
Aspect
Fact
Who controls it
Transport
MCP over Streamable HTTP at /mcp
WORKSPACE.PM
Sign-in
OAuth 2.0 with PKCE and dynamic client registration (OAuth 2.1 profile), each person individually
the person
Identity
WORKSPACE.PM account, can be coupled to Microsoft Entra ID via SSO, provisioning via SCIM 2.0
your IT
Permissions
exactly the rights of the person, checked server-side on every call, including tenant separation in the database
your roles
External AI access
per role: no access, read only or write access; the gate can only narrow rights
your admin
Tools
over 200, read and write, from projects, risks and resources to Kanban, OKRs, requirements, portfolios and scenarios
catalogue
Traceability
changes: audit trail with channel MCP and client name; reads: counters per person, last use, last client, no content logging
your admin
Switch-off
tenant-wide switch in the Integration Hub, running connections end immediately
your admin
AI provider
none required for this route; Copilot remains your assistant
nobody
Operation
SaaS in German data centres, managed hosting or on-premises
contract
Identity
Copilot never signs in as an application
Each person signs Copilot in as themselves, via OAuth 2.0 with PKCE. No service account, no shared token. The consent screen names the application, the account, the tenant and the scope.
If SSO via Microsoft Entra ID is enforced, your Entra policies including MFA apply to this sign-in as well
An account deactivated in WORKSPACE.PM loses access immediately, even with a valid token
To make a block in Microsoft Entra ID reach WORKSPACE.PM automatically, enable SCIM 2.0 provisioning; without SCIM, block the account in WORKSPACE.PM as well
Sign in to WORKSPACE.PM
Application
Copilot agent (as registered)
Account
m.lang@example.com
Tenant
Example AG
Scope
workspace:pm
The application acts with exactly your permissions.
CancelAllow
Permissions
Exactly the rights of the person, plus a gate for AI clients
Copilot acts with exactly the permissions of the signed-in person, checked server-side with roles and row-level security. On top of that you limit per role what external AI clients may do: nothing, read only or write.
The gate can only narrow permissions, never widen them
Our recommendation for the start: read only, then enable write access role by role
The gate applies to all external AI clients alike; restricting it to a single application, such as only your Copilot agent, is not possible at present
Whether Copilot asks before an action is decided by your Copilot agent; whether the change is possible at all is decided by WORKSPACE.PM
External AI clients per role
No access
Read only
Write access
Administrator
PMO
Team
80 read tools0 write tools
The gate can only narrow permissions, never widen them.
Traceability
Every change carries channel MCP and the client name
Every change triggered through Copilot is written to the audit trail with channel MCP, the acting person and the name under which the client registered, linked to the changed object and filterable by source.
Administrators see which person connected when, how many requests ran and which client was used last
Read access is counted per person, not logged by content; WORKSPACE.PM stores neither your prompts nor the answers
The audit trail is append-only and records the channel, not the network address of the client
One switch disconnects the entire MCP access of the tenant, running connections end immediately
Connected people
PersonRequestsLast client
M. Lang142Copilot agent
S. Kern37Copilot agent
B. Bolzmann9Claude Desktop
Audit trail, filtered by source: MCP
Risk R-18 created
M. Lang
Channel: MCPClient (as registered): Copilot agent
Card K-204 moved
S. Kern
Channel: MCPClient (as registered): Copilot agent
Data flow and contracts
Copilot pulls. WORKSPACE.PM does not push.
Over the MCP route Copilot retrieves data from WORKSPACE.PM. WORKSPACE.PM sends nothing to Microsoft on its own and runs no AI model of its own for this route. There is no broker in between and no additional store.
Project data is processed in German data centres or in your own operation, governed by the data processing agreement under Art. 28 GDPR
Which data an AI client you connect retrieves is your decision as controller; Microsoft Copilot acts on the basis of your Microsoft contract, WORKSPACE.PM is not involved in that processing
Answers Copilot obtains from WORKSPACE.PM become part of the Copilot chat history in your Microsoft tenant and are subject to your retention rules there; deletion in WORKSPACE.PM does not reach those copies
Depending on the question, answers also contain personal data of your employees, such as names, assignments and time entries; use the role gate to limit which roles get access at all
Your Microsoft contract
Microsoft Copilot
agent in your tenant
DPA with WORKSPACE.PM
WORKSPACE.PM
MCP endpoint, Germany
pulls with the rights of the person
answer becomes part of the Copilot chat history
no push, no broker, no extra store
Operated where your rules require it
The Copilot connection works the same in all three operating models. What changes is who runs the endpoint.
SaaS in Germany
Operated in German data centres, DPA under Art. 28 GDPR, no US sub-processor for project data.
Managed hosting
Your own instance, operated by us, in Germany or in the data centre you specify.
On-premises
Your own operation. The MCP endpoint of your installation must be reachable from the Microsoft cloud over HTTPS, for example through a reverse proxy or application proxy.
Purely internal installations without internet ingress cannot connect Copilot. For public sector clients: on-premises and managed hosting in Germany, Copilot connection optional and switchable per role.
Your existing Microsoft controls continue to apply
According to Microsoft documentation as of September 2026. These are statements about Microsoft products, not commitments by WORKSPACE.PM.
Approval in the Microsoft 365 admin center
Your IT approves agents, assigns them to groups or blocks them.
DLP in the Power Platform admin center
MCP access in Copilot Studio runs through Power Platform connectors and is subject to your data policies.
Microsoft Purview
Purview logs Copilot interactions with the agent and the plugin used. WORKSPACE.PM adds the audit trail on the data side.
How WORKSPACE.PM gets into your Copilot
WORKSPACE.PM provides the prerequisites Microsoft documents for external MCP servers in Copilot Studio. The step-by-step guide with screenshots will follow in the knowledge base once our own end-to-end test is complete.
Microsoft Copilot Studio
Your maker adds WORKSPACE.PM as a tool of type Model Context Protocol, enters the MCP address of WORKSPACE.PM (for on-premises, the address of your installation) and selects OAuth 2.0. Copilot Studio supports exactly the transport WORKSPACE.PM speaks: Streamable HTTP.
Microsoft Teams without Copilot
The WORKSPACE.PM Teams app delivers adaptive cards, bot commands and project tabs today, without a Copilot licence. Note: this integration actively sends notifications into your Teams channels.
For integrators and IT projects
Streamable HTTP, OAuth with dynamic client registration, tool catalogue in the knowledge base. GitHub Copilot in VS Code can use the MCP server as well, with the same rights and the same role gate.
What your IT needs for it
Check two settings in the WORKSPACE.PM Integration Hub before the pilot: the MCP switch itself and the role gate for external AI clients, which we recommend setting to read only for the start
One WORKSPACE.PM account per person, ideally provisioned via SCIM from Microsoft Entra ID
On the Microsoft side: a Copilot Studio agent with actions, approved in the Microsoft 365 admin center
The four questions that come up in every security review, answered with what the product actually does.
Then Copilot sees everything?
No. Every answer is computed under the identity of the person asking. Confidential projects remain invisible, including for search and evaluation. What Copilot stores from the answer is governed by your Microsoft contract.
What if the AI changes something wrong?
Write tools can be blocked completely per role or limited to reading. Whether Copilot asks back before an action is controlled by your agent; in the system the person's normal rights apply in addition. Every change is marked as an MCP change in the audit trail.
What does the works council need to know?
WORKSPACE.PM stores no questions you ask Copilot and no answers. Stored per person are the number of requests, the time of last use and the client, plus every change with channel MCP. Your Microsoft tenant does store the chat history, under your retention rules there.
Are we locking ourselves into Microsoft?
MCP is an open standard. The same endpoint works with Claude, ChatGPT or local models. If you change the assistant, the connection stays. And you can switch the integration off tenant-wide at any time.
Frequently asked questions
Short answers for IT, data protection and PMO. Where a point still needs our own end-to-end test, we say so.
Yes, through an agent in Microsoft Copilot Studio that uses the MCP server of WORKSPACE.PM as a tool. There is no Microsoft Graph connector; the connection works over the open Model Context Protocol with Streamable HTTP and OAuth and is acting, not just searching. The agent runs in your Microsoft tenant and is approved by your IT in the Microsoft 365 admin center.
Read and, if the role allows it, write: projects, portfolios and scenarios, risks with measures, Kanban cards, time entries, resource assignments, OKRs, requirements, lessons learned and more, over 200 tools in total. Every answer links to the object in WORKSPACE.PM. Not reachable via MCP are meetings, documents, stakeholders, change requests, dashboards and user administration.
No. Each person signs Copilot in as themselves, and every call is checked server-side with exactly their rights, including tenant separation in the database. An additional role gate for external AI clients can only narrow these rights further, never widen them. Confidential projects remain invisible to Copilot as well.
Only if the person's role is set to write access for external AI clients. Administrators set no access, read only or write access per role. Write tools are additionally tied to a valid licence. Whether Copilot asks back before an action is controlled by your Copilot agent; the change itself is logged in WORKSPACE.PM with channel MCP.
Every change carries the channel in the audit trail (user interface, embedded assistant, MCP, API) and, for channel MCP, the name under which the connecting client registered. The audit view can be filtered by source, every entry links to the changed object, and the audit trail is append-only. The client name is what the client registered, so treat it as a label, not as proof of a specific product.
The usage overview shows connected people, active connections, requests, last use, last client and token validity. A switch disconnects the integration tenant-wide, running connections end immediately. If an account is deactivated, it loses access even with a valid token. Revoking a single connection per person from the admin side is not available at present.
WORKSPACE.PM processes project data exclusively in Germany, as SaaS, managed hosting or on-premises. Copilot retrieves the endpoint directly; there is no broker and no additional store. What Microsoft processes from the answer in your tenant is governed by your Microsoft contract, not by WORKSPACE.PM.
For WORKSPACE.PM the data processing agreement under Art. 28 GDPR applies that you conclude for the platform anyway. Which optional functions and third-party integrations you activate, and which data is transmitted in the process, is your decision as controller under that agreement. For Microsoft Copilot your existing Microsoft contract applies. Please have the final assessment made by your data protection officer.
The Copilot sign-in runs through the normal WORKSPACE.PM sign-in. If SSO via Microsoft Entra ID is enforced, your Entra policies including MFA apply to it. Roles can be assigned via Entra groups, accounts can be provisioned and withdrawn via SCIM 2.0. The end-to-end flow inside the Copilot sign-in popup is part of our own verification and will be documented in the knowledge base.
An agent with actions is built in Microsoft Copilot Studio and runs on your organisation's Copilot licence or Copilot credits. The costs for operating the agent arise at Microsoft; WORKSPACE.PM needs no AI provider of its own for this route. Which licence level your tenant has can be found in the current information from Microsoft.
Yes. The same MCP endpoint works with every client that speaks Streamable HTTP and OAuth. The integration can be switched off tenant-wide, independently of the embedded assistant of WORKSPACE.PM, which optionally works with Anthropic, OpenAI, Google, an OpenAI-compatible or a local model.
Thirty minutes with someone who knows the MCP server from the code: identity chain, role gate, audit trail and what your data protection officer will ask.
Product facts as of September 2026, taken from the WORKSPACE.PM source code and tool catalogue. Statements about Microsoft products are based on public Microsoft documentation as of September 2026. Microsoft, Microsoft 365, Copilot, Entra ID, Teams and Purview are trademarks of the Microsoft group of companies. WORKSPACE.PM is not affiliated with Microsoft.