AIPSO Setup Wizard
The Platform & Security Officer (AIPSO) Setup Wizard walks IT admins through configuring the managers, autonomy level, communication schedule, email channel, and tools for your AIPSO agent, then activates it.
Prerequisites
Before starting this wizard, ensure you have completed:
- Configure AI Providers wizard - At least one LLM provider must be configured
- Configure Safety Gateway wizard - Content safety controls must be set up first
AIPSO appears as its own dashboard section (not inside the main Getting Started group) and stays locked until both prerequisites are met. It is optional and can be deferred at any time.
The Escalation Router is not a prerequisite. AIPSO's human-in-the-loop approvals work without a dedicated escalation mailbox; see Delivery Modes.
Starting the Wizard
- Navigate to the Platform & Security Officer dashboard section
- Click Set Up Your Platform & Security Officer
The wizard has seven steps. Two of them - Monitored Mailbox and Tools - are optional and can be skipped and configured later from Settings.
Step 1: Welcome & Managers
Select which IT admins will manage AIPSO. Only users holding the platform-admin role are eligible.
- Choose one or more managers from the list of eligible platform admins
- Designate one manager as the primary manager (defaults to yourself, if eligible)
- Click Continue
At least one manager and a primary manager are required to proceed.
Step 2: Autonomy
Choose how much independent authority AIPSO has when it finds something to fix:
| Level | Behavior |
|---|---|
| Investigate Only | AIPSO can look into issues and report findings, but has no ability to make changes |
| Approve Every Change | Every change, regardless of risk, waits for a manager to approve it |
| Auto-Approve Low Risk (recommended) | Low-risk changes execute automatically; medium and high-risk changes wait for approval |
| Auto-Approve Low & Medium Risk | Only high-risk changes wait for manager approval |
| Full Autonomy | AIPSO acts independently across all risk levels |
Select a level and click Continue. You can revisit this setting later in Settings.
Step 3: Schedule & Channels
Configure when AIPSO runs and how it reaches your managers:
- Timezone - Authoritative for all schedule and quiet-hours calculations (required)
- Working hours and days - When AIPSO's activity is considered "business hours"
- Wake-up cadence - How often AIPSO checks the platform (hourly, every 4 hours, twice daily, or daily)
- Digest cadence - How often a summary digest is sent (daily, weekly, or never)
- Alert channels - Email (on by default), Teams, and/or Slack
- After-hours policy - Page managers only for critical findings, page for all findings, or queue everything until working hours resume
- Quiet hours - Optionally suppress non-critical alerts during a set window
A timezone selection is required before you can continue.
Step 4: Monitored Mailbox (optional)
Give AIPSO its own dedicated shared mailbox (for example, aipso@your-domain) so your managers can reach it by email. This is AIPSO's email inbox, not one of your managers' mailboxes.
- Pick an existing mailbox from your tenant's monitored mailboxes, or click Link or create a mailbox to link an existing Microsoft 365 mailbox or provision a brand-new shared mailbox through the shared mailbox modal.
- If the mailbox you pick is already assigned to another active agent, you must confirm the reassignment before continuing.
- When a mailbox is selected, its email subscription must be healthy; the wizard checks and, if needed, creates the subscription in this step.
- To skip, choose Clear selection (set up later). You can assign a mailbox later from the Settings page.
Once a mailbox is assigned, your managers can email AIPSO at that address. Mail from anyone who is not a manager is ignored. AIPSO currently reads inbound mail from its managers; conversational email replies arrive in a later release. See AIPSO Overview for more on the email channel.
Step 5: Tools (optional)
Grant AIPSO tools from your general tool catalog (for example, web search, HTTP, or SQL tools). These are selective grants: pick only the tools you want AIPSO to have.
- Nothing is preselected. Choose any catalog tools you want to grant now, or grant none and add them later in Settings.
- AIPSO's built-in capabilities are always available and are not listed here.
Passing through this step is required, but granting zero tools is perfectly valid.
Step 6: Interview (optional)
AIPSO can run a short guided interview to personalize its identity, tone, security posture, cost thresholds, and near-term objectives to your organization. The interview opens in a full-screen conversation.
- Click Begin the guided interview to start, or click Next to skip it.
- The interview is optional. If you skip it (or if the personalization experience is unavailable for your tenant), AIPSO is still fully set up with sensible defaults from the earlier steps.
If you run the interview, AIPSO returns you to the manage page when it finishes.
Step 7: Review & Activate
Review your selected managers, autonomy level, schedule, monitored mailbox, and granted tools, then click Activate.
The summary includes a Monitored Mailbox row (the mailbox address, or "Not configured - set up later in Settings") and a Tools row (the number of tools granted, or "No tools granted").
Activation is live: clicking Activate creates and starts your AIPSO agent, seeds its standing goals and first security review, and notifies your managers. You are then taken to the Platform & Security Officer manage page.
Related Topics
- AIPSO Overview - Introduction to the Platform & Security Officer
- Managing AIPSO - Day-to-day status, autonomy, managers, mailbox, tools, and lifecycle management