› Protime Labs / Signals / Recap
Weekly signals · Endpoint DLP & agentic software delivery
Purview AI Investigation and the Agentic Delivery Shift
Monday, June 8, 2026
Purview Endpoint DLP gets an AI-powered investigation skill — and your June preview window is open
If you're running a Copilot governance engagement right now, Microsoft 365 Roadmap item 562016 is the most operationally significant update this week. The Purview Endpoint Data Loss Prevention team has added an AI agent skill that detects and alerts on unhealthy policy sync and device configuration states. Preview lands this month; GA is July CY2026.
Here's the concrete problem this addresses: in every large Endpoint DLP rollout we've done, the gap between "policy authored in Purview" and "policy actually enforced on the endpoint" is the silent failure mode. A device that missed a sync cycle, a stale configuration after an OS update, a conditional access policy that silently excluded a device group — none of these surface cleanly in the current admin center. Admins are left correlating event logs and DLP reports manually, usually after an incident.
The new AI investigation skill closes that loop automatically. It's not a dashboard widget — it's an agent skill that reasons over device health telemetry and policy sync state, then fires an alert when the two diverge. That distinction matters for how you architect your response playbooks.
What this means for your posture. If you have a Purview Endpoint DLP deployment in flight, schedule time in June to get into preview. The GA date is tight enough that waiting for July means you're doing your steady-state tuning without preview learnings. Focus the preview evaluation on: does the alert signal map cleanly to your existing SIEM ingestion path, and does the AI-generated investigation summary reduce analyst triage time enough to retire the manual correlation runbook? Those two answers will define your July cutover scope.
Endava's delivery model is the architecture question your engineering leaders will ask you next quarter
OpenAI published a case study on Endava this week that's worth reading past the headline. Endava — a 12,000-person software engineering and delivery firm — has restructured its delivery model around AI agents, ChatGPT Enterprise, and Codex. The surface story is productivity. The structural story is more significant: they've reoriented team composition and workflow sequencing around what agents can own autonomously versus what requires human judgment in the loop.
This is the conversation we're starting to have with engineering leaders at mid-to-large organizations who are asking whether Claude Code and Codex are tools for individual developers or components of a redesigned delivery pipeline. The answer Endava's model gives is: both, but the leverage is in the pipeline redesign, not the individual productivity gain.
Why it matters for a Protime engagement. We're not deploying AI coding tools into existing SDLC processes and calling it done. The Endava model — and the pattern we're building toward with Claude Code deployments — requires a genuine re-evaluation of where human review checkpoints sit, how agent-generated code is tested and promoted, and what your code ownership model looks like when an agent is the primary author of a feature branch. Those are governance questions, not just tooling questions.
What to do. If your engineering org is past the "individual developer pilot" phase and moving toward team-level adoption of Codex or Claude Code, use the Endava case as a structured conversation starter with your engineering directors. Specifically: what does your sprint workflow look like when agent-generated pull requests are the norm rather than the exception? That question surfaces the governance gaps before they become incidents.
The thread connecting both signals
These two signals are not unrelated. The Purview AI investigation skill is itself an agentic capability embedded in a governance workflow. The Endava delivery model is an agentic capability embedded in a delivery workflow. In both cases, the deployment question is identical: what does the agent own, what does it escalate, and how do you verify it's operating within the boundaries you set?
That's the architecture pattern we're working through on every engagement right now — not "should we use agents" but "where do we draw the human-in-the-loop boundary, and how do we instrument it." The Purview skill gives you a Microsoft-native example of a well-scoped agent: a narrow, observable action (policy sync health check) with a defined escalation path (alert). The Endava model is the more complex end of the spectrum, where agents are composing and committing code across a full delivery pipeline.
If you're a CIO trying to scope your next 90 days, the June Purview preview is a concrete, low-risk place to get hands-on with what a production AI agent skill looks and behaves like — before you're asked to approve something with a much larger blast radius.
Watch next week for any Microsoft Build follow-on guidance on Purview + Security Copilot integration depth, which would materially change the alert-to-response automation story for the Endpoint DLP skill covered above.