Distributing agents to desk-less frontline (Kwik Trip caveat, 7/13 sync)
The constraint: ~70% of staff are desk-less — no email, no Microsoft ID. They have phones. Okta is the corporate IdP. (Consistent with our jobs-corpus read: 93.8% of 1,790 postings store-facing.)
Path A — M365 Copilot proper: the wrong tool, know why
M365 Copilot ($30/user/mo) requires an Entra ID + eligible M365 base license per user. The frontline pattern exists (F-series SKUs ~$2.25-8/user, Entra federated to Okta, QR+PIN frontline sign-in, Teams mobile) — but at Kwik Trip scale (~24k desk-less if 70% of ~35k), that's roughly $8-9M/yr in licensing before anyone types a prompt. Nobody buys per-seat Copilot for frontline. Say this in the room: it kills the "just buy Copilot" reflex early.
Path B — the RIGHT Microsoft answer: Copilot Studio agents on non-Teams channels
- Copilot Studio agents publish to web / mobile app / custom channels (Direct Line), not just Teams.
- User auth = "Authenticate manually" with any OAuth2 provider — Okta explicitly supported; Microsoft ships an official Okta SSO sample (token from Okta → Direct Line). No Entra identity needed for end users.
- Licensing: end users of a published agent need NO license. Billing is capacity-based — Copilot Credits via pay-as-you-go (Azure sub) or prepaid capacity packs (per May 2026 licensing guide; since ~April 2026 capacity packs work without an Azure subscription).
- Shape: PWA or lightweight web app → Okta login (passwordless: Okta Verify / SMS OTP) → Copilot Studio agent. QR poster in the back office is the whole distribution mechanism.
- Budget flag: a frontline agent at 10k users can consume 1-3M messages/month — model consumption before quoting; capacity is the real cost line, not seats.
Path C — platform-independent options (ranked by fit)
- Custom agent surface (PWA), model-agnostic backend — Okta OIDC direct, backend = Bedrock/Claude/whatever wins the eval. Same distribution mechanics as Path B but the orchestration layer is decoupled from any one vendor (the Nadella "Choice" principle from this morning's article — own the surface, swap models). This is the CAF-shaped answer.
- Embed in the existing frontline app — stores already live in SOME workforce app (scheduling/comms: UKG/Workday/WorkJam class). An agent tab inside the app they open every shift beats any new surface on adoption. Discovery Q: what's their frontline app?
- Shared in-store device / kiosk — back-office terminal or shared tablet, badge/QR sign-in, agent on it. No personal-phone dependency; sidesteps BYOD entirely.
- SMS / voice line — zero install, works on any phone; weak auth + no rich UI; good for narrow high-volume use cases (policy Q&A, shift info hotline).
Two consultant-grade caveats
- Identity precheck (Discovery Q #1): "Okta is the IdP" ≠ "desk-less workers are IN Okta." If frontline only exists in the HR system (Workday/UKG), then HR→Okta provisioning is step 0 for EVERY path above. Ask whether a store associate can log into anything corporate today.
- Wage/hour exposure: pushing work agents to hourly employees' PERSONAL phones creates off-the-clock work risk (FLSA). Retail norm: gate access to on-shift/on-network, or use in-store shared devices. Legal/HR belongs in this design conversation — raising it early reads as senior.
CAF tie-in
Distribution channel is a port. The archetype register should tag which use cases are desk-less-reachable (kiosk/PWA/SMS-servable) vs desk-bound — it changes the value math on the 93.8% store-facing workforce.