feat(community/agents): add AL agent quality guidance

- add 20 agent knowledge rules with good and bad AL samples
- clarify setup dialog shape, temporary persistence, permissions, profiles, instructions, capability registration, and interface wiring
- add the community-owned AL agents review skill
- make review fixture discovery layer-aware with custom, community, and Microsoft precedence
- document layer-aware evaluation behavior
This commit is contained in:
Stefano Demiliani 2026-08-23 22:10:10 +02:00
parent 841b4e7cab
commit 2d0913568e
63 changed files with 1489 additions and 34 deletions

View file

@ -0,0 +1,30 @@
---
bc-version: [27..]
domain: agents
keywords: [getdefaultaccesscontrols, access-control-buffer, permissionset, least-privilege, iagentfactory]
technologies: [al]
countries: [w1]
application-area: [all]
---
# Default agent permission sets must exist in AL and stay least privilege
## Description
`IAgentFactory.GetDefaultAccessControls` fills a temporary `Access Control Buffer` used when an instance is created. Permission sets that exist only as user-created sets in a sandbox are missing in the next environment. Granting `D365 BUS FULL ACCESS` or SUPER gives the agent a user-sized blast radius. Effective rights are still the intersection with the assigning user's permissions.
## Best Practice
Insert only the permission sets the agent needs, with the correct Scope and App ID. Recreate any BC-only sets as AL permissionset objects first. Prefer a dedicated permission set over a full-user role.
See sample: `get-default-access-controls-least-privilege.good.al`.
## Anti Pattern
Empty `GetDefaultAccessControls`, or inserting `SUPER` / `D365 BUS FULL ACCESS` because it made the demo work. Detection signal: Role ID on the default buffer that is a full-user role, or a set that is not in the app.
See sample: `get-default-access-controls-least-privilege.bad.al`.
## See also
`agent-permissions-intersect-with-assigner.md` explains the platform limits that still apply after default access controls are assigned.