Quality skills and knowledge for Business Central development. The shared bar for humans and agents alike.
Find a file
Jeremy Vyska 02e7ab15b0
Some checks are pending
Validate knowledge index / validate-index (push) Waiting to run
Validate AL review fixtures / validate-review-fixtures (push) Waiting to run
Validate skill index and report schemas / validate-contract (push) Waiting to run
Validate frontmatter and structure / validate (push) Waiting to run
Add retention policy knowledge to the privacy domain (#177)
* Add retention policy knowledge to the privacy domain

Two articles covering retention policies for extension-owned tables,
the gap that lets high-volume log tables grow unbounded:

- register-owned-log-tables-for-retention-policies: an extension's own
  log tables must be added to the allowed-tables list from install AND
  upgrade code, guarded by IsAllowedTable plus an upgrade tag, with a
  mandatory minimum retention where audit needs one.
- ship-a-default-retention-policy-setup: registration only makes a table
  selectable; nothing is deleted until a Retention Policy Setup record
  exists, so ship one (disabled by default) as the platform's own
  Retention Policy Installer does.

Each ships good/bad AL samples. Claims verified against the BC admin
docs and the Retention Policy module in microsoft/BCApps.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011gvTjm746MtJEVWeRTbG46

* Address review feedback on retention policy knowledge

- Scope both articles to bc-version [17..] (retention policies shipped in v17).
- Allowed-tables sample: add OnRefreshAllowedTables subscriber with a
  ForceUpdate path; the upgrade tag now gates one-time setup only.
- Default-policy sample: use Retention Policy Setup.FindOrCreateRetentionPeriod
  instead of a hand-rolled lookup-then-insert that can collide on code.
- Anti-pattern now keys on append-only tables rather than table names.
- al-privacy-review: add retention-policy tokens and deterministic routing
  for both articles, with a bounded per-table text search for delete and
  registration paths.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Address second review round on retention policy knowledge

- Scope both articles to bc-version [22..]: FindOrCreateRetentionPeriod
  first appears in the 21.1 System Application and OnRefreshAllowedTables
  in 22.
- Reframe the default-setup article as optional guidance; registration
  without a setup is valid. The anti-pattern and review routing now cover
  only false claims that registration alone cleans up data.
- Make all four samples self-contained: declare Contoso Activity Log in
  each, add the Retention Policy Setup permission, and guard the default
  setup on IsAllowedTable.
- Let evaluation overrides list additionalArticles and register both
  retention pairs as extra privacy cases (38 cases, existing IDs unchanged).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Revert evaluation harness change for multiple articles per domain

The harness intentionally evaluates one paired article per domain. Keep it
as designed; how the retention pairs join privacy evaluation is left to the
maintainers.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Register retention policy pairs in the privacy evaluation override

Use main's articles override so both retention article pairs get positive
and clean cases alongside no-pii-in-telemetry-message-string.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Jeremy Vyska <jeremy@sparebrained.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-10-05 15:02:04 +02:00
.claude-plugin Simplify standalone AL code review skill (#150) 2026-09-03 10:25:44 +02:00
.github Strengthen review contracts and add AL reliability guidance (#196) 2026-09-29 13:03:39 +02:00
community Add AL-focused AppSource validation guidance (#142) 2026-09-14 12:42:45 +02:00
custom Improve partner onboarding and documentation navigation (#174) 2026-09-09 17:31:03 +02:00
docs Validate composed reviews against the expected leaf worklist (#204) 2026-10-02 10:27:27 +02:00
evaluation Add retention policy knowledge to the privacy domain (#177) 2026-10-05 15:02:04 +02:00
microsoft Add retention policy knowledge to the privacy domain (#177) 2026-10-05 15:02:04 +02:00
schemas Harden findings-report producer constraints (#218) 2026-10-05 15:01:04 +02:00
skills Harden findings-report producer constraints (#218) 2026-10-05 15:01:04 +02:00
tools Harden findings-report producer constraints (#218) 2026-10-05 15:01:04 +02:00
.gitignore Own the knowledge-index generator + index-aware review skills (#25) 2026-06-04 15:02:12 +02:00
CODEOWNERS Add JesperSchulz to every CODEOWNERS rule (#219) 2026-10-05 14:56:10 +02:00
LICENSE Add initial project structure with .gitignore, LICENSE, README, and CODEOWNERS 2026-04-17 05:56:10 +02:00
plugin.json Simplify standalone AL code review skill (#150) 2026-09-03 10:25:44 +02:00
README.md Add SCM functional knowledge domain (#192) 2026-09-21 10:16:44 +02:00
SECURITY.md Microsoft mandatory file 2026-04-17 03:58:13 +00:00

BC Quality - Don’t teach one agent. Teach the ecosystem. 🤝

Quality skills and knowledge that help AI tools make better Business Central development decisions: catch BC-specific defects, avoid misleading advice, and explain findings with references you can read.

BCQuality contains knowledge and reusable skills, not agents or a Business Central extension. Your host supplies the agent. You can install the content as a plugin, use it from another integration, or browse the knowledge directly.

Quick start

The walkthrough below uses GitHub Copilot CLI in a terminal, not the Copilot Chat panel in VS Code. First install Copilot CLI and sign in. Your account and organization policy must allow its use. You do not need to clone BCQuality, build a runner, or deploy an app to Business Central for this source-review example.

Standalone plugin installation

Run these commands in your terminal:

copilot plugin install microsoft/BCQuality
copilot plugin list

The list should include bcquality. The plugin currently exposes the al-code-review skill. Installation and skill discovery are the general pattern; reviewing an app is one example of using it.

Example: Review a complete app folder

Start a new CLI session in your own app folder, replacing the example path:

cd "C:\Repos\MyBusinessCentralApp"
copilot

Approve access only to a project you trust, then ask:

Use the installed al-code-review skill to review the complete Business Central app in this folder without changing my source files. Return the complete BCQuality findings report.

The folder should contain app.json and your AL source; it does not need to be a Git repository. On macOS or Linux, use your app's local path instead.

Expect a report for each selected review, with findings, source locations, severity, confidence, and references to the relevant guidance. Some hosts show the structured JSON directly. completed with no findings means nothing was flagged in that review's scope; partial or failed is not a clean result. See reading your results.

PowerShell 7 (pwsh) is recommended for fast knowledge discovery. If it is unavailable, the review can still discover knowledge by reading the folders.

Documentation

I want to... Start here
Choose direct reading, a supplied skill, or my own agent Ways to use BCQuality
Review a file, changes, a branch, or a particular concern Using BCQuality
Resolve setup problems, incomplete reviews, or incorrect findings Troubleshooting and support
Browse the available guidance Knowledge by domain
Configure the plugin or use my organization's rules Customizing BCQuality
Contribute knowledge or improve a rule Your first contribution
Connect a host, agent, or CI integration Minimal integration example

All documentation and technical references.

Scope

Today's curated content covers technical AL code review and a focused Supply Chain Management (SCM) functional domain. It augments the agent's judgment; it is not an exhaustive BC manual or a substitute for compilation, analyzers, tests, or human review. See coverage and limits for the available domains and the difference between a folder review and a comparison. Mechanical issues already enforced by the AL compiler or standard analyzers are intentionally left to those deterministic tools rather than duplicated here.

The SCM domain covers selected inventory, costing, reservation, tracking, and warehouse/posting workflows, not exhaustive supply chain validation. Broader functional coverage such as Finance, Manufacturing, Jobs, and Service, and technologies such as PowerShell, pipelines, and Power Platform, remain valid future scope, not current coverage claims.

What's in this repo

Knowledge articles cover one concern each. Skills tell an agent how to find and apply the relevant knowledge. Both live in three layers:

Layer Purpose
Microsoft Microsoft-endorsed skills and their knowledge.
Community Community-owned skills and their knowledge.
Custom Organization-specific additions and overrides in your own fork.

All three are enabled by default; Custom is empty upstream. You do not need to configure layers to get started.

Versioning

Update the installed plugin from your terminal, then start a new session:

copilot plugin update bcquality

Plugin versions and content-release tags are different. For reproducible runs and organization forks, see updates and versions.

What belongs here

Knowledge belongs here when it prevents a BC-specific mistake an otherwise capable agent would make, including false-positive findings. BC facts belong in knowledge articles, not skill instructions. See the admission test and examples.

Contributing

Partners are welcome to contribute to the layer that owns the domain, regardless of affiliation. Start with the contribution guide. To report a problem without authoring a rule, see support.

License

MIT