bcquality/community/knowledge/agents/cross-app-agent-calls-need-your-public-api.md
Stefano Demiliani 53e2cf2fa4
Add community guidance and review support for Business Central agents (#137)
* feat(community/agents): add AL agent quality guidance

- add 20 agent knowledge rules with good and bad AL samples
- clarify setup dialog shape, temporary persistence, permissions, profiles, instructions, capability registration, and interface wiring
- add the community-owned AL agents review skill
- make review fixture discovery layer-aware with custom, community, and Microsoft precedence
- document layer-aware evaluation behavior

* fix(community/agents): align setup and permission samples

- mark agent setup pages as non-extensible where required
- narrow the agent profile by hiding an unrelated sales-order field
- define a dedicated read-only permission set for the sales review agent
- assign AL-defined permission sets with system scope and the owning app ID
- clarify the permission scope guidance for default access controls

* Address agent review feedback
2026-09-02 16:06:25 +02:00

1.2 KiB

bc-version domain keywords technologies countries application-area
27..
agents
cross-app
public-api
agent-create
isolation
access-public
al
w1
all

Other apps cannot call the toolkit APIs on your agent; publish your own API

Description

For isolation, Agent, Agent Task Builder, and related toolkit codeunits error when the target instance belongs to another app. There is no supported way to pass another extension's metadata provider into SetInstructions or Create. Partners who need to enqueue work must call a public API you own.

Best Practice

Expose a public codeunit in the agent app (Access = Public) whose procedures take User Security ID and forward to Agent / Agent Task Builder. Document that surface as the integration contract. Keep toolkit calls inside that app.

See sample: cross-app-agent-calls-need-your-public-api.good.al.

Anti Pattern

From app B, calling Agent.SetDisplayName or Agent.Create with app A's metadata provider. Detection signal: toolkit agent APIs used with an Agent Metadata Provider value not declared in the same app.

See sample: cross-app-agent-calls-need-your-public-api.bad.al.