bcquality/community/knowledge/agents/get-default-access-controls-least-privilege.good.al
Stefano Demiliani 53e2cf2fa4
Add community guidance and review support for Business Central agents (#137)
* feat(community/agents): add AL agent quality guidance

- add 20 agent knowledge rules with good and bad AL samples
- clarify setup dialog shape, temporary persistence, permissions, profiles, instructions, capability registration, and interface wiring
- add the community-owned AL agents review skill
- make review fixture discovery layer-aware with custom, community, and Microsoft precedence
- document layer-aware evaluation behavior

* fix(community/agents): align setup and permission samples

- mark agent setup pages as non-extensible where required
- narrow the agent profile by hiding an unrelated sales-order field
- define a dedicated read-only permission set for the sales review agent
- assign AL-defined permission sets with system scope and the owning app ID
- clarify the permission scope guidance for default access controls

* Address agent review feedback
2026-09-02 16:06:25 +02:00

25 lines
951 B
AL

permissionset 50100 "SALES REVIEW AGENT"
{
Assignable = true;
Caption = 'Sales Review Agent';
Permissions =
tabledata "Sales Header" = R,
tabledata "Sales Line" = R;
}
codeunit 50100 "Sales Review Agent Factory"
{
procedure GetDefaultAccessControls(var TempAccessControlBuffer: Record "Access Control Buffer" temporary)
var
CurrentModuleInfo: ModuleInfo;
RoleIdTok: Label 'SALES REVIEW AGENT', Locked = true;
begin
NavApp.GetCurrentModuleInfo(CurrentModuleInfo);
Clear(TempAccessControlBuffer);
TempAccessControlBuffer."Company Name" := CopyStr(CompanyName(), 1, MaxStrLen(TempAccessControlBuffer."Company Name"));
TempAccessControlBuffer.Scope := TempAccessControlBuffer.Scope::System;
TempAccessControlBuffer."App ID" := CurrentModuleInfo.Id;
TempAccessControlBuffer."Role ID" := RoleIdTok;
TempAccessControlBuffer.Insert();
end;
}