bcquality/community/knowledge/agents/agent-permissions-intersect-with-assigner.md
Stefano Demiliani 53e2cf2fa4
Add community guidance and review support for Business Central agents (#137)
* feat(community/agents): add AL agent quality guidance

- add 20 agent knowledge rules with good and bad AL samples
- clarify setup dialog shape, temporary persistence, permissions, profiles, instructions, capability registration, and interface wiring
- add the community-owned AL agents review skill
- make review fixture discovery layer-aware with custom, community, and Microsoft precedence
- document layer-aware evaluation behavior

* fix(community/agents): align setup and permission samples

- mark agent setup pages as non-extensible where required
- narrow the agent profile by hiding an unrelated sales-order field
- define a dedicated read-only permission set for the sales review agent
- assign AL-defined permission sets with system scope and the owning app ID
- clarify the permission scope guidance for default access controls

* Address agent review feedback
2026-09-02 16:06:25 +02:00

1.4 KiB

bc-version domain keywords technologies countries application-area
27..
agents
permissions
assigner
intersection
user-card
least-privilege
al
w1
all

Agent permissions intersect the assigner's; agents cannot configure users

Description

An agent is a user, but it cannot configure users or other agents, and it cannot open sensitive pages such as user cards or permission-set assignment. Effective rights are the intersection of the assigning user's permissions and the agent's permission sets. Granting the agent a wide set does not bypass the assigner's limits, and a wide assigner still cannot give the agent user-admin powers the platform forbids.

Best Practice

Document that intersection. Give the agent only the table and page rights its tasks need. Do not add user-setup or permission-assignment pages to the agent profile or permission sets; those operations will fail by design.

See sample: agent-permissions-intersect-with-assigner.good.al.

Anti Pattern

Permission sets or profiles that include User card, Permission Set Assignment, or agent-admin pages, or comments that the agent runs as SUPER regardless of who assigned it. Detection signal: default access controls or profile including user-administration objects.

See sample: agent-permissions-intersect-with-assigner.bad.al.

See also

get-default-access-controls-least-privilege.md covers the permission sets assigned when an agent instance is created.