Lead with a complete plugin quick start and add task-oriented usage, troubleshooting, customization, and contribution guides. Preserve the broader plugin framing, correct conflicting contract guidance, support Agents folder reviews, and align repository validation. Convert existing sample references to clickable links without changing knowledge rules. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
1.6 KiB
| bc-version | domain | keywords | technologies | countries | application-area | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
agents |
|
|
|
|
Default agent permission sets must exist in AL and stay least privilege
Description
IAgentFactory.GetDefaultAccessControls fills a temporary Access Control Buffer used when an instance is created. Permission sets that exist only as user-created sets in a sandbox are missing in the next environment. Granting D365 BUS FULL ACCESS or SUPER gives the agent a user-sized blast radius. Effective rights are still the intersection with the assigning user's permissions.
Best Practice
Insert only the permission sets the agent needs. For an AL permissionset object, use Scope::System and the ID of the app that defines it. Recreate permission sets that exist only as user-defined configuration in Business Central as AL objects first. Prefer a dedicated permission set over a full-user role.
See sample: get-default-access-controls-least-privilege.good.al.
Anti Pattern
Empty GetDefaultAccessControls, or inserting SUPER / D365 BUS FULL ACCESS because it made the demo work. Detection signal: Role ID on the default buffer that is a full-user role, or a set that is not in the app.
See sample: get-default-access-controls-least-privilege.bad.al.
See also
agent-permissions-intersect-with-assigner.md explains the platform limits that still apply after default access controls are assigned.