bcquality/community/knowledge/agents/show-can-create-agent-does-not-block-code-create.md
Stefano Demiliani 53e2cf2fa4
Add community guidance and review support for Business Central agents (#137)
* feat(community/agents): add AL agent quality guidance

- add 20 agent knowledge rules with good and bad AL samples
- clarify setup dialog shape, temporary persistence, permissions, profiles, instructions, capability registration, and interface wiring
- add the community-owned AL agents review skill
- make review fixture discovery layer-aware with custom, community, and Microsoft precedence
- document layer-aware evaluation behavior

* fix(community/agents): align setup and permission samples

- mark agent setup pages as non-extensible where required
- narrow the agent profile by hiding an unrelated sales-order field
- define a dedicated read-only permission set for the sales review agent
- assign AL-defined permission sets with system scope and the owning app ID
- clarify the permission scope guidance for default access controls

* Address agent review feedback
2026-09-02 16:06:25 +02:00

1.3 KiB

bc-version domain keywords technologies countries application-area
28..
agents
showcancreateagent
agent-discovery
agent-create
administrator
agent-configuration-rights
al
w1
all

ShowCanCreateAgent only hides UI create, not programmatic create

Description

IAgentFactory.ShowCanCreateAgent controls whether the type appears in the in-client create UI. Returning false does not stop Agent.Create from AL. From 28.1, non-admins can discover extension agents unless this method (and agent configuration rights) restrict them. Models treat a false return as a hard create lock.

Best Practice

Use ShowCanCreateAgent to decide discovery. If only agent administrators should see the type, return Agent System Permissions.CurrentUserHasCanManageAllAgentsPermission. Enforce extra policy inside your own create API. Never assume UI hiding blocks code.

See sample: show-can-create-agent-does-not-block-code-create.good.al.

Anti Pattern

Returning exit(false) from ShowCanCreateAgent and then documenting that instances cannot be created, while page actions or other apps still call Agent.Create. Detection signal: ShowCanCreateAgent always false with no matching guard on programmatic create.

See sample: show-can-create-agent-does-not-block-code-create.bad.al.