bcquality/community/knowledge/agents/skip-incoming-review-only-for-trusted-input.md
Stefano Demiliani 53e2cf2fa4
Add community guidance and review support for Business Central agents (#137)
* feat(community/agents): add AL agent quality guidance

- add 20 agent knowledge rules with good and bad AL samples
- clarify setup dialog shape, temporary persistence, permissions, profiles, instructions, capability registration, and interface wiring
- add the community-owned AL agents review skill
- make review fixture discovery layer-aware with custom, community, and Microsoft precedence
- document layer-aware evaluation behavior

* fix(community/agents): align setup and permission samples

- mark agent setup pages as non-extensible where required
- narrow the agent profile by hiding an unrelated sales-order field
- define a dedicated read-only permission set for the sales review agent
- assign AL-defined permission sets with system scope and the owning app ID
- clarify the permission scope guidance for default access controls

* Address agent review feedback
2026-09-02 16:06:25 +02:00

1.2 KiB

bc-version domain keywords technologies countries application-area
28..
agents
setrequiresreview
agent-task-message-builder
approval
trusted-input
skip-review
al
w1
all

Skip incoming message review only after the caller validated the payload

Description

Incoming task messages default to requiring user approval before the agent runs. From 28.1, Agent Task Message Builder.SetRequiresReview(false) starts the agent immediately. That is safe only for inputs you already validated in AL (your page action, your posting subscriber). External email or partner payloads are not trusted by default. Analysis Warnings still force a review.

Best Practice

Leave the default review-on for anything that originated outside your extension. Call SetRequiresReview(false) only on messages you constructed from already-authorized BC data.

See sample: skip-incoming-review-only-for-trusted-input.good.al.

Anti Pattern

SetRequiresReview(false) on simulated email, incoming webhooks, or user-free text. Detection signal: SetRequiresReview(false) next to external content with no prior validation.

See sample: skip-incoming-review-only-for-trusted-input.bad.al.