bcquality/community/knowledge/agents/get-default-access-controls-least-privilege.md
Jesper Schulz-Wedde b6da405376 Improve partner onboarding and documentation navigation
Lead with a complete plugin quick start and add task-oriented usage, troubleshooting, customization, and contribution guides. Preserve the broader plugin framing, correct conflicting contract guidance, support Agents folder reviews, and align repository validation. Convert existing sample references to clickable links without changing knowledge rules.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-09 17:25:29 +02:00

1.6 KiB

bc-version domain keywords technologies countries application-area
27..
agents
getdefaultaccesscontrols
access-control-buffer
permissionset
least-privilege
iagentfactory
al
w1
all

Default agent permission sets must exist in AL and stay least privilege

Description

IAgentFactory.GetDefaultAccessControls fills a temporary Access Control Buffer used when an instance is created. Permission sets that exist only as user-created sets in a sandbox are missing in the next environment. Granting D365 BUS FULL ACCESS or SUPER gives the agent a user-sized blast radius. Effective rights are still the intersection with the assigning user's permissions.

Best Practice

Insert only the permission sets the agent needs. For an AL permissionset object, use Scope::System and the ID of the app that defines it. Recreate permission sets that exist only as user-defined configuration in Business Central as AL objects first. Prefer a dedicated permission set over a full-user role.

See sample: get-default-access-controls-least-privilege.good.al.

Anti Pattern

Empty GetDefaultAccessControls, or inserting SUPER / D365 BUS FULL ACCESS because it made the demo work. Detection signal: Role ID on the default buffer that is a full-user role, or a set that is not in the app.

See sample: get-default-access-controls-least-privilege.bad.al.

See also

agent-permissions-intersect-with-assigner.md explains the platform limits that still apply after default access controls are assigned.