bcquality/custom/knowledge/mcp/agent-must-not-write-business-process-status.md
Michael Dieringer dd5637b1db Custom-laget bestaar nu begge CI-checks: 72 validator-fejl -> 0
Normalisering af alle 39 custom knowledge-filer til READ-kontraktens
skema (validate_frontmatter.py + Test-KnowledgeIndex.ps1 begge groenne):

- R01/R02: 28 filer manglede frontmatter eller brugte aeldre skemaer
  (title/category/severity/rule-id m.fl.) - alle har nu praecis de 6
  kraevede noegler; keywords haandskrevet pr. fil da de driver
  worklist-selektionen i INDEX/knowledge-index
- R09: manglende Description-sektion - regel-agtige foersteoverskrifter
  (Core Rule/Rule/Regel/Core Principle) omdoebt, eller sektion indsat
  efter titlen hvor intro-tekst fandtes
- R10: fenced code blocks konverteret til 4-space indrykkede blokke
  i alle filer (indhold uaendret)
- R11: 4 filer over 100 linjer fortaettet redaktionelt uden semantisk
  tab (ai-eval-scores 143->100, git-lifecycle 121->97,
  permission-sets 113->99, test-feature-scenario-tags 105->91)
- R05: AL0197->al0197, add_repo->add-repo; keyword-lister trimmet
  til maks 10

Ingen regler er fjernet eller aendret i betydning - kun form.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-01 23:47:31 +02:00

1.8 KiB

bc-version domain keywords technologies countries application-area
all
mcp
mcp
agent
business-process
status
write-scope
al
w1
all

CURABIS MCP: Agents Must Not Write Business Process Status Fields

Description

MCP agents must only write developer-managed tracking fields — never fields that drive business process workflows such as invoicing, approval, or time registration. Writing a business status field from an agent can block downstream operations for users working in Business Central.

The Distinction

Field type Examples Agent may write
Developer tracking gitHubDevStatus, gitHubBranch Yes
Business process status Task Status (Accepted, In progress, Done) Never

Developer tracking fields are independent of BC workflow. Business process status fields control what users can do — for example, a task marked as ready for invoicing cannot receive new time entries.

Requirements

  • API pages exposed to MCP agents must mark business status fields as Editable = false
  • Agent instructions (.agent.md files) must explicitly list which fields the agent may write
  • Any field that affects time registration, posting, approval, or invoicing is a business process field and must be read-only for agents
  • Developer-managed fields (GitHub dev status, branch, comments) are the only writable surface

Example Agent Instruction

Write only gitHubDevStatus and gitHubBranch on tasks.
Never write Status — it controls the invoicing workflow.

Verification

For each API page with write access, verify that fields controlling BC workflow transitions carry Editable = false. Review the agent instruction file to confirm it names the allowed writable fields explicitly and prohibits status fields.