bcquality/community/knowledge/agents/set-instructions-as-secrettext.md
Stefano Demiliani 53e2cf2fa4
Add community guidance and review support for Business Central agents (#137)
* feat(community/agents): add AL agent quality guidance

- add 20 agent knowledge rules with good and bad AL samples
- clarify setup dialog shape, temporary persistence, permissions, profiles, instructions, capability registration, and interface wiring
- add the community-owned AL agents review skill
- make review fixture discovery layer-aware with custom, community, and Microsoft precedence
- document layer-aware evaluation behavior

* fix(community/agents): align setup and permission samples

- mark agent setup pages as non-extensible where required
- narrow the agent profile by hiding an unrelated sales-order field
- define a dedicated read-only permission set for the sales review agent
- assign AL-defined permission sets with system scope and the owning app ID
- clarify the permission scope guidance for default access controls

* Address agent review feedback
2026-09-02 16:06:25 +02:00

1.2 KiB

bc-version domain keywords technologies countries application-area
27..
agents
setinstructions
secrettext
instructions
per-instance
resource
al
w1
all

Set agent instructions as SecretText on the instance

Description

Instructions are instance data, not an enum caption. Agent.SetInstructions takes SecretText so the payload is not logged or copied as ordinary text. A Label or plaintext Text on the agent type is the wrong store: it leaks into telemetry-friendly strings and cannot vary per instance or company.

Best Practice

Load instruction text from a resource or builder into a SecretText variable and call Agent.SetInstructions(AgentUserSecurityId, Instructions) after Create. Keep one instruction document per instance.

See sample: set-instructions-as-secrettext.good.al.

Anti Pattern

Passing a Label or Text to SetInstructions, storing instructions in a setup Text field without wrapping as SecretText, or putting the prompt only in a code comment. Detection signal: SetInstructions with a non-SecretText argument, or no SetInstructions after Create.

See sample: set-instructions-as-secrettext.bad.al.