Skip to content

Add governed chat agent discovery and recommendation#1039

Merged
paullizer merged 1 commit into
microsoft:feature/orchestrationfrom
paullizer:feature/orchestration-phase-08b-governed-agent-discovery
Jul 15, 2026
Merged

Add governed chat agent discovery and recommendation#1039
paullizer merged 1 commit into
microsoft:feature/orchestrationfrom
paullizer:feature/orchestration-phase-08b-governed-agent-discovery

Conversation

@paullizer

Copy link
Copy Markdown
Contributor

Summary

  • extend the Phase 8A inventory, proposal, decision, inline card, and durable resume contracts to governed unselected personal, global, and group agents
  • add explicit discoverable_by_orchestrator policy and bounded safe descriptors, defaulting existing and new agents to undiscoverable
  • reauthorize the exact source turn and rebuild the current governed catalog at decision, resume, and invocation before resolving an opaque scope-namespaced agent reference
  • execute approved agents once as required discovery_approved evidence sources, disable inherited tools, and hand the terminal ledger to the central response finalizer
  • add shared agent-policy authoring controls, safe inert card rendering, documentation, release notes, and version 0.250.067

Security And Governance

  • catalog construction occurs only after current personal ownership, global feature/item policy, group membership/status, enabled/hidden, local-runtime, action-free, creation-identity, and descriptor checks
  • proposal and browser surfaces contain only an opaque reference, display label, scope class, capability/evidence tags, read-only/external state, risk, sensitivity, latency, and cost
  • instructions, secrets, endpoints, connector settings, canonical IDs, group details, attached actions/arguments, hidden tools, assigned-knowledge details, inaccessible entries, and unsafe counts stay outside planner/proposal/browser metadata
  • descriptor or identity changes, deletion, disablement, policy loss, action attachment, runtime changes, or membership revocation invalidate approval
  • discovered invocations suppress prompt/response previews and raw plugin citations, clear reusable agent state, disable function choice at agent/execution/service levels, and restore normal selected-agent behavior afterward

Validation

  • orchestration, durable choice, planner/runtime, evidence, synthesis, and no-tools contracts: 105 passed
  • agent schema/catalog/scope/Foundry compatibility: 44 passed, 2 unrelated stale source-text assertions deselected
  • authenticated capability/agent decision and resume routes: 20 passed
  • route Blueprint and unauthenticated policy contracts: 12 passed
  • desktop/mobile choice-card Playwright: 5 passed
  • authenticated desktop/mobile agent modal validation completed against the local app, including default-off, local-only, action-free, edit reconstruction, ARIA, keyboard, and overflow checks
  • Python compilation, JavaScript syntax, JSON schema parsing, VS Code diagnostics, whitespace, full-file Broken Access Control (12 files), and XSS (16 files) checks passed

Deliberate Phase Boundaries

  • no automatic discovered-agent invocation; explicit user choice remains required
  • no second-agent recommendation when an agent is already selected
  • Foundry-backed and action-attached agents remain explicitly selectable but undiscoverable in Phase 8B
  • generalized multi-agent orchestration, consequential/write approval, and durable in-flight execution remain out of scope

Refs #1021

@paullizer
paullizer merged commit cbf44d5 into microsoft:feature/orchestration Jul 15, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant