1. Support case assistant

Support question enters a Foundry agent; it retrieves policy and authorized case context before a human reviews the draft
Grounded answer first; human approval before an external reply or account change.

Business need: An agent should draft an answer about a delayed order using the current case and the approved returns policy, without exposing the full CRM.

  1. Connect an approved knowledge source and require citations for policy claims.
  2. Expose a read-only get_case_context tool that checks the caller's case-level authorization on the server.
  3. Ask the agent for a draft with evidence; route missing evidence or low confidence to a person.
  4. Have a support representative review the draft before sending. Keep write actions disabled unless separately authorized and approved.

Illustrative tool exchange, not a Microsoft Foundry SDK payload:

{
  "tool": "get_case_context",
  "input": { "caseId": "CASE-1042" },
  "output": { "status": "open", "issue": "delivery delayed" }
}

Enforce authorization and redaction in the tool implementation, not just in agent instructions. Test with a case the caller is not allowed to see, a stale policy, and a question that has no matching source.

2. Invoice exception triage

Business need: Accounts payable receives invoices with mismatched purchase orders. A document-processing step extracts invoice fields; an agent can compare them with an approved purchase-order lookup tool and explain the mismatch.

  1. Extract the supplier, PO number, line totals, and confidence from each document; validate mandatory fields.
  2. Look up the purchase order through a scoped, read-only enterprise API.
  3. Route low-confidence extraction, missing orders, or price differences to a reviewer with source-page references.
  4. Record the decision and audit trail. Do not auto-approve a payment from a model-generated conclusion.

Measure extraction accuracy and the percentage of exceptions correctly routed before automating further steps.

3. Integration incident triage

Business need: An integration alert fires when order events stop arriving. An agent can gather recent dependency errors and deployment changes through read-only tools, then propose likely causes for an on-call engineer.

  1. Trigger the workflow from a monitored alert with a trace or correlation ID.
  2. Fetch a bounded, redacted window of logs and the latest approved runbook.
  3. Summarize evidence, separate observations from hypotheses, and cite the log or runbook source.
  4. Require an on-call engineer to approve any replay, rollback, or production change.

Evaluate on historical incidents: did the summary identify the failed dependency, avoid invented causes, and escalate when evidence was insufficient?

Further reading

Microsoft Learn covers grounded knowledge retrieval, custom agent tools, and human-in-the-loop workflows. Start with one read-only tool, test unauthorized and missing-data paths, then expand only after evaluation.