1. Support case assistant
Business need: An agent should draft an answer about a delayed order using the current case and the approved returns policy, without exposing the full CRM.
- Connect an approved knowledge source and require citations for policy claims.
- Expose a read-only
get_case_contexttool that checks the caller's case-level authorization on the server. - Ask the agent for a draft with evidence; route missing evidence or low confidence to a person.
- Have a support representative review the draft before sending. Keep write actions disabled unless separately authorized and approved.
Illustrative tool exchange, not a Microsoft Foundry SDK payload:
{
"tool": "get_case_context",
"input": { "caseId": "CASE-1042" },
"output": { "status": "open", "issue": "delivery delayed" }
}
Enforce authorization and redaction in the tool implementation, not just in agent instructions. Test with a case the caller is not allowed to see, a stale policy, and a question that has no matching source.
2. Invoice exception triage
Business need: Accounts payable receives invoices with mismatched purchase orders. A document-processing step extracts invoice fields; an agent can compare them with an approved purchase-order lookup tool and explain the mismatch.
- Extract the supplier, PO number, line totals, and confidence from each document; validate mandatory fields.
- Look up the purchase order through a scoped, read-only enterprise API.
- Route low-confidence extraction, missing orders, or price differences to a reviewer with source-page references.
- Record the decision and audit trail. Do not auto-approve a payment from a model-generated conclusion.
Measure extraction accuracy and the percentage of exceptions correctly routed before automating further steps.
3. Integration incident triage
Business need: An integration alert fires when order events stop arriving. An agent can gather recent dependency errors and deployment changes through read-only tools, then propose likely causes for an on-call engineer.
- Trigger the workflow from a monitored alert with a trace or correlation ID.
- Fetch a bounded, redacted window of logs and the latest approved runbook.
- Summarize evidence, separate observations from hypotheses, and cite the log or runbook source.
- Require an on-call engineer to approve any replay, rollback, or production change.
Evaluate on historical incidents: did the summary identify the failed dependency, avoid invented causes, and escalate when evidence was insufficient?
Further reading
Microsoft Learn covers grounded knowledge retrieval, custom agent tools, and human-in-the-loop workflows. Start with one read-only tool, test unauthorized and missing-data paths, then expand only after evaluation.