Verifiable decision evidence for Microsoft agents.
The released LoopGrid adapter attaches to Microsoft Agent Framework’s native Python chat and function middleware. Keep Microsoft’s runtime and approval flow; record policy, human review, tool execution and observed outcomes in your existing LoopGrid Core.
Published v0.1.0 · Validated with Microsoft Agent Framework 1.21.0, LoopGrid Python SDK 0.8.0, and Core 0.8.1-design-partner. Python support only.
Execution stays with Microsoft and your application. LoopGrid records tamper-evident evidence; it is not the payment system or the source of reviewer identity.
Install the published Python integration.
pip install loopgrid-microsoft-agent==0.1.0
Use your existing LoopGrid Core workspace and credentials. The package depends on agent-framework-core>=1.19.0,<2 and loopgrid>=0.8.0,<0.9. This is the Python adapter, not a separate backend or a .NET package.
Bind an Agent run to one consequential decision.
from agent_framework import Agent, tool
from loopgrid_microsoft_agent import LoopGridMicrosoftAgent
bridge = LoopGridMicrosoftAgent(
workspace_id="YOUR_WORKSPACE_ID",
agent_id="finance-agent",
)
@tool(approval_mode="never_require") # harmless sandbox only
async def sandbox_refund(amount: int) -> str:
return "sandbox simulated only"
decision = bridge.start_decision(
decision_type="sandbox_refund",
agent={"id": "finance-agent"},
authority={"acting_for": "sandbox", "scope": ["refund:simulate"]},
model={"provider": "your-model-provider", "name": "your-model-name"},
context={"prompt_version": "v1"},
proposed_action={"tool": "sandbox_refund", "arguments": {"amount": 25}},
policy={"policy_id": "reviewed-sandbox-policy", "version": "1", "decision": "auto_allowed"},
metadata={"sandbox": True, "real_money_moved": False},
)
# YOUR_CONFIGURED_CHAT_CLIENT is provided by your application.
agent = Agent(client=YOUR_CONFIGURED_CHAT_CLIENT,
tools=[sandbox_refund], middleware=bridge.middleware)
# In an async function:
with bridge.decision_context(decision["decision_id"]):
result = await agent.run("Perform the sandbox simulation using amount 25")This example deliberately shows a host-configured model client placeholder, not a paid-model-free runnable script. For a fully executable local test with a deterministic Microsoft client and actual LoopGrid Core verification, use the repository examples ↗.
Use Microsoft middleware, not a renamed generic adapter.
The host creates the decision and records a real application policy result before tool authorization.
ChatMiddleware records observed non-streaming model completions and SHA-256 commitments.
FunctionMiddleware binds the exact tool name and arguments; authorized execution records actual return evidence.
The application independently observes and records downstream success or failure; a framework return alone is not a business receipt.
Pause first. Resume only after the host verifies review.
For consequential tools, configure approval_mode="always_require" in Microsoft Agent Framework. The real framework pauses tool dispatch; the host authenticates the reviewer, records bridge.record_human_review(...) and resumes the same Microsoft session. Rejected or missing approvals must not run the tool.
A framework result is not an independent business outcome.
# Only after observing a trustworthy external/sandbox result:
bridge.record_outcome(
decision["decision_id"],
{"status": "succeeded", "external_reference": "trusted-receipt-id",
"sandbox": True, "real_money_moved": False},
observer="authoritative-sandbox-ledger",
)
record = bridge.get_decision(decision["decision_id"])
print(record["coverage"], record["verification"])Capture the authoritative receipt from your external system or sandbox ledger, separately from the model and tool return. Core signs the recorded evidence using its existing Ed25519/SHA-256 infrastructure.
Passed against the real Microsoft runtime and LoopGrid Core.
# Run the real Microsoft Agent Framework test against a running Core: python examples/native_core_e2e.py # Test blocked policy, missing/rejected approval, wrong arguments # and injected evidence-write failure (fail closed): python examples/native_core_policy_e2e.py # Test Microsoft's native always_require pause/resume in the same session: python examples/native_core_microsoft_approval_e2e.py
All example refunds are sandbox simulations; no real money was moved. Native approval tests used synthetic host responses and did not validate enterprise reviewer authentication.
Clear boundaries before production adoption.
Streaming model responses are not recorded as completed model calls until proper finalization is supported. Approval identity comes from the host application, not from an untrusted agent message. Action/approval bindings are process-local and require explicit reauthorization after restart; v0.1.0 defaults to one exactly matched action per decision. Use host authorization and downstream idempotency for real-world workflows.
Read the complete integration contract ↗, security notes ↗ and validation record ↗.
Keep the Microsoft runtime. Make the evidence independently verifiable.
Start with one sandbox workflow, review what evidence proves, then connect your application’s actual policy, reviewer authentication and downstream outcome systems.