← All integrations
MICROSOFT AGENT FRAMEWORK · PYTHON · NATIVE MIDDLEWARE · PYPI v0.1.0

Verifiable decision evidence for Microsoft agents.

The released LoopGrid adapter attaches to Microsoft Agent Framework’s native Python chat and function middleware. Keep Microsoft’s runtime and approval flow; record policy, human review, tool execution and observed outcomes in your existing LoopGrid Core.

Published v0.1.0 · Validated with Microsoft Agent Framework 1.21.0, LoopGrid Python SDK 0.8.0, and Core 0.8.1-design-partner. Python support only.

DECISION EVIDENCE FLOW
01Host decision + delegated authority
02Microsoft model middleware
03Application policy + native approval
04Authorized function dispatch
05Independently observed outcome
06Evidence complete + Core verify

Execution stays with Microsoft and your application. LoopGrid records tamper-evident evidence; it is not the payment system or the source of reviewer identity.

01 · INSTALL · AVAILABLE NOW

Install the published Python integration.

pip install loopgrid-microsoft-agent==0.1.0

Use your existing LoopGrid Core workspace and credentials. The package depends on agent-framework-core>=1.19.0,<2 and loopgrid>=0.8.0,<0.9. This is the Python adapter, not a separate backend or a .NET package.

02 · CONNECT

Bind an Agent run to one consequential decision.

from agent_framework import Agent, tool
from loopgrid_microsoft_agent import LoopGridMicrosoftAgent

bridge = LoopGridMicrosoftAgent(
    workspace_id="YOUR_WORKSPACE_ID",
    agent_id="finance-agent",
)

@tool(approval_mode="never_require")  # harmless sandbox only
async def sandbox_refund(amount: int) -> str:
    return "sandbox simulated only"

decision = bridge.start_decision(
    decision_type="sandbox_refund",
    agent={"id": "finance-agent"},
    authority={"acting_for": "sandbox", "scope": ["refund:simulate"]},
    model={"provider": "your-model-provider", "name": "your-model-name"},
    context={"prompt_version": "v1"},
    proposed_action={"tool": "sandbox_refund", "arguments": {"amount": 25}},
    policy={"policy_id": "reviewed-sandbox-policy", "version": "1", "decision": "auto_allowed"},
    metadata={"sandbox": True, "real_money_moved": False},
)

# YOUR_CONFIGURED_CHAT_CLIENT is provided by your application.
agent = Agent(client=YOUR_CONFIGURED_CHAT_CLIENT,
              tools=[sandbox_refund], middleware=bridge.middleware)

# In an async function:
with bridge.decision_context(decision["decision_id"]):
    result = await agent.run("Perform the sandbox simulation using amount 25")

This example deliberately shows a host-configured model client placeholder, not a paid-model-free runnable script. For a fully executable local test with a deterministic Microsoft client and actual LoopGrid Core verification, use the repository examples ↗.

03 · NATIVE EVENTS

Use Microsoft middleware, not a renamed generic adapter.

01Decision + policy

The host creates the decision and records a real application policy result before tool authorization.

02Model completion

ChatMiddleware records observed non-streaming model completions and SHA-256 commitments.

03Tool request + result

FunctionMiddleware binds the exact tool name and arguments; authorized execution records actual return evidence.

04External outcome

The application independently observes and records downstream success or failure; a framework return alone is not a business receipt.

Never label an agent’s claim as a verified payment or approved action. The verifier proves integrity and provenance of captured events, not correctness or completeness of the underlying business process.
04 · MICROSOFT NATIVE APPROVALS

Pause first. Resume only after the host verifies review.

For consequential tools, configure approval_mode="always_require" in Microsoft Agent Framework. The real framework pauses tool dispatch; the host authenticates the reviewer, records bridge.record_human_review(...) and resumes the same Microsoft session. Rejected or missing approvals must not run the tool.

Denied / missing approvalNo sandbox tool execution; Core may reject pre-execution request evidence. Never fabricate a tool execution event.
Native rejectionMicrosoft pauses; host records rejection; resumption executes zero sandbox tools.
Native approvalMicrosoft pauses; host records approval; resumption dispatches one sandbox tool.
Trust boundaryThe host must authenticate the reviewer; demo identifiers are synthetic and do not prove production identity.
05 · OBSERVED OUTCOME

A framework result is not an independent business outcome.

# Only after observing a trustworthy external/sandbox result:
bridge.record_outcome(
    decision["decision_id"],
    {"status": "succeeded", "external_reference": "trusted-receipt-id",
     "sandbox": True, "real_money_moved": False},
    observer="authoritative-sandbox-ledger",
)
record = bridge.get_decision(decision["decision_id"])
print(record["coverage"], record["verification"])

Capture the authoritative receipt from your external system or sandbox ledger, separately from the model and tool return. Core signs the recorded evidence using its existing Ed25519/SHA-256 infrastructure.

06 · RELEASE VALIDATION

Passed against the real Microsoft runtime and LoopGrid Core.

Automated tests28/28 passed on Windows with Microsoft Agent Framework 1.21.0
Real Core E2ECore 0.8.1-design-partner; evidence_complete; applicable coverage 100%; verifyValid true
Security scenarios6/6 passed: blocked policy, missing approval, rejection, approval, wrong arguments and evidence-write failure
Native Microsoft approvalBoth reject and approve pause/resumption paths passed using the same agent session
Public packagingGitHub CI, PyPI Trusted Publishing, fresh public PyPI installation and import passed
# Run the real Microsoft Agent Framework test against a running Core:
python examples/native_core_e2e.py

# Test blocked policy, missing/rejected approval, wrong arguments
# and injected evidence-write failure (fail closed):
python examples/native_core_policy_e2e.py

# Test Microsoft's native always_require pause/resume in the same session:
python examples/native_core_microsoft_approval_e2e.py

All example refunds are sandbox simulations; no real money was moved. Native approval tests used synthetic host responses and did not validate enterprise reviewer authentication.

07 · LIMITATIONS

Clear boundaries before production adoption.

Streaming model responses are not recorded as completed model calls until proper finalization is supported. Approval identity comes from the host application, not from an untrusted agent message. Action/approval bindings are process-local and require explicit reauthorization after restart; v0.1.0 defaults to one exactly matched action per decision. Use host authorization and downstream idempotency for real-world workflows.

Read the complete integration contract ↗, security notes ↗ and validation record ↗.

MICROSOFT AGENT FRAMEWORK + LOOPGRID

Keep the Microsoft runtime. Make the evidence independently verifiable.

Start with one sandbox workflow, review what evidence proves, then connect your application’s actual policy, reviewer authentication and downstream outcome systems.