Skip to main content

aiyoplane-microsoft-agent-framework

AEAP Composition Boundary Adapter for the Microsoft Agent Framework.

A thin wrapper that attaches the AEAP Runtime Decision Point (RDP) to the Microsoft Agent Framework's middleware chain and workflow nodes. Consequential actions produce independently verifiable Execution Receipts. The adapter composes with the framework's own middleware, telemetry, session, and tool machinery.

pip install aiyoplane-microsoft-agent-framework

Why Microsoft Agent Framework

Microsoft's current Agent Framework — the successor to AutoGen and Semantic Kernel — explicitly includes middleware for intercepting agent actions as a first-class architectural primitive. That middleware primitive is architecturally adjacent to the AEAP Composition Boundary, which makes this one of the cleanest adapter integrations in the Wave 1 set. AEAP sits in the middleware chain; the agent gets independently verifiable authorization for every consequential action without application code changes.

The framework also positions workflows around explicit execution paths — nodes with declared pre- and post-conditions. AEAP's second integration surface in this adapter is the workflow-node wrapper.

See the AEAP specification §9 for the Composition Boundary primitive this adapter realizes.

Minimal usage — middleware integration

from agent_framework import Agent
from aiyoplane_mcp_authz import create_aiyo_mcp_authz, create_local_rdp
from aiyoplane_microsoft_agent_framework import (
    AiyoAgentMiddleware,
    BlockedByPolicy,
    EscalationRequired,
)

policy = {
    "rules": [
        {"action_type": "payment", "amount_max": 1_000, "effect": "allow"},
        {"action_type": "payment", "amount_max": 10_000, "effect": "escalate"},
        {"action_type": "payment", "effect": "block"},
    ]
}

authz = create_aiyo_mcp_authz(
    rdp=create_local_rdp(policy=policy),
    tool_config={
        "transfer_funds": {"aiyo_gated": True, "action": {"type": "payment"}},
    },
)

aiyo_mw = AiyoAgentMiddleware(
    authz=authz,
    intent_builders={
        "transfer_funds": lambda payload: {
            "type": "payment",
            "amount": payload["amount"],
            "target": payload["to_account"],
        },
    },
)

agent = Agent(
    name="banker",
    instructions="Help the user manage their accounts.",
    middleware=[aiyo_mw, ...],
)

The middleware pattern: AEAP runs before every action matching an entry in intent_builders. Non-registered actions pass through unchanged (explicit opt-in).

Minimal usage — workflow node wrapping

For workflow nodes defined as plain callables, use wrap_action:

from aiyoplane_microsoft_agent_framework import wrap_action

async def deploy(target: str, artifact_hash: str) -> str:
    return actually_deploy(target, artifact_hash)

guarded_deploy = wrap_action(
    deploy,
    authz=authz,
    tool_name="deploy",
    intent_builder=lambda kwargs: {
        "type": "deploy",
        "target": kwargs["target"],
        "artifact": kwargs["artifact_hash"],
    },
)

# Register with your workflow the usual way.

Composition Boundary — what the adapter actually does

For each gated action:

  1. Intent construction. intent_builder(action_payload) produces an AEAP Intent payload.
  2. RDP evaluation. Via aiyoplane-mcp-authz's AiyoAuthz middleware.
  3. Verdict composition.
    • ALLOW → action proceeds to the next middleware / inner function; receipt attached to context.
    • ESCALATE → EscalationRequired is raised.
    • BLOCK → BlockedByPolicy is raised; the action never executes.
  4. Fail-closed default on every ambiguous condition.

Local vs. hosted RDP

from aiyoplane_mcp_authz import create_local_rdp, create_hosted_rdp

# Development:
authz = create_aiyo_mcp_authz(rdp=create_local_rdp(policy=policy), tool_config={...})

# Production:
authz = create_aiyo_mcp_authz(
    rdp=create_hosted_rdp(api_key="aiyo_live_..."),
    tool_config={...},
)

API reference

AiyoAgentMiddleware(*, authz, intent_builders, attach_receipt_key="aeap_receipt")

Middleware class. Register in the agent's middleware chain. Hook: before_action(context, action).

aiyo_middleware(*, authz, intent_builders, attach_receipt_key="aeap_receipt")

Convenience factory for AiyoAgentMiddleware.

wrap_action(fn, *, authz, tool_name, intent_builder, attach_receipt=False)

Function-level wrapper for workflow nodes or direct function invocations outside the middleware chain.

Exceptions

  • AiyoMSAgentFrameworkError — base class
  • AdapterConfigError, BlockedByPolicy, EscalationRequired

License

Apache License 2.0.

Microsoft, Microsoft Agent Framework, AutoGen, and Semantic Kernel are trademarks of Microsoft Corporation. This package is an independent AEAP Composition Boundary Adapter and is not affiliated with or endorsed by Microsoft Corporation.

Verify First. Execute Second.

Metadata

Release files for aiyoplane-microsoft-agent-framework 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for aiyoplane-microsoft-agent-framework 1.0.0
File Size Uploaded
aiyoplane_microsoft_agent_framework-1.0.0.tar.gz 13.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for aiyoplane-microsoft-agent-framework 1.0.0
File Interpreter ABI Platform
aiyoplane_microsoft_agent_framework-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 27.4 kB

Release files / aiyoplane_microsoft_agent_framework-1.0.0.tar.gz

Download URL aiyoplane_microsoft_agent_framework-1.0.0.tar.gz
Size 13.9 kB
Tags Source
SHA-256 checksum
How to use checksums
1bb9ec9bcb3850c9e7155804a337a96641c477aa2f93de2cb8fe1370fdd6e70d
BLAKE2b-256 checksum
How to use checksums
af08461e57ab108601f5a3abbab636965f29c61d8f2fbe0814b2237187960335
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.0rc3

Release files / aiyoplane_microsoft_agent_framework-1.0.0-py3-none-any.whl

Download URL aiyoplane_microsoft_agent_framework-1.0.0-py3-none-any.whl
Size 13.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
2c89feebc7a1069f6f4e1c299c399cc538c4d41fb6b6250b5c3e28c6a6aab9bd
BLAKE2b-256 checksum
How to use checksums
77f539e45f9982691932628eb3e404c6fb65dd54514a62528581007517f3cddf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.0rc3

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page