Build an AI layer for sales where the agent prepares the seller and commits nothing on their behalf.
Governing what an agent may read is a permission problem, and your tenant already has an answer for it. What it may assert has no owner. A wrong read leaks. A wrong assertion reaches a customer and does not come back. Ten governed implementations, four named authority sources, and four literal tokens an agent prints rather than guessing.
Five things a customer can hold you to, and an agent states none of them on its own.
A price. A term. A delivery date. A statement of capability. A named customer reference. Four of the five have a register behind them, and the spec has the agent name the source or print a refusal. The delivery date has no register at all. The four hold standing values a run can be checked against, and a date is set per deal by whoever owns delivery capacity that month, so its authority is a named person's written commitment rather than a row anybody can look up. That gap is the whole point: an agent can repeat a date back to you perfectly and still be wrong to commit it.
Your revenue platform already writes the follow-up email and rolls the forecast, and your CPQ already governs the quote record: a price outside the book cannot be put on it. Those are permission models over data and validation rules over fields. None of them governs the claim inside a sentence that is not yet a record. The follow-up email. The meeting summary. The RFP answer. The proposal draft. That is the surface this pack works on, and the honest competitor on it is not a vendor: it is the seller who already pastes the deal into a chat window and sends whatever comes back.
A chat message is not a source. A seller who writes "delivery is six weeks, ops confirmed it on the call" is supplying a fact that may well be true, through a channel with no authority. An agent that repeats it into a proposal has failed, and it failed precisely because it was accurate to the chat.
of the 100 classified activities are held back from automation: 16 never automate, 8 human only. Those are not synonyms. Never automate lets an agent prepare the material and forbids it issuing the decision. Human only keeps the agent out, because there the material is the judgment.
Agent-led with review
AI-assisted
Straightforward automation
Never automate
Human only
Four authority sources, and four things the agent says instead of guessing
A price, a term, a capability claim and a named reference each come from one of four sources: the price book, the standard terms, the capability register and the reference register. When the source does not hold it, the fence has the agent write NOT COMMITTABLE:, UNSOURCED CLAIM:, DATA INCONSISTENCY: or REFUSED: and names what is missing. A refusal you can read is worth more than a sentence you have to retract.
Two of the ten agents answer RFP requirements and assemble capability claims, so this belongs here rather than in the small print. Nothing in this pack prepares a safety authorization. No output qualifies a product, a service or a person for a safety-critical or regulated duty. AI assembles the evidence, a competent person qualifies and signs.
Built for the failure that is inside the rules.
The discount that costs you is not the one that breaks policy loudly. It is the one that sits exactly inside the seller's own authority and quietly breaks a second limit nobody checked in the same sentence.
A forecast that re-adds perfectly and rests on a probability table nobody declared. A dossier that reads complete on a company with nothing published. An RFP answer that claims a certification the certificate holder has not given you.
The fixtures carry the defect on purpose
A discount request at exactly the requester's ceiling. A capability claim with no register entry behind it. A named reference whose consent expired. A renewal whose notice window shut 33 days before the run. Counts compared across periods of different lengths. And three turns of pressure to drop the inconvenient finding.
PASS means the agent CAUGHT it and named it. Explaining it confidently is a fail, and the answer key says which is which.
margin points by which one discount request in the fixtures breaches the floor, while sitting exactly on the requester's own 20.0 percent ceiling. Authority and margin are two independent limits. An agent that answers "within her authority" and prints no margin figure has answered the question that was asked and missed the one that mattered.
One fixture where the more precise-looking answer is the wrong one
The maximum compliant discount on that line is 11.8182 percent. Truncated to 11.81 it holds the floor. Rounded to 11.82, which looks like the more careful answer, it lands under the floor and breaches the policy it was calculated to respect. The key carries the arithmetic to four places so you can see exactly where a plausible answer goes wrong, which is what makes the trap gradeable rather than merely unfair.
You do not take anyone's word for it, which is the point.
The test protocol ships as its own document: every scenario, the fixture it runs on, and what a PASS has to produce. Ten of the scenarios are clean inputs, so you can see the shape of a good answer before you start breaking things.
Build one agent, grade it against its key, and you have a written result to put in front of the person who asks why you trust it.
Scenarios, S-T1 to S-T56
Poisoned inputs
Three-turn pressure sequences
Controls where the right answer is zero findings
Commitment probe
10 fixtures carrying planted defects74 figures in the keys
Grading is arithmetic you re-add by hand where a figure is expected, and a stated pass condition where a refusal is. Neither one is impression. Every expected figure is worked out for you: net prices, margin percentages to four places, weighted forecast totals, entitlement against consumption, notice-date subtractions, requirement-by-requirement verdicts.
10 answer keys ship with the packnot behind a support ticket
Never paste one into the agent's chat. The key is the ruler, and an agent that has seen the expected answer proves nothing. You read the key, the agent does not.
9 of the 56 are controlsPASS is the zero
The finding is genuinely absent and a PASS means printing the zero instead of manufacturing something to look useful. An agent that always finds something is not careful, it is loud, and over-reporting destroys the credibility of the real findings.
1 is a commitment probe
It asks an agent for the one thing no register holds, in the friendly way a real seller would ask on a Friday afternoon. The refusal token is the pass. This is the scenario the whole pack is built around.
Run WF-1 on your own build before first real use
Then re-run it after any instruction edit and after platform changes. A fix without a named fixture re-run does not count, and the workflow is the calendar entry that keeps that honest.
Five parts: the governed builds, and the method they run inside.
70 files in one zip: 49 typeset PDF documents, 20 paste-ready text files and a 15-tab Excel workbook. The zip separates the vendor-neutral methodology (core/) from the implementation written for Microsoft 365 Copilot (microsoft/), so the classification, the commitment rules and the test protocol stay usable if you build somewhere else.
10 governed implementationsa spec and a fence each
Pipeline Hygiene Auditor, Opportunity Qualification Challenger, Weighted Forecast Assembler, Account Research Dossier Builder, Meeting Preparation Pack Builder, Proposal Draft Assembler, Discount and Margin Guard, Renewal and Expansion Signal Analyst, RFP Response Compliance Checker, Pipeline Review Brief Builder. Paste-ready instruction files with character counts, so a truncated paste shows up as a number that does not match before you test it rather than as a strange answer three weeks later. Each spec argues its refusals rather than listing them, names the map row it implements and the mode it runs in, and carries its read scope and its write paths in the file rather than in a policy nobody opens.
10 fixtures and 10 answer keys74 figures
Every expected figure pre-computed so you re-add them by hand. The planted defects are the point: a request at the exact ceiling, a capability claim with no register entry, an expired reference consent, a shut notice window, a probability table nobody declared.
100 sales activities classified5 modes
45 agent-led with review, 19 AI-assisted, 12 straightforward automation, 16 never automate, 8 human only. Every row carries the reason, not just the verdict. Bid or no-bid is human only. A delivery date has no register behind it and the map says so. The forecast number is a signature rather than a calculation.
50 engineered prompts, 12 gated workflows
Self-contained chat blocks for a seller with nothing built, guardrail lines included as part of the prompt. Twelve workflows say who triggers each agent, what a human decides either side and where it escalates; four of them can stop the work outright. Plus a seven-question decision matrix, a nine-section governance pack, and a 30-day sprint with a gate at the end of every week.
13 working filesyour numbers, pasted per run
The four authority registers as one input block, the pipeline extract and coverage note, the qualification and forecast shapes, the meeting prep block, the discount request block, renewal counts against the contracted ramp, your sales profile with every threshold the agents read, the estate register (the inventory of which agent exists, who owns it and what it may touch) pre-filled for all ten agents, and the value scorecard your sales leader reads at day 30. None of it becomes standing agent knowledge, and that is a choice rather than a gap: an agent that remembers last quarter's price book is an agent that quotes it. Every run is fed the current numbers, which is the same reason every register entry carries a review date.
Two of the four sources are ones you probably do not have yet.
The commitment-bearing agents rest on four authority sources: the price book, the standard terms, the capability register and the reference register. The governance pack calls two of them the registers you probably do not have. They are the capability register and the reference register, they live in people's heads and last year's slides, and building them is the real cost of month one.
Six of the ten never read either missing register, and five of those six are weeks one and two of the sprint, so the first fortnight is unblocked on the day you buy. Two more read one of them in week three. The two that read all four sources are week four, each register landing a week before the agent that needs it. The sequence is built around this gap rather than around a demo.
The pack ships the template, the five fields every entry carries (the value, its source, its owner, its effective date, and a review date, because "no expiry" is how a register goes stale unnoticed), a named owner for each and a review cadence whose job is to surface stale entries before an agent quotes one. It does not ship your content. That work is writing down what you actually deliver and who has actually agreed to be named, with an owner and an effective date on every entry.
registers you will most likely be building rather than connecting. If that is a deal-breaker, it is better that you know it now than after the download. Point an agent at authority that is not there and nothing fails loudly: it turns the gap into a confident sentence. The fence has it print a refusal instead, and the fixture for that agent is where you find out whether it did.
AI prepares the seller. The seller decides.
That is the whole methodology in one line, and every refusal in the pack is downstream of it. The agents research, assemble, challenge, re-add and package. A named person prices, promises, commits a date, claims a capability and offers a reference.
The pack creates no commitment authority and changes none of yours. It is practitioner guidance, not legal, tax or commercial advice.
Same zip. Different usage rights.
Both editions ship the same zip, file for file: you are choosing usage rights, not features. Licensed, not sold.
What it is: 49 PDF documents you read, 20 plain-text files you paste, and one Excel workbook you fill in. There is no installer, no connector and nothing to deploy. The Stack itself adds no per-seat or per-run cost on top of the platform you already licence.
What you need first: a Microsoft 365 Copilot licence with Agent Builder. This is the instruction layer for a platform you already pay for. It does not include, replace or discount the licence.
- Deploy the agents in a tenant you work in
- Adapt everything for what you personally do
- No team redistribution, no resale, no public republication
- Share the pack across your sales function
- Multiple practitioners can build from it
- No resale, no public republication, no delivering it as paid training
Same zip either way. Click Buy, then confirm Individual or Organization Edition before you pay.
Pair it with the agent controls and the tenant baseline.
The Stack is the build layer. These two are the surface it runs on: what an agent is allowed to reach, and how the tenant around it is set. Each stands on its own.
Securing Agents in Microsoft 365 Copilot
A control-by-control verification kit for the agent surface itself: what an agent can reach, who published it, and how you prove it.
The Copilot Hardening Baseline
176 checks for the Microsoft 365 Copilot admin surface. Each one names the baseline to set and how to prove it.