Procurement AI should not just know what to do. It should know what it is allowed to read. The Procurement AI Stack gives you 100 mapped activities, 10 governed implementations, 12 workflows, 50 engineered prompts and a test regime built around the mistakes that matter. Licensed, not sold. Needs a Microsoft 365 Copilot licence with Agent Builder: this is the instruction layer for a platform you already pay for. Individual Edition $99 for one named user, Organization Edition $349 for one legal entity. Full terms (Kesslernity License & Terms, KESS-LIC-2026-001, Article 3.2) at kesslernity.com/license; the version in force on your purchase date applies. Practitioner guidance, not legal, procurement, audit or compliance advice. Read scope is a control Most AI guidance treats access as plumbing. In procurement it is the control itself. One agent that can read every live bid can carry one bidder's price into another bidder's clarification, and nobody in the room will see it happen. That is not a data-loss incident with a report to file. It is a tender you cannot defend. So every agent in this pack ships with its read scope written down and its write paths set to NONE, the estate register records what each one may read before its first real use, and one test scenario exists purely to try to make an agent reach outside its scope. Built for the failure modes that matter A savings register that ties out perfectly is the most convincing way to certify a double count. An agent that checks the total and stops has done the damage. A bid tabulation that ranks two bids on different bases hands the award to whoever excluded the most. A supplier dossier that reads complete on a company with no public filings is worse than a blank page, because someone will sign against it. The fixtures do not stop at tidy inputs. They carry a register that re-adds correctly and is still wrong by 23.3, one saving claimed twice across two initiatives, a baseline quietly restated against the same source document, a currency mismatch with no rate, bids where one excludes freight and duty and another annualizes a nine-month volume, an index-linked increase the published index does not support, and three turns of pressure to drop an inconvenient finding. PASS means the agent CAUGHT the inconsistency and named it. Explaining it confidently is a fail. One fixture is built so that correct arithmetic produces the wrong answer. A three-way-match exception clears a 2.0 percent tolerance and breaches the policy as written by 10.00, because the policy says whichever limb is lower. An agent that clears it shows its working while doing so, which is what makes the trap gradeable rather than merely unfair. How you test this You do not take anyone's word for it, which is the point. 56 scenarios, P-T1 to P-T56, across 10 clean inputs, 26 poisoned inputs, 10 three-turn pressure sequences, 9 controls and 1 read-scope probe. The protocol ships as its own document: every scenario, the fixture it runs on, and what a PASS has to produce. 7 numeric fixtures carrying 90 pre-computed equations, 66 of them restated in the answer keys. Grading is arithmetic you re-add by hand, not impression. 10 answer keys ship with the pack instead of sitting behind a support ticket. Never paste one into the agent's chat: the key is the ruler, and an agent that has seen the expected answer proves nothing. 9 of the 56 are controls, where the finding is genuinely absent and PASS means printing the zero instead of manufacturing something to look useful. Over-reporting destroys the credibility of the real findings. Run WF-1 on your own build before first real use, and re-run it after any instruction edit and after platform changes. A fix without a named fixture re-run does not count. Build one agent, grade it against its key, and you have a written result to put in front of the person who asks why you trust it. What is in the pack 10 governed implementations, each with a build sheet and a spec. Paste-ready instruction files with character counts, so a truncated paste cannot masquerade as a working agent. Each one takes you from a blank Agent Builder form to a run you have graded yourself. 100 procurement activities classified into five operating modes: 49 agent-led with review, 15 AI-assisted, 8 straightforward automation, 24 never automate, 4 human only. 30 of the 100 are rows where the arithmetic has to reconcile to a stated baseline. 50 engineered prompts, 12 gated workflows, a decision matrix that gives the next AI idea a lane instead of a debate, a nine-section governance pack with mechanisms instead of posters, 13 working templates, an AI estate register pre-filled for all ten agents, and a 30-day sprint with a gate at the end of every week. A 20-page Playbook PDF and a 15-tab workbook: the 100-row map with your own posture, priority and owner columns, the paste shapes the agents expect (spend extract, bid tabulation, savings register, match input, performance counts), your procurement profile with its tail threshold and delegation levels, the pre-filled estate register, an agent test log with blank columns for your own run dates, and the value scorecard your CPO reads at day 30. 28 of the 100 activities are held back from automation, 24 never automate and 4 human only. Seven of them cost something: the award decision, purchase order release above the delegation-of-authority threshold, goods receipt certification, the sanctions hit determination, supplier onboarding approval, supplier bank detail changes, and inspection release. Gates that cost nothing are decoration. Nothing in this pack prepares a safety authorization. AI assembles the evidence, a competent person qualifies and signs. 83 files in one zip, 62 PDFs across 190 pages, 20 paste-ready text files and one workbook. The zip separates the vendor-neutral methodology (core/) from the implementation written for Microsoft 365 Copilot (microsoft/), so the classification, the gates and the test protocol stay usable if you build somewhere else. AI prepares. Humans decide. Read scope is a control. What you need first: a Microsoft 365 Copilot licence with Agent Builder. This is the instruction layer for a platform you already pay for. It does not include, replace or discount the licence. Individual Edition ($99): one named purchaser, for use in your own work. Deploy the agents in a tenant you work in and adapt everything for what you personally do; no team redistribution, no resale, no public republication. If anyone else on your team will use the pack, you need the Organization Edition. Deploying this with your procurement function? Organization Edition ($349): one legal entity, internal use, no per-seat cap. Share the pack across your procurement team; multiple practitioners can build from it. A subsidiary that operates as its own company needs its own copy. Same exclusions: no resale, no public republication, no delivering it as paid training to others. Both editions ship the same zip, file for file: you are choosing usage rights, not features. Licensed, not sold. Full terms (Kesslernity License & Terms, KESS-LIC-2026-001, Article 3.2) at kesslernity.com/license; the version in force on your purchase date applies. Kesslernity is an independent publisher: this product is independent analysis, not affiliated with, sponsored by, or endorsed by Microsoft. Microsoft 365 and Copilot are trademarks of the Microsoft group of companies.