Building an AI agent is relatively easy, however – building one that is useful, secure and reliable requires a bit of planning.
Microsoft has an Agent Design Framework, that provides a structured way to plan agents, before you start trying to build them! Before embarking on your agentic journey, we’d recommend you use this framework to agree what your agents should do, how they will work, and to manage risk.
Focus on business outcomes
The very first questions you should be asking include:
For example, a CFO Agent might review your debtors reports, prepare a narrative, and share the report with the relevant people in your business. Starting with the outcome prevents organisations from creating agents simply because the technology is available.
Nearly 90% of the Fortune 500 now have active agents built with our low-code/no-code tools.
Define how the agent will work
Microsoft’s framework asks organisations to consider several practical areas:
For example, a CFO Agent might review your debtors reports, prepare a narrative, and share the report with the relevant people in your business. Starting with the outcome prevents organisations from creating agents simply because the technology is available.
Consider what knowledge your staff members would need, what systems they would access, and the data they would retrieve.

Decide where humans remain involved (“human in the loop”)
Not every task should be completed autonomously. Low-risk actions, such as retrieving information or drafting a response, may require little supervision. Higher-risk or irreversible actions should normally include validation, approval or escalation.
This avoids both extremes: agents that are too restricted to be useful and agents that have more access or authority than they require.
Include governance from the beginning
Security, permissions and governance should form part of the original design – not thrown in at the end!
Organisations should establish who owns the agent, what information it can access, which actions it can perform and how its activity will be monitored and audited. In the same way each member of staff should have a line-manager, your agent should have an owner.
Testing & Evaluation
Evaluation is equally important. Agents should be tested against real scenarios, including incorrect data, unavailable systems, permission restrictions and situations where the correct response is to refuse or escalate. Microsoft recommends measuring accuracy, relevance, adoption, time saved, user satisfaction and compliance with permissions.
From AI experiment to business service
Many organisations begin their AI journey with small proofs of concept. This is useful for learning, but a successful demonstration is not necessarily ready for production. Microsoft’s Agent Design Framework helps turn an initial idea into a managed business service. By defining the outcome, data, actions, controls and measures of success before development, organisations can create agents that are more useful, trustworthy and easier to maintain.
Speak to us about where AI agents could save time, reduce costs and improve how your business operates.




