| title | Foundry Hosted Agents Workshop - Financial Services (FSI) |
|---|---|
| description | Bilingual hands-on workshop adapting Microsoft Foundry hosted agents to a synthetic Ontario auto-insurance quote-preparation scenario with a deterministic calculator and a mandatory employee-approval gate. |
This repository is a bilingual (English/French) hands-on workshop adapted
from the sibling
foundry-hosted-agents
repository. It replaces that repository's airline threat-assessment
scenario with a financial-services scenario: a synthetic Ontario
auto-insurance quote-preparation agent, backed by a deterministic
calculator and a mandatory, separately persisted employee-approval gate
before any applicant-facing preview.
Important
Every fixture, rulebook, and calculator output in this repository is synthetic and non-binding. Nothing here represents an actual Desjardins product, rate, or policy, and no regulator or insurer has reviewed or endorsed this workshop.
The default path through these labs does not require GitHub Copilot or any other AI coding assistant. Where workshop authors used AI-assisted tooling to help draft or review content, that assistance is disclosed in the affected lab or file rather than implied as part of the learner experience.
docs/holds the English workshop site (Jekyll, Just the Docs theme); start at docs/index.md.docs/fr/holds the French workshop site, structurally paired withdocs/; start at docs/fr/index.md.src/quote-preparation-agent/will hold the hosted LangGraph quote-preparation agent.mcp/application-server/will hold a read-only MCP service exposing synthetic application data.mcp/rulebook-server/will hold a read-only MCP service exposing synthetic rulebook data.apps/workshop/will hold the deterministic calculator, approval repository, and applicant/reviewer views.apps/web-chat/holds an internal-pilot web chatbot for the hosted agent, ported from the sibling repository. It is deployed out of band (infra/web-chat.bicep) alongsideapps/reviewer-app/-- see Deployment links below for both UIs' current URLs.data/synthetic/will hold the synthetic fixtures and JSON Schema for the quote-preparation contract.eval/will hold the evaluation harness for arithmetic, approval, injection, and bilingual-parity checks.infra/will hold Bicep infrastructure modules, author-only until platform and regulatory review gates clear.scripts/will hold shared helpers, including the bilingual workshop-deck generator.
Start at the workshop landing page: docs/index.md in English, or docs/fr/index.md in French. The same content is published as a browsable site at https://devopsabcs-engineering.github.io/foundry-hosted-agents-fsi/ (GitHub sign-in is required while this repository is private).
The chat UI in apps/web-chat/ is deployed out of band to production (see
Deployment links for the current URL). To run it
locally instead, against the real deployed agent:
cd apps/web-chat/frontend
npm install
npm run build
cd ..
$env:AGENT_ENDPOINT = "$env:FOUNDRY_PROJECT_ENDPOINT/agents/quote-preparation-agent/endpoint/protocols/openai/responses?api-version=v1"
$env:ENTRA_TENANT_ID = (az account show --query tenantId -o tsv)
$env:ENTRA_CLIENT_ID = "<app registration id from scripts/setup-web-chat-identity.ps1>"
$env:PILOT_GROUP_ID = "<pilot security group object id>"
python -m uvicorn app:create_app --factory --host 127.0.0.1 --port 8000Then open http://127.0.0.1:8000/. The landing screen renders without any
Entra configuration; Sign in with Microsoft and the message composer
only become usable once ENTRA_CLIENT_ID and PILOT_GROUP_ID point at a
real app registration and pilot group.
If npm install fails with EALLOWREMOTE, the npm 12 default
allow-remote = "none" is rejecting the corporate feed proxy's absolute
tarball URLs; re-run it as npm install --allow-remote=all.
apps/reviewer-app/ is the reviewer-facing case queue: every case the
agent submits for review lands here, gated by an Entra app role rather
than the chatbot's security-group membership. See
Deployment links for the current deployed URL, or
docs/labs/lab-13-reviewer-ui.md for
running it locally against a real Entra registration.
Note
The production environment's underlying Azure resource and azd
environment names carry a historical -poc suffix (for example
cosmos-desjardins-quote-preparation-poc,
aif-desjardins-quote-preparation-poc). Despite that suffix, these are
the production resources, not a separate proof-of-concept deployment --
the wiki's Deployment Links table labels each row (production) or
(staging) explicitly, so trust that label over any -poc text you spot
in a resource name or URL.
This repository does not hardcode a "live demo" URL here, because the
underlying Container Apps hostnames and Foundry project name are
environment-specific and can be re-provisioned. Instead, the
wiki Home page
carries an always-current Deployment Links table -- refreshed
automatically after every staging or production run of
Deploy and Evaluate (Staging -> Production)
-- with clickable links to whatever is genuinely deployed right now, including
both pilot UIs:
- the reviewer app (case approval queue) and the web chatbot (applicant-facing chat UI)
- the hosted agent's Foundry project (Azure Portal, sign-in required)
- the agent's Responses API endpoint
- the
application-serverandrulebook-serverMCP endpoints - the resource group and container registry
- the published workshop site on GitHub Pages
Always follow the wiki Home page for the current UI URLs rather than any link recorded elsewhere -- both container apps can be re-provisioned with a new hostname, and the wiki page is the only copy that is refreshed on every deploy.
See also the Continuous Test Trends wiki page for the latest offline-test, deterministic-gate, and LLM-judge evaluation results.
Web chatbot pilot: apps/web-chat/ (a browser-based chat UI in front
of the hosted agent) is deployed out of band rather than by
deploy-and-evaluate.yml. Its template is
infra/web-chat.bicep, applied with a direct
az deployment group create into the Container Apps environment that
infra/main.bicep already provisioned, and its Entra app registration comes
from scripts/setup-web-chat-identity.ps1.
Because the managed environment is recreated whenever its network
configuration changes, redeploy the chat and rerun the identity script after
any network rebuild. Its URL is not an azd output, so
deploy-and-evaluate.yml's promote-production job reads it from the
WEB_CHAT_APP_NAME/WEB_CHAT_URL repository variables (production
environment) to include it in the wiki's Deployment Links table -- update
those variables after redeploying the chat to a new hostname.

