| metadata | {"author":"github: Raishin","version":"0.1.0","updated":"2026-06-17","category":"data","execution_tier":"mutating-runtime","mcp_servers":[],"oauth_scopes":[],"run_as_permissions":{"required":["Custom Dataverse security role with Write (prvWrite) on ONLY the one in-scope table — record-level/owner-scoped where supported","Read (prvRead) on the same table to capture prior field values for ROLLBACK","Application user (SystemUser row) in the target Dataverse environment bound to the custom least-privilege write role — NOT System Administrator, NOT System Customizer","Dataverse data-plane access via S2S application user (ApplicationId/AzureActiveDirectoryObjectId on SystemUser)"],"denied":["System Administrator","System Customizer","Delete privilege on any table (prvDelete)","Bulk/multi-record write operations (any query that targets more than one record ID)","Wildcard or all-records operations","Ownership change operations (ownerid field reassignment)","Security role or privilege edits (no write on role, roleprivileges, systemuserroles, teamroles)","prvActOnBehalfOfAnotherUser","Power Platform management SPN path (pac admin create-service-principal — cannot be least-privileged)","Write on any table other than the single in-scope table"]},"required_egress":["*.dynamics.com","login.microsoftonline.com"],"requires_credentials":["DATAVERSE_CLIENT_ID","DATAVERSE_ENV_URL"],"output_attestation":{"schema":"field-update-attestation-v1","signed_with":"idempotency-key","audit_log":"required"},"liveAgentFields":{"execution_tier":"mutating-runtime","single_op":true,"reversible":true,"requires_approval_token":true,"dry_run_preflight":true,"idempotency_key":true,"blast_radius_required":true},"companion_agents":["d365-live-record-field-update-guard-agent"]} |