Your Teams agent's policy refusal is showing up as "the agent hit an error"
A Microsoft 365 Agents SDK custom engine agent holds its own model client, so it is ordinary library work — except that the guardrail call RAISES on a block rather than returning one, three separate exception types reach a governed handler, and on the TypeScript port the session cap silently never accumulates. A step-by-step journey with the real Agents Playground on screen, a mid-stream break, a verifiable audit chain, and the whole agent replayed for $0. No tenant, no tunnel, no key. Plus the governance Adaptive Card that makes all of it visible to the person in the chat, because `channelData` is not.
read →