An architecture explains how a task moves through the system and which component controls each step. Start with one execution path. Add framework names after you understand the decisions, data and actions.
This conceptual design uses a support-drafting agent. It does not require six services or a particular vendor.
Follow the execution cycle
- Receive the task. Validate the request and identify user, case and permitted scope.
- Assemble context. Provide instructions and retrieve relevant information.
- Request a decision. The model proposes a response or tool call.
- Validate and execute. Check arguments, identity, limits and approval before calling the tool.
- Record the result. Save progress and return the tool result for the next decision.
- Stop, continue or ask. End on a confirmed result, defined limit or condition needing a person.
An SDK may supply the repeated execution logic. Your application supplies tools and business rules. Microsoft describes agents, workflows, integrations and state as distinct components. Microsoft Agent Framework.
Separate the components
| Component | Responsibility in the example |
|---|---|
| Model | Propose the next lookup or draft. |
| Runtime | Execute the cycle, manage limits and interruptions. |
| Retrieval | Find permitted order and carrier records. |
| Tool adapter | Call the case system through a defined interface. |
| Authorization | Reject unrelated records and unapproved actions. |
| State store | Record progress and unfinished work. |
| Monitoring | Report outcomes, failures and usage. |
The model can suggest an order ID. The lookup service must verify access. Valid JSON can contain the wrong record. Output-format validation does not establish meaning or permission.
Context, state and memory differ
Context is information available for one model call. It has a size limit. Your application decides what to include. Summarizing old messages can remove an important constraint.
State records progress: which case was requested, which lookup completed and whether a draft was saved. Store structured facts needed for recovery rather than relying entirely on a conversational summary.
Memory commonly means information retained across tasks or sessions. It needs rules for ownership, accuracy, retention and deletion. A preference remembered for one user should not affect an unrelated user.
Decide what survives a restart, what is temporary and what should never be stored. Conversation history may omit operational evidence.
Keep actions explicit
Use narrow tools such as lookup-order and save-draft. Define required identifiers and structured results. Distinguish access denied, missing record and temporary outage.
Tie sending approval to the actual recipient and content. A changed draft may need another decision. The backend should reject sending when the task permits only preparation.
MCP standardizes communication with tools and other capabilities. It does not choose your business permissions. MCP architecture.
Design recovery before the first write
Suppose save-draft succeeds but its response is lost. Retrying could create two drafts. Use an operation identifier and a destination that recognizes completed requests, or check the previous result before repeating.
A checkpoint records progress. It cannot undo a delivered message. Separate read retries from write recovery. Decide what the user sees when the action outcome remains uncertain.
Set a maximum tool-call count, timeout and usage budget. These are application choices. On reaching a limit, return completed work and the unresolved step.
Architecture review checklist
- Draw the normal path and a failure path.
- Locate permission and argument checks before actions.
- Define restart state and duplicate prevention.
- Identify provider and network boundaries.
- Show how people inspect evidence, approve and stop work.
Use that drawing when comparing frameworks. It exposes responsibilities a feature list may leave unclear.
Tools, MCP and integration boundaries ↗
Understand what a tool exposes, how MCP connects it and where your application must enforce access.
Prepared with AI assistance and checked against the linked documentation. Examples and numerical limits are illustrative unless stated otherwise. These guides do not report independent product testing. Check current documentation before choosing a tool.