Hybrid validation architectures are increasingly common in enterprise D365 deployments, and the tension you’re describing between adaptability and auditability is the core design problem worth unpacking.
Architectural Pattern: Layered Validation with Explicit Handoff
The practical approach most teams land on is a two-tier validation pipeline:
- Tier 1 — Synchronous plugin chain handles deterministic rules (field requirements, stage-gate logic, discount ceiling enforcement). These fire pre-operation, block on failure, and log to a structured audit entity.
- Tier 2 — Async agentic validation runs post-create/update via Power Automate + Azure AI (or a custom connector to your model endpoint). It flags anomalies, writes a scored recommendation back to the Opportunity, and routes edge cases to a review queue — but does not block the transaction.
This separation preserves explainability for compliance: every hard block is traceable to a deterministic rule, while AI signals are advisory and auditable separately.
Plugin Skeleton (C# / Dataverse plug-in paradigm)
// Tier 1: Synchronous pre-validation plugin
public class OpportunityValidationPlugin : IPlugin
{
public void Execute(IServiceProvider serviceProvider)
{
var context = (IPluginExecutionContext)serviceProvider
.GetService(typeof(IPluginExecutionContext));
var target = (Entity)context.InputParameters["Target"];
// Hard rule: discount ceiling
if (target.Contains("discountpercentage"))
{
decimal discount = target.GetAttributeValue<decimal>("discountpercentage");
if (discount > 40m)
throw new InvalidPluginExecutionException(
PluginHttpStatusCode.BadRequest,
"DISC_CEILING_001: Discount exceeds policy maximum of 40%.");
}
// Write deterministic audit record
// Log: rule ID, entity ID, user, timestamp, outcome
}
}
Agentic Layer Audit Contract
Every AI validation call must write a structured ai_validationlog record containing: model version, input feature snapshot, confidence score, decision rationale (feature importance or rule-equivalent string), and reviewer action if overridden. This satisfies audit requirements because the decision artifact is persisted, not just the outcome.
Debug Approach
Use Plugin Trace Log (Settings → Customization → Plugin Trace Log) for Tier 1. For Tier 2, instrument your Azure Function or Flow with Application Insights and correlate on the Opportunity regardingobjectid. Replaying a suspicious validation decision means you have the feature snapshot to feed back into the model offline.
Rollback
Tier 1 plugins are registered via Plugin Registration Tool — maintain versioned assemblies in source control and keep the prior assembly registered as an inactive step for fast rollback. Tier 2 is stateless async; disable the triggering Flow step or swap the connector endpoint. Neither rollback path requires a Dataverse solution reimport if you stage this correctly.
On Explainability for Business Users
Surface the ai_validationlog.rationale field on the Opportunity form as a read-only control visible to managers. Frame AI output as signals requiring human confirmation rather than autonomous blocks — this sidesteps most compliance objections and keeps your audit trail clean. Verify that your chosen AI model supports extractable feature importance in your version; some Azure OpenAI configurations require additional instrumentation for this.
The brittleness you’re seeing in pure rule engines at complex pattern detection is real, but the answer isn’t replacing rules — it’s giving them an adaptive signal layer they can escalate to.
This draft is based on general Microsoft Dynamics 365 Sales knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.