# Teams app registration for a daimon deployment.
#
# The full walkthrough, portal by portal, with troubleshooting, is in
# docs/self-hosting.md under "Microsoft Teams (optional)". Below is the short
# version.
#
# Teams has no manifest-paste equivalent of Slack's app creator that also
# provisions the Entra side, so registration is two artifacts: an Entra app
# registration (what the adapter authenticates as) and a Teams app package
# (a zip with manifest.json + icons, installed by a user or admin).
#
# 1. Entra portal → App registrations → New registration:
#      - Accounts in this organizational directory only (single tenant).
#      - Certificates & secrets → New client secret → DAIMON_TEAMS__CLIENT_SECRET.
#      - Application (client) ID → DAIMON_TEAMS__CLIENT_ID.
#      - Directory (tenant) ID → DAIMON_TEAMS__TENANT_ID.
#    No API permissions are required: the bot calls the Bot Framework REST
#    API, which authorizes on the app registration itself, and reads channel
#    messages through Microsoft Graph under the resource-specific consent
#    below, which a team owner grants when installing the app in a team.
#    Channel files optionally need the Graph application permission
#    Sites.Selected plus a grant per team site (docs/teams.md); this
#    manifest stays the same.
# 2. Azure portal → Create a resource → Azure Bot:
#      - Type of App: Single Tenant; point it at the registration above.
#      - Configuration → Messaging endpoint:
#          https://DAIMON_HOST/api/messages
#        DAIMON_HOST must be a public HTTPS host that reaches the adapter's
#        listener (DAIMON_TEAMS__PORT, default 3978) — a tunnel or reverse
#        proxy in front of the `teams` compose service.
#      - Channels → add Microsoft Teams.
# 3. Build the Teams app package from the manifest below: manifest.json,
#    color.png (192×192) and outline.png (32×32, white on transparent),
#    zipped at the top level. Then upload it in the Teams admin center or
#    sideload it.
#
# The adapter provisions the tenant for DAIMON_TEAMS__TENANT_ID at boot; there
# is no install flow. The bot answers in 1:1 chat and when @mentioned in a
# channel, replaying the thread it is in; group chats are refused, so the
# manifest does not offer them.
#
# Private and shared channels: `supportsChannelFeatures: tier1` lets the app
# be added to them (manifest 1.25 or later; never `supportedChannelTypes`,
# which blocks the upload there). Installing the app in a team does not add
# it to these channels: each one's owner adds it from the channel itself.

manifestVersion: "1.25"
id: "${DAIMON_TEAMS__CLIENT_ID}"        # must equal the Entra app id
version: "0.4.1"                       # bump on every change, then re-upload
supportsChannelFeatures: tier1          # private and shared channels (see above)
developer:
  name: daimon
  websiteUrl: https://DAIMON_HOST
  privacyUrl: https://github.com/pymc-labs/daimon/blob/main/PRIVACY.md  # or DAIMON_PRIVACY_POLICY_URL
  termsOfUseUrl: https://DAIMON_HOST/terms  # your own terms page; daimon serves none
name:
  short: daimon
  full: daimon
description:
  short: Data-science agent that writes and runs code, fits models, and answers in chat.
  full: Data-science agent that writes and runs code, fits models, and delivers answers in a chat or channel thread.
icons:
  outline: outline.png
  color: color.png
accentColor: "#0b110e"
bots:
  - botId: "${DAIMON_TEAMS__CLIENT_ID}"
    scopes:
      - personal
      - team                            # channels: answers when @mentioned
    commandLists:
      - scopes:
          - personal
        commands:
          - title: help
            description: List the commands.
          - title: new
            description: Start a fresh conversation.
          - title: setup
            description: See your agents and who answers where.
          - title: routines
            description: Show and manage scheduled routines.
          - title: memory
            description: Show what the agent remembers.
          - title: privacy
            description: See, export or delete your data.
          - title: billing
            description: Usage this month and top-ups.
          - title: support                 # answered only when human support is configured
            description: Ask a person for help.
    supportsFiles: true                 # files shared in 1:1 chats, file consent cards
    isNotificationOnly: false
permissions:
  - identity
  - messageTeamMembers
validDomains:
  - DAIMON_HOST                         # token.botframework.com is implicit
webApplicationInfo:
  id: "${DAIMON_TEAMS__CLIENT_ID}"
  resource: https://RscBasedStoreApp    # unused by RSC, but must be set
authorization:
  permissions:
    resourceSpecific:
      # Read the channel threads the bot is mentioned in, and their images.
      - name: ChannelMessage.Read.Group
        type: Application
      # List the team's owners, for channel admin grants that name the team.
      - name: TeamMember.Read.Group
        type: Application
      # List a channel's members and their home tenants, to tell people from
      # another organisation (shared channels' external participants, guests).
      - name: ChannelMember.Read.Group
        type: Application
