M365 COMMUNITY DAYS NYC · JULY 31, 2026

From vibes
to verifiable.

Open agents are thrilling. Governed agents are useful. Follow the evidence trail from OpenClaw and Microsoft Scout to Tula, Wren, My Aria, Waza, and an operational trust bridge.

Speaker
Paul Swider
Venue
Microsoft · 11 Times Square
Format
50 minutes · 3 live demos
M365 Community Days New York City 2026 event artwork
Community-powered. Evidence-driven.

THE THESIS

If it acts, it needs evidence.

Inspect Test Constrain Audit

THE STORY · THREE ACTS

Same substrate.
Different stakes.

Scout handles the coordination surface of work. Tula handles the deeply personal surface of health. OpenClaw makes the shared runtime visible—and visibility lets us ask better trust questions.

01

WORKFORCE AGENT

Microsoft Scout

An always-on personal agent built on OpenClaw and Work IQ, acting across Microsoft 365 with enterprise identity, access control, policy, and human signoff.

  • Work IQ
  • Identity
  • Approval
  • Policy
Open Scout docs ↗
02

PATIENT AGENT

Tula

An open-source health skill layer for OpenClaw: private workspace, explicit behavioral contracts, human handoffs, and an evaluation standard designed around real failure modes.

  • Skills
  • FHIR
  • Privacy
  • Evals
Explore Tula on GitHub ↗

The feedback loop matters. Microsoft says it is contributing policy conformance directly upstream to OpenClaw. Enterprise governance can strengthen the open substrate everyone builds on.

Read the announcement ↗

THE VERIFIABLE STACK

Follow one action all the way down.

Tap a layer. The question changes, but the requirement does not: preserve enough evidence to explain what happened.

QUESTION 01

What did the agent know?

Context determines the decision surface. Identify the tenant, person, files, messages, record, and time window that shaped the action.

Proof to keep Context references + identity

WREN · THE HEALTH-DATA BRIDGE

Patient-authorized data.
A relay that cannot read it.

Wren is Tula's MIT-licensed SMART on FHIR records relay. It wraps the records connection as an OpenClaw skill while preserving a hard, inspectable boundary around the patient record.

Inspect Wren ↗
  1. 01Patientchooses provider
  2. 02Epic / FHIRauthorizes access
  3. 03Wrenrelays ciphertext
  4. 04Tula skilldecrypts locally
  5. 05My Ariamakes it visible

ECDH P-256 + AES-256-GCM · SMART on FHIR · operator-controlled infrastructure

MY ARIA · THE HUMAN SURFACE

The record should answer human questions.

My Aria is the patient-facing visual layer for Tula's longitudinal record: results, medications, messages, appointments, devices, and agent conversations in one coherent experience.

Current public screenshots use synthetic fixtures. My Aria is not affiliated with Epic or MyChart and is not a medical device.

Synthetic My Aria patient dashboard
One longitudinal view
Synthetic My Aria AI chats screen
Grounded conversations
Synthetic My Aria home devices screen
Signals beyond the portal
Tula dual-spec skill and evaluation architecture

WAZA · EXECUTABLE EVIDENCE

A passing demo is not a release gate.

Waza checks the structure and behavior of agent skills. Tula's Patient Agent Eval Standard currently covers 78 tasks across eight skills plus composition.

PositiveHandoffPHI boundary AdversarialGolden
$ waza check skills/prep-my-visit
$ waza run evals/prep-my-visit/eval.yaml -v
Explore Microsoft Waza ↗

MELLOW MUSHROOM · THE TRUST BRIDGE

Governance becomes real when you can point to it.

The synthetic Trust Bridge demo makes consent, attention, policy, and audit visible across workforce and patient agents.

IdentityConsentPolicy AttentionAudit
Open the synthetic demo ↗
SYNTHETIC DEMO
Synthetic Mellow Mushroom Trust Bridge governance dashboard

THREE DEMOS · ONE QUESTION

Where is the evidence?

LIVE DEMO 01

Follow the action and the controls.

Trace one Microsoft 365 task from context to tool boundary, approval, and evidence.

  1. Name the context Scout is using.
  2. Follow the action into the runtime and tool boundary.
  3. Pause on the sensitive-action approval.
  4. Show what an administrator could reconstruct.
“The result is the least interesting part. Who acted, with which context, under which permission?”
Open the complete demo runbook →

FIELD NOTES

Steal these presenter moves.

01

Narrate the boundary.

Explain why data or authority is crossing—not every click.

02

Show one refusal.

A good negative test often explains the safety model best.

03

Name the status.

Say synthetic, prototype, phase 1, or in progress when that is true.

04

End with evidence.

Close every demo on a trace, result, approval, or decision record.

PRIMARY SOURCES

Read the source.
Fork the pattern.

Every important claim in this story maps to product documentation, an open repository, or an explicitly labeled synthetic demo.

THE TAKEAWAY

Build agents you can interrogate after they act.