PowerShell UserGroup InnSalzach Meeting – 7th October 2026

• 3 min read
Share:

PowerShell UserGroup Inn-Salzach LINK TO JOIN THE MEETUP: https://app.gather.town/events/KVZL0-_nQn-S4bUPT9s6

Join us for an exciting PowerShell UserGroup InnSalzach session where we dive into the art of scripting! Topic: The Agentic Operating Model, Part 2: Agents That Reach Out, Ask First, Remember, and Hand Off Speaker: Raimund Andree Date: 7th October 2026 Once an Agent works reliably inside one repository, the next questions follow quickly. How does it reach systems beyond the repository? Who questions an idea before the Agent acts on it? What does it still know after the session ends or its context is compacted? And who checks its work? This second session on the Agentic Operating Model (AOM) is built around these four questions. Attending Part 1 helps but is not required. One running example, shown live in VS Code with GitHub Copilot, connects all four: a new Tool for a PowerShell MCP server, taken from a vague idea to a reviewed commit.

Reach out: MCP servers. The Model Context Protocol (MCP) is the open standard that connects Agents to Tools and data. We walk through a complete MCP server written as one PowerShell script without an SDK: JSON-RPC over stdio, tools/list, and tools/call. Once the protocol stops being magic, the questions that matter become visible: under whose identity the server runs, which Tools need confirmation, and why every Tool result is untrusted input.

Ask first: questionnaires and Grill-Me. Agents act eagerly on vague prompts and tend to agree with you. Questionnaires and the Grill-Me pattern reverse the direction: the Agent interviews you about purpose, edge cases, failure modes, security, and rollback, challenging your assumptions until the idea becomes a Design Concept you can sign off on. We also look at why the interview worked reliably only after it moved from a Skill into its own Custom agent.

Remember: the Memory Bank, revisited. The practice has changed considerably this year. VS Code and other Agent hosts now ship built-in memory, long sessions are compacted mid-task, and reading every Memory Bank file at every session start no longer scales. We cover routed loading through an index, evals that show whether routing drops context a task needs, hooks that save state before compaction, and why Agents should pass state through files rather than through the conversation.

Hand off: from Software Engineer to Security Reviewer and back. Custom agents can pass work along a chain: design, implement, review, and document. Automating that chain is easy; bounding it is not. A real run in which two Agents bounced the same change between them for fifteen round trips shows why a loop needs a structural limit rather than one more instruction, where a human click belongs, and how a Pester test can check the handoff graph.

PowerShell remains the demonstration medium, not the subject: the same practices apply to infrastructure, runbooks, research, and correspondence.

Learning Outcomes: After the session, participants will be able to:

  • Explain how an MCP server works at the protocol level and assess the identity, privilege, and untrusted-input risks it introduces.
  • Use questionnaires and the Grill-Me pattern to turn a vague idea into a Design Concept before any work starts.
  • Describe how Memory Bank practice has changed and decide what belongs in a versioned Memory Bank and what in an Agent host’s built-in memory.
  • Design Agent handoff chains with explicit gates: what to automate, where a human decides, and how to keep a review loop bounded.
  • Choose between an Instruction file, a Skill, a Custom agent, and an MCP server for a recurring need.