Chapter 4 of 6
Decisions and stop conditions#
Decide four things before deployment:
- Scope, ownership, and access. Name the approved subscription and exact resource group. The cloud platform owner approves the deployment operator's two time-bound assignments through the customer access process, then removes them after confirmation. Confirm who owns the baseline, policy assignment, inventory record, exemptions, and promotion decision.
- Network pattern. Select
public,public-private-inbound, orbyo-vnet. The choice has no default. Forbyo-vnet, approve the delegated subnet, private-endpoint subnet, route, firewall next hop, and network owner. - Governance values. Set the approved regions and the required ownership, classification, criticality, cost, and expiry tags.
- Policy promotion. Name the cloud platform owner who reviews Policy Insights and the change authority that may approve
Default.
| Gate | Continue when | Stop when |
|---|---|---|
| Deployment scope | Azure CLI targets the approved subscription and resource group | The scope is wrong, shared without approval, or marked for another implementation |
| Deployment preview | The preview contains the documented baseline and optional network foundation | It changes unrelated resources or uses unresolved values |
| Policy definition | Both built-ins are current and still match the intended location and tag checks | A definition is unavailable, deprecated, or has changed behavior |
| Promotion | Policy Insights is current, exemptions are understood, restore ownership is ready, and enforcement is approved | Results are stale or either owner has not approved the change |
Keep the Application Insights connection on the stable ApiKey path. Stop if the selected network pattern, approved region, policy behavior, or tracing authentication changes. Recheck the sources in session.yaml before continuing.