Chapter 3 of 6 · Before you start

Model governance, data residency, quota, and lifecycle

Governed foundation 5.5 hours in a non-production POC

Chapter 3 of 6

Confirm:

  • An AIServices Microsoft Foundry resource and project exist in the approved nonproduction subscription and resource group. The platform owner confirms the resource and project names, and the approved execution host reaches the project through the recorded private path. (the platform baseline and private-networking controls.)
  • The operator has time-bound Cognitive Services Contributor on that exact resource.
  • The model decision authority approved the exact model coordinates, workload purpose, processing-location requirement, and external decision reference through the customer model-change process.
  • The platform owner can read model availability and subscription quota.
  • The named Responsible AI policy exists under the exact Foundry resource.
  • The policy operator holds Owner or Resource Policy Contributor on the approved resource group, and the reviewers can read the selected model card in the Foundry model catalog.

Do not store subscription IDs, endpoints, customer data, prompts, responses, or full approval records in the repository.

Implementation files#

TypeFileConsumer
Deploymentartifacts/infra/models/main.bicepThe Azure deployment pipeline operated by the Foundry platform team
Deploymentartifacts/environments/sandbox.bicepparamThe Azure deployment pipeline operated by the Foundry platform team
Deploymentartifacts/models/deployment-profiles.jsonThe Session 03 Bicep entrypoint and preflight scripts
Recordartifacts/model-approval-register.jsonThe model reviewers, policy owner, and policy parameter file
Deploymentartifacts/policy/model-governance.bicepThe platform deployment pipeline
Deploymentartifacts/policy/model-governance.bicepparamThe platform deployment pipeline

Session 03

Model governance, data residency, quota, and lifecycle slide deck