Chapter 3 of 6 · Before you start

Governed Microsoft Foundry agent baseline

Governed foundation 2.5 hours in a non-production POC

Chapter 3 of 6

Confirm:

  • The approved nonproduction AIServices Foundry resource and project are reachable from the approved execution host. The platform owner confirms the recorded subscription, resource group, resource, project, and private path. (The platform baseline, private-networking, and model-governance controls establish these prerequisites.)
  • The recorded model approval matches a live ARM child model deployment in Succeeded state. The selected region and model support prompt agents and OpenAPI tools. (Model governance and lifecycle guide.)
  • The operator has time-bound Foundry User, role ID 53ca6127-db72-4b80-b1b0-d745d6d5456d, on the exact Foundry project.
  • The downstream API accepts a policy ID over HTTPS and supports managed identity. Its authorization owner has assigned the exact read role to the Foundry project managed identity at the downstream API resource scope. A custom role must name the action required by get_policy.
  • The named RAI policy exists. Application Insights is connected to the project. The approved operations group has Log Analytics Reader on that Application Insights resource and, for protected tables, Privileged Monitoring Data Reader. The operations owner has approved trace access, retention, regional handling, sampling, cost, and sensitive-content rules.

Keep endpoints, credentials, access tokens, prompts, responses, trace exports, and customer data out of the repository.

Implementation files#

TypeFileConsumer
Deploymentartifacts/agents/policy-assistant/agent.jsonThe Session 04 agent deployment scripts
Deploymentartifacts/agents/policy-assistant/instructions.mdThe Microsoft Foundry prompt-agent version
Deploymentartifacts/agents/policy-assistant/tool-manifest.jsonThe Session 04 agent deployment scripts

Session 04

Governed Microsoft Foundry agent baseline slide deck