Chapter 6 of 6
Confirm the result#
Intended path#
After propagation, run the labelled synthetic interaction through the approved path. Block stops the matched interaction. Audit allows it and records the match. Inspect the DLP result, scoped audit activity, and generated-content label behavior in Purview.
Blocked or failure path#
Repeat the interaction with the approved excluded-user alias. Keep the agent, source, label, direction, location, and action unchanged. The policy must not report a match.
Stop if the policy reaches a wider scope, the action differs, the output is treated as protected without the chosen output control, the excluded user finds the agent, the included member cannot find it, or audit activity remains absent after the recorded ingestion allowance.
Delivery-owner checkpoint#
The delivery owner observes the propagation wait, included-user availability, excluded-user denial, intended policy result, non-match, and scoped audit activity. Keep the policy in simulation or disable it if a check fails. Record the result in Purview and the approved change system.
After implementation#
| What remains | Owner |
|---|---|
| DLP policy, simulation and enablement state, findings, and change history | Purview operator and Agent 365 owner |
| Label, encryption rights, and generated-content control | Information protection owner |
| Agent Registry installation and deployment contract | Microsoft 365 administrator |
| Product-boundary ownership record | Data governance owner |
| Published agent and native runtime controls | Source-platform owner |
| Payload-free query definition and audit operation | Audit owner |
Conditional Foundry Data Security rule and processContent integration | Foundry platform owner, Purview operator, and application developer |
Restore through the approved Purview and Microsoft 365 change paths:
- Return the policy to
TestWithNotifications. - Disable it after reviewing dependencies.
- Remove the scoped agent installation and group assignment before deleting a policy created for this session.
- Remove label rights or source sharing after the data owner confirms that no Agent 365 dependency remains.
Do not delete a reused label, audit records, or source data. For a Foundry agent, use its separate dependency review to change Foundry coverage or billing. The data governance owner reviews coverage-handoff.md quarterly and after an owner or product-boundary change.