Chapter 4 of 6
Decisions and stop conditions#
Resolve every __REQUIRED_*__ value in the design record, gateway-control.json, and sandbox.json. Use an endpoint reference in the design record, never the live endpoint.
Set recordStatus to ready-for-implementation when no readiness gap is open. Each gap needs an owner and a resolution action. The record must name foundry-agent-service and the policy-assistant-responses variant. Its APIM instance must match sandbox.json.
| Control | Approved value |
|---|---|
| Tokens per minute per APIM subscription | 20,000 |
| Daily token quota per APIM subscription | 500,000 |
| Request body limit | 65,536 bytes |
| Backend response-header timeout | 120 seconds |
| Retry for 429/5xx | 1 |
| Circuit breaker | 5 errors in 1 minute; open for 1 minute |
APIM enables Prompt Shields and checks Hate, SelfHarm, Sexual, and Violence at threshold 4. It logs zero request and response body bytes and no client IP. Keep the secondary backend disabled.
Stop before deployment when the design record is incomplete, a resource differs from approved inputs, a required role or workload subscription is absent, Content Safety uses a key, or ARM what-if changes APIM itself or an unrelated resource. Stop if a retry could repeat a consequential action. Do not place live endpoint or customer data in source control.