Chapter 4 of 6 · Decisions and boundaries

Azure API Center and the AI/MCP inventory

Runtime assurance 3 hours in a non-production POC

Chapter 4 of 6

Decisions and stop conditions#

Complete sandbox.json and agent-api-definition.json. Resolve every __REQUIRED_*__ value.

DecisionContinue whenStop when
Inventory and APIM scopeAPI Center is the approved inventory, and every imported API has a metadata ownerAnother inventory is authoritative, or the APIM link would import ownerless assets
Plan and regionThe live provider advertises the region, and Free or Standard is approvedThe region, support position, eligibility, or cost is unresolved
AccessThe deployment operator has Contributor on the API Center resource group and User Access Administrator on the exact APIM serviceEither assignment is broader than approved, or the API Center identity would receive APIM write access
Deployment previewwhat-if changes the marked API Center scope and exact reader assignmentIt replaces or removes unrelated resources, targets another APIM instance, or broadens the role assignment
SynchronizationThe source is healthy and the APIM gateway API appears onceInitial sync is pending or failed; do not create a duplicate API
MCP serverThe endpoint is approved HTTPS Streamable HTTP, read-only, and ownedIt uses stdio, embeds credentials, permits writes, or lacks a runtime owner

Every in-scope entry needs these properties:

PropertyRequired decision
Business ownerAccountable role or group
Technical ownerOperating role or group
AI asset kindai-api, agent-api, or mcp-server
Data classificationpublic, internal, confidential, or restricted
Permitted consumersApproved groups or workload classes
Model/providerProvider, or not-applicable for a non-model MCP server
Residency profileApproved processing and storage boundary
Risk tierlow, moderate, high, or critical
Evaluation results URLOwned evaluation record or backlog
Last review and expiryISO dates, with expiry after review
Implementation session07-api-center-ai-mcp-inventory

The API program owner defines the schema. Business owners approve consumers and lifecycle. Technical owners maintain runtime locations and review dates. Data and risk owners maintain classification, residency, risk, and evaluation destinations.

At expiry, the technical owner has one business day to renew after review, retire and remove the entry from discovery, or quarantine it from approved use.

Session 07

Azure API Center and the AI/MCP inventory slide deck