Chapter 3 of 6
Confirm:
- An approved nonproduction MCP foundation is in place. It includes a pinned Foundry policy assistant, an APIM-managed
GEToperation over synthetic policy records with no side effects, the private network paths required by the approved topology, and an API Center metadata update process. The gateway owner checks thatGETreturns approved fields without changing state; the platform, network, and inventory owners confirm the remaining resources and configurations. (The private-networking, governed-agent, APIM, and API Center inventory controls establish these prerequisites.) - The Foundry policy assistant is pinned to a known version.
- The approved APIM service has a system-assigned identity, an Application Insights logger, a supported tier, and no workspace.
- The deployment operator has time-bound Contributor on the exact APIM resource group.
- The agent operator has Foundry User on the exact Foundry project.
- The existing APIM operation uses
GET, validatespolicyId, returns approved fields, and does not change state. - Approved-read and adversarial records exist in the synthetic data set.
- The Foundry agent identity has the approved MCP app role.
- The APIM identity has the approved backend role definition at the exact backend scope. That role contains only the Actions or DataActions needed by
get_policy. - Global and MCP diagnostics set request and response body logging to zero bytes.
- Release, data, security, tool, identity, APIM, and API program owners are named.
- The customer permits
2025-09-01-previewfor this nonproduction APIM deployment.
Implementation files#
| Type | File | Consumer |
|---|---|---|
| Deployment | artifacts/apim/main.bicep | The Session 08 APIM deployment scripts |
| Deployment | artifacts/apim/policies/mcp-policy.xml | The API Management MCP runtime |
| Deployment | artifacts/environments/sandbox.json | The Session 08 preflight and deployment scripts |
| Deployment | artifacts/governance/agent-mcp-binding.json | The Foundry agent release owner |
| Record | artifacts/governance/security-evaluation.md | The security owner running the Foundry candidate-version checks |
| Record | artifacts/governance/threat-model.md | The security and identity owners |
| Runtime | artifacts/operations/mcp-traffic.kql | The APIM operations owner |