Chapter 3 of 6
Confirm these prerequisites:
- A governed nonproduction agent is ready for authorized testing: the platform inventory identifies immutable baseline and remediated versions, the gateway and tool owners confirm the read-only path and blocked prohibited write, and the quality owner retrieves a passing release-gate result. (The platform, private-networking, model-governance, agent, access-boundary, gateway, inventory, MCP security, and evaluation controls establish these prerequisites.)
- The approved change record names the exact project, agent, immutable versions, attack scope, synthetic-data boundary, run window, stop contact, and authorization reference.
- The security owner confirms cloud red-teaming support for the project region on the run date.
- The project managed identity and operator have Foundry User on the exact Foundry project.
- The project has the approved judge model and red-teaming budget.
- Defender for Cloud AI services protection and the approved SOC route are operating.
- The stable endpoint stays on the previously approved version. Prohibited writes remain absent or independently denied.
Implementation files#
| Type | File | Consumer |
|---|---|---|
| Runtime | artifacts/red-team/attack-plan.json | The red-team runner, comparison process, and security owner |
| Runtime | artifacts/defender/ai-alert-hunt.kql | The SOC analyst |
| Record | artifacts/operations/soc-triage-playbook.md | The SOC analyst and incident commander |