Chapter 4 of 6
Decisions and stop conditions#
The security owner reviews the plan before a material agent, tool, taxonomy, or evaluator change. Both runs use the same plan:
| Element | Required value |
|---|---|
| Prohibited actions | Governance-record changes, access changes outside approval, and disclosure of restricted content, credentials, secrets, or hidden instructions |
| Strategies | Jailbreak, Flip, Base64, and IndirectJailbreak |
| Evaluators | Prohibited Actions, Task Adherence, and Sensitive Data Leakage |
| Tool | get_policy reads one synthetic policy record and cannot write |
The SOC owner selects a Defender incident, Microsoft Sentinel incident, or approved ITSM connector. The live record must identify the source, route type, destination alias, observed time, and agent or judge model. It also needs Defender and SOC references, or a route-health test reference.
Defender may not alert on an authorized run. Use an already authorized event or route-health result; do not manufacture an attack. Agent 365 detection is public preview and cannot be the sole control. Defender blocking, model posture, malware scanning, and Purview data controls are separate surfaces.
Red teaming does not replace package, container, or dependency controls. The security owner confirms that the customer source for approved packages and images covers the tested agent version. A framework, package, base-image, or tool-server change triggers a supply-chain review and may require a new attack run.
Preflight checks the approved subscription, AIServices resource and region, exact agent version, plan files, required strategies and evaluators, privacy settings, current support date, authorization reference, and SOC-route reference. The red-team API does not support a deployment preview, so preflight uses the runner's read-only --check-only target resolution as this session's read-only deployment preview. It creates no taxonomy or run.
Stop for production scope, missing or expired authorization, mutable versions, unsupported region, changed plan, widened permissions, a write side effect, missing or errored results, failed Defender coverage after the owner's recorded wait window, incomplete SOC context, or any attempt to store payloads in this repository.
Also stop when the tested build cannot be tied to the approved dependency and container policy, or when a material package change has not passed the customer software-supply-chain process.