Chapter 3 of 6 · Before you start

Observability, cost, and operational controls

Runtime assurance 3.5 hours in a non-production POC

Chapter 3 of 6

Confirm these requirements:

  • An approved governed runtime can be inspected: the platform owner identifies the immutable agent and project, the gateway owner identifies the versioned APIM policy and tool path, the quality owner can retrieve the current evaluation result, and the security owner can retrieve the payload-free adversarial result and Defender route check. (The governed-agent, APIM, MCP security, threat-defense, and observability controls establish these prerequisites.)
  • The nonproduction policy assistant and APIM route support an approved read-only request and a separate handled failure for a nonexistent synthetic policy.
  • A workspace-based Application Insights component, its Log Analytics workspace, an action group, and an approved retention boundary exist.
  • Application instrumentation is deployed. The customer-owned APIM policy already preserves W3C context and emits bounded token metrics.
  • The Foundry agent type is recorded. Prompt and hosted agent tracing is generally available. Workflow and external agent tracing remains preview and requires an approved nonproduction preview-use decision.
  • Baseline telemetry has been reviewed before owners set alert thresholds.
  • The observability, application, gateway, tool, AI quality, security operations, data-protection, cost, and service owners can make their required decisions.

When prerequisite sessions were implemented elsewhere, verify:

ControlRequired stateOwner check
RuntimeThe deployment record names the Foundry project, immutable agent version, Microsoft Entra agent identity, network path, versioned APIM policy, tool identities and scopes, and data-policy assignmentPlatform, gateway, tool, and data owners confirm that one approved read-only request reaches the listed backend and tool
TracingOpenTelemetry and APIM propagate W3C traceparent and one non-sensitive correlation IDObservability owner finds joined gateway, agent, model, and tool spans with separate results
EvaluationThe evaluation definition, threshold policy, and approved aggregate result name the deployed versionAI quality owner gets the recorded pass or block result from the release gate
SecurityThe payload-free adversarial summary, Defender onboarding state, and security-event route name the protected versionSecurity operations finds blocked prohibited actions and one expected signal in the listed Defender or SOC record

The deployment operator needs:

  • Monitoring Contributor at the exact deployment resource-group scope;
  • Log Analytics Reader at the exact workspace scope;
  • Monitoring Reader at the exact Application Insights and action-group resource scopes when either resource is outside the deployment group; and
  • Cost Management Contributor at the exact subscription scope.

Human access lasts through preflight, deployment, and confirmation. Remove or expire it through the approved access process afterward.

Implementation files#

TypeFileConsumer
Runtimeartifacts/telemetry/telemetry-contract.jsonApplication developers, the observability owner, and preflight scripts
Deploymentartifacts/infra/main.bicepThe Azure deployment pipeline
Deploymentartifacts/infra/main.bicepparamThe Azure deployment pipeline
Deploymentartifacts/monitoring/workbook.jsonOperators and the workbook deployment
Runtimeartifacts/queries/request-error-rate-alert.kqlThe request-error scheduled-query alert
Runtimeartifacts/queries/tool-failure-alert.kqlThe tool-failure scheduled-query alert
Runtimeartifacts/queries/quality-safety-alert.kqlThe quality and safety scheduled-query alert
Deploymentartifacts/cost/budget.bicepThe subscription deployment pipeline and cost owner
Deploymentartifacts/cost/budget.bicepparamThe subscription deployment pipeline
Recordartifacts/cost/cost-allocation.mdThe cost owner
Recordartifacts/governance/data-retention-decision.mdThe observability owner
Recordartifacts/governance/prompt-response-logging-decision.mdThe privacy and observability owners
Recordartifacts/operations/incident-runbook.mdThe incident commander and service operators

Session 11

Observability, cost, and operational controls slide deck