Trust layer: access, guardrails, and compliance
Production agents need more than prompts. They need user identity, scoped access,
policy-aware orchestration, compliance controls, and an audit trace that shows what
happened, why it happened, and who approved it when approval was required.
Model guardrails
Content filters, Azure AI Content Safety, Prompt Shields, denied topics, PII
handling, grounding rules, and protected-material checks.
Data controls
Microsoft Purview, sensitivity labels, DLP policies, encryption, retention,
data residency, and approved data-source boundaries.
Access control
Microsoft Entra ID, delegated permissions, native RBAC, scoped connectors, and
no shared high-privilege service identity for user actions.
Audit trace
Microsoft Foundry evaluations, monitoring, and traces for prompts, sources, tool
calls, approvals, responses, quality, latency, cost, and exceptions.
Compliance policy
Human-in-the-loop gates, autonomy limits, approval workflows, responsible AI review,
audit evidence, and escalation rules for sensitive actions.