USE CASES / AZURE

Connect without handing over a standing key.

Azure connection uses a short-lived bootstrap session rather than a long-lived credential. The session is orchestrated, persisted while it is needed, and swept when it is not — so the onboarding path does not leave a permanent key behind.

Short-lived bootstrap credentials Azure AI account discovery Explicit deprovision path Verified against a live Azure tenant
CONNECT WITHOUT HANDING OVER A STANDING KEY Bootstrap session opened short-lived, not a standing key 01 Read-only discovery AI and Cognitive Services accounts in scope 02 Mode recorded explicitly persisted, and validated against the credential 03 Session swept a sweeper reclaims it, so nothing accumulates 04 Deprovision a first-class path, not the absence of a record 05 Connection and discovery are not enforcement. No Azure-native inbound point equivalent to Bedrock is claimed.

A short-lived bootstrap session rather than a long-lived credential, so onboarding does not leave a permanent key behind — and a sweeper reclaims the session so the temporary path does not accumulate.

no standing keyread-only discoveryconnection is not enforcement

CONNECTION MODEL

How the subscription is attached.

01
A bootstrap session is openedA temporary connection session is created and persisted, orchestrated through a deployment against your subscription rather than a credential paste.
02
Discovery runs read-onlyAzure AI and Cognitive Services accounts in scope are enumerated through the Azure SDK, so the inventory comes from the platform's own API rather than from a survey.
03
The mode is recorded explicitlyThe connection mode is persisted alongside the credential shape, and a mismatch between the two is rejected rather than stored — so the console cannot label a connection production-safe when it is not.
04
The session is sweptA sweeper reclaims bootstrap sessions, so the temporary credential path does not accumulate.
05
Deprovision is a first-class pathDisconnecting is an explicit operation with its own handling, not the absence of a connection record.

ENFORCEMENT

Where the decision goes on Azure.

Azure OpenAI proxy in path, not alongside. The deployment endpoint is swapped to GovernorAI, so a model call reaches Azure only on an allow. Anything that is not an allow resolves to a denial rather than an unshaped forward. ENFORCEMENT POINT 01 Azure OpenAI proxy in path, not alongside Workload calls the deployment GovernorAI decides, then forwards Allow reaches Azure  /  deny 403 Keys are never stored
LLM gateway Portkey or LiteLLM fronts the call If a gateway such as Portkey or LiteLLM fronts the model call, GovernorAI registers as a guardrail on that gateway and governs the call itself. ENFORCEMENT POINT 02 LLM gateway Portkey or LiteLLM fronts the call Workload calls the gateway GovernorAI registered as a guardrail The model call itself is governed Governs the model call
SDK no gateway in front of it Where the workload is yours to instrument and no gateway sits in front of it, the SDK consults GovernorAI directly. ENFORCEMENT POINT 03 SDK no gateway in front of it Your workload, instrumented GovernorAI consulted in-process The call proceeds on the verdict Where the code is yours
Enforcement point
Applies to
Azure AI Foundry agents
Agents and threads running in Foundry. GovernorAI is in the path: it opens the thread, posts the message and runs it, and verifies its own shaping before the request leaves. Allow, deny and constrain.
Azure OpenAI proxy
Model calls to an Azure OpenAI deployment. The endpoint is swapped to GovernorAI, so the call is governed in path. Allow and deny.
LLM gateway
If a gateway such as Portkey or LiteLLM fronts the model call, GovernorAI registers as a guardrail on it and governs the call itself.
SDK
Where the workload is yours to instrument and no gateway sits in front of it.
API Management
APIM can call GovernorAI's check endpoint as a policy step: allow returns 200, deny returns 403. GovernorAI ships the endpoint; the policy that calls it is yours to place. This pattern decides, it does not rewrite a body.

Connection and discovery are not enforcement. Attaching a subscription tells you what is running; an enforcement point has to be chosen before anything is governed.

THE FOUNDRY PATH

It re-reads the request before it sends it.

When a policy narrows an outbound call — a field removed, a value constrained — GovernorAI does not assume the change took. It re-reads the exact payload it is about to send to Azure and confirms every change is present in it. If it cannot prove one landed, the call is denied rather than forwarded.

BEFORE THE REQUEST LEAVES Policy shapes it a field is removed GovernorAI re-reads the exact outbound payload VERIFIED Azure Foundry receives the call CANNOT PROVE IT LANDED Denied nothing half-shaped is sent

A half-governed request is worse than a blocked one: it looks governed and is not. The same check reaches inside values Azure carries as encoded text, where a change is easiest to lose quietly.

On this path
What it means
Allow, deny, constrain
The three outcomes this path can carry out. Anything a policy asks for beyond them is reported as unsupported and resolved as a denial — never quietly downgraded to an allow.
Verified end to end
The Foundry round trip and the Azure OpenAI proxy are exercised against a live Azure tenant, not against unit and contract tests alone.
No response shaping
GovernorAI governs the call, not the model's reply. The product publishes this rather than implying coverage it does not have.

WHAT THE CONNECTION SURFACES

What the subscription actually contains.

Discovery reads the platform's own APIs, so the inventory is what Azure reports — not what a team remembered to declare.

Found
Detail
Azure AI accounts
Seventeen kinds of Cognitive Services account across the subscription, including OpenAI, AIServices, ContentSafety and SpeechServices.
Model deployments
Each deployment with its model, version, provisioning state, SKU and capacity — so a policy can target a deployment rather than a subscription.
Foundry projects and agents
Projects, and the agents and assistants inside them, read across four API surfaces so older and current Foundry deployments are both covered.
A permission gap, named
If a role is missing, discovery says so and names the role it needs. It does not report zero agents and let you believe the estate is empty.

Discovery is read-only, and it is not enforcement. Attaching a subscription tells you what is running; an enforcement point has to be chosen before anything is governed.

POLICY INTO AZURE'S OWN CONTROLS

It tells you what Azure cannot enforce.

A policy can be compiled into Azure's content-filter configuration — category thresholds for both prompt and completion, and blocklists from the rules that name specific terms. The compiled output is worth less than what comes with it.

Recorded alongside the output
Why
Where detection is probabilistic
Every category filter is marked as approximate. Azure's classifiers judge likelihood; a GovernorAI deny is a decision. The two are not the same control and the export says so.
Where a rule lost precision
A pattern that had to be reduced to a literal term is recorded as a lossy transformation, naming what narrowed.
What did not map at all
Approvals, transforms, step and duration limits and cost ceilings have no content-filter equivalent. Each is listed as unmapped with the reason, rather than dropped silently.

This is the part a reviewer needs and rarely gets: not the claim that a policy was applied, but a written account of what survived the translation and what did not.

BEFORE IT REACHES THE SUBSCRIPTION

Enforcement decides the call. Something has to decide the agent.

Everything above governs actions an agent is already taking. Assurance is the gate before that: an immutable snapshot of the agent is scored against acceptance bars registered before the run, and the result is a CI/CD exit code, not a dashboard state. An agent that cannot clear the bar does not reach the subscription.

Whether a domain can be measured depends on how your environment is wired, so that is computed per deployment and the missing prerequisite is named. not_assessed is never reported as a pass.

See what each domain needs →

Continue