secureskies
Expertise/02 · Agentic Operations

How much may your AI model
and agent do in your subscription?

An agent that changes infrastructure needs three things an auditor will ask for: its own identity, a policy per call and evidence per step. On the example of a co-engineer we define what it may do alone, what it may only propose and what stays blocked.

FormatPilot · programme · operationsscope per use case
PlatformsAzure · AWSEntra Agent ID · AgentCore
ReferenceAI Act Art. 12 · 14 · 26Art. 25 on changes
OutcomeRole model plus evidence fileper agent, kept current
01 · Model

Seven steps,
one pull request.

The agent never writes to the cloud directly. It reads, plans and opens a pull request; approval and apply run through your existing pipeline in Azure DevOps or GitHub, and the model stays on a private endpoint. Every step has a ring that governs it and an article that requires it.

Step 07 → step 01 · evaluation and trace feed back into the next request↺
01 · Trigger
Request
An alert from Azure Monitor or Grafana, a ticket in ServiceNow, or a person in chat: “Extend the WAF rule for checkout to the new partner IP.”
Ring 05 · Art. 50 notice
02 · Identity
Agent authenticated
Its own agent identity in Microsoft Entra: created from a blueprint, with a sponsor, without credentials of its own — tokens come through federated identity credentials. Acting for a user, it receives that user’s delegated right, which expires. On AWS: AgentCore Identity, one IAM role per agent.
Ring 02
03 · Model
Private endpoint
Azure OpenAI as a Data Zone EU deployment over a private endpoint; “Global” deployments blocked by Azure Policy. On AWS: Bedrock in eu-central-1 over PrivateLink. Prompt, context and response never leave the landing zone.
Ring 01
04 · Tools
Read, then plan
Only tools from the gateway, only with reader rights: Log Analytics (KQL), Resource Graph, reading the repository. No Contributor on the subscription — the agent produces a Terraform change instead.
Ring 03
05 · Pull request
Azure DevOps / GitHub
The agent opens a PR with the changed WAF policy in Terraform, a rationale and a trace ID. The pipeline runs: terraform plan, Azure Policy and OPA checks, cost estimate. The plan appears as a comment on the PR.
Ring 03 · 04
06 · Gate
Approval
Branch policies with required reviewers: a person reviews and merges. Auto-merge only where the policy allows it — for example scaling within 2–10 instances during business hours. WAF, RBAC and production data always escalate.
Ring 05 · Art. 14
07 · Apply
Apply & logging
The pipeline runs terraform apply with its own managed identity — not the agent’s. Trace, PR, plan and apply log land immutably in immutable storage or S3 Object Lock.
Ring 04 · Art. 12 · 26(6)
Human · monitoring
Identity
Private AI
Agent runtime
Repo · pipeline
Oversight
Cloud · log

The detour through the pull request is deliberate. It separates proposing (agent) from applying (pipeline), makes every change reviewable and uses approval mechanics your team already knows — branch policies and approvals in Azure DevOps, branch protection and required reviewers in GitHub. The same pattern applies to AWS: ecs:UpdateService becomes a Terraform change, not an API call.

02 · Example

A co-engineer
in your subscription.

An agent on the platform team, with tasks like a new colleague — and with a role model that exists before day one. The table is an excerpt from such a model; which row runs autonomously in your environment is decided by your policy, not by the prompt.

Agent action
Permission & route
Mode
Evidence
Deploy a new resource to the architecture modelStorage account, App Service plan, private endpoint in the landing zone
Terraform module from the approved catalogue; PR; Azure Policy checks EU region, tags, private endpoint, customer-managed key
Autonomous when policy passes
Plan and apply log, policy result on the PR
Configure or update a WAF ruleFront Door or Application Gateway WAF policy, custom rules, managed rule sets
Terraform change in a PR; required reviewer from the security team; no direct access to the policy
Approval only
PR with rationale, review comment, apply log
Scale App Service or AKSWithin 2–10 instances, business hours
PR with changed capacity; auto-merge when the policy is met; outside the limits it escalates
Autonomous within limits
Trace with limit check, merge log
Diagnosis and analysisKQL in Log Analytics, Resource Graph, metrics, cost analysis
Reader roles; no write rights; result as comment or ticket
Autonomous
Query and result in the trace
Open a ticket, report a cost anomalyServiceNow, Azure DevOps work item, Teams channel
Connector with write access to the ticketing system only
Autonomous
Ticket ID in the trace
Change an RBAC assignmentGrant a role, extend a group, Key Vault access
Blocked for the agent; humans only, through Privileged Identity Management, time-limited
Blocked
Proposal as a ticket; change in the Entra audit log
Rotate keys or secretsKey Vault, connection strings
Only through an approved runbook, triggered with approval
Approval only
Runbook run with approver in the log
Change production dataDatabase, storage holding customer data
Blocked; no tool in the gateway
Blocked
Attempt is logged and escalated
 Autonomous — within the policy Approval only — a person merges Blocked — no tool, no right
AgentReader on the subscription, Log Analytics Reader, read access to the repository. Writes only to a branch. No Contributor, Owner or User Access Administrator role.
PipelineIts own managed identity with Contributor on the target resource groups; sign-in through workload identity federation, no stored secrets. Executes approved plans only.
HumansOwner and RBAC changes only through Privileged Identity Management, time-limited and justified. Named reviewers for WAF, network and identity.
03 · Permission models

What the state
of the art offers.

Six patterns that vendors now document and that we translate into role models. Each with source and date.

Identity

Agent identity in Microsoft Entra

An agent gets its own identity instead of a shared service account: created from a blueprint, with a sponsor as the accountable person, without credentials of its own — tokens run through federated identity credentials. Conditional Access can be applied to every agent of a blueprint; it requires Entra ID P1/P2 and an Agent 365 licence.

Microsoft Learn, “Overview of agent identities”, updated 15 June 2026; “Conditional Access for agents” — learn.microsoft.com
Identity

AgentCore Identity and Gateway on AWS

Agent identities as workload identities with their own attributes; inbound authentication via JWT, outbound credentials from a token vault. Tools are attached through the gateway via MCP, every call checked against Cedar policies — with separate roles for operating and administering the gateway.

AWS documentation, Amazon Bedrock AgentCore, Identity and Gateway/Policy — docs.aws.amazon.com
Oversight

Review mode before autonomy

Azure SRE Agent starts with Reader rights and in review mode by default: the agent proposes infrastructure actions, an administrator approves. Autonomy is enabled per response plan or task, not globally; Microsoft recommends two to four weeks of review before individual triggers run autonomously. Missing rights are requested time-limited on behalf of the user.

Microsoft Learn, “Run modes in Azure SRE Agent” (preview), updated 2 June 2026 — learn.microsoft.com
Pipeline

Plan and apply separated

The agent gets short-lived, read-only credentials and produces a plan; policy as code (OPA, Conftest, Sentinel) checks it for protected resources, IAM, keys and the state backend; a person reviews; a separate CI identity executes the saved plan. What runs is exactly what was approved.

Gruntwork, “AI Coding Assistants and Infrastructure as Code”, 8 May 2026 — www.gruntwork.io
Model access

Data Zone EU instead of Global

With Azure OpenAI the deployment type decides where prompts are processed: “Global” in any Azure region, “Data Zone EU” only within the EU Data Boundary, “Standard” in the chosen geography. An Azure Policy blocks the GlobalStandard SKU for the whole subscription — blocked, not merely deselected.

Microsoft Learn, “Deployment types in Microsoft Foundry Models”, updated 6 August 2026 — learn.microsoft.com
Rights

Just in time instead of standing rights

Write rights an agent rarely needs are not granted permanently: elevation is time-limited through Privileged Identity Management or the on-behalf-of flow, with a reason and an expiry. The same rule applies to the people who approve agents — reviewing WAF rules does not come with Owner rights.

Microsoft Learn, SRE Agent “How permissions interact with run modes” (OBO flow) — learn.microsoft.com
04 · Method

The 5-ring model.

An agent is as secure as the weakest ring around it. We build five rings from the inside out — from private model access to oversight — and let an agent act autonomously only once all five stand. Every ring has a question the deployer must be able to answer at any time.

Ring 05 · Oversight & evidenceArt. 14 · 26 · 72
Ring 04 · Logging & observabilityArt. 12 · 26(6)
Ring 03 · Tool boundarypolicy per call
Ring 02 · Identity & rightsagent = identity
Ring 01 · Private model access

Model, prompt and session stay in your environment.

01

Private model access

Azure OpenAI or Bedrock in an EU region, connected over a private endpoint or PrivateLink. On Azure, “Global” deployments are blocked by Azure Policy, on AWS global inference profiles by SCP — blocked, not merely deselected. Customer-managed keys, no training on your data, one data processing agreement.

Question: Where was this prompt processed — and can you prove it?
02

Identity & rights

Every agent is its own non-human identity — an agent identity in Entra, an IAM role with AgentCore Identity — with the least rights needed and its own lifecycle. Acting on a user’s behalf, the permission is delegated and expires; a shared service account is not an agent but a risk.

Question: Which identity just acted, and who approved it?
03

Tool boundary

The agent sees only the tools registered in the gateway — MCP servers, connectors, functions — and every call passes a policy: permitted systems, limits, time windows, approval for writes. On Azure through connector DLP and Conditional Access, on AWS in Cedar. The policy lives in code, not in the prompt.

Question: What may the agent not do — and where is that written?
04

Logging & observability

Every tool call, every model response, every approval as a trace with time, identity and result. Export from Application Insights or CloudWatch into your platform — Grafana, Datadog, Dynatrace — with retention under Art. 26(6): at least six months, longer where sector law requires it. Evaluation runs alongside: tool choice, accuracy, aborts.

Question: Can you replay yesterday’s process step by step?
05

Oversight & evidence

Named oversight persons with training, a stop switch per agent, an escalation path for exceptions, a change register for model changes and new tools (Art. 25). A report to management whenever model, tools or purpose change — and an evidence file per agent, kept current.

Question: Who can stop this agent today, and when was that last exercised?
05 · Rollout

4 phases,
3 gates.

Autonomy is not switched on, it is earned. An agent starts as an assistant in a sealed environment and gains room with every phase — but only once the gate before it has been passed. The gates are evidence, not dates. Whoever does not deliver it stays in the phase.

Gate = evidence, not a date · phase 04 continues on an ongoing basis↺
Phase 01

Sandbox

One use case, one agent, reading and proposing only. Landing zone with private model access is in place (ring 01), the agent has its own identity without write rights (ring 02). AI Act classification and provider/deployer roles are settled. Synthetic and masked data.

Gate A · Classification & identityRisk class documented, role settled, agent in the identity inventory, prompt residency evidenced.
Phase 02

Approval operations

Real data, tools in the gateway, every write action waits for a person — review mode. Traces flow into your observability platform (rings 03–04). Evaluation measures tool choice and aborts. The Art. 50 transparency notice is live wherever people talk to the agent.

Gate B · Policy & loggingTool policy in code, trace per call reconstructable, retention configured, evaluation baseline set.
Phase 03

Bounded autonomy

Defined actions run without individual approval within limits — instances, systems, time windows. Exceptions escalate to named oversight persons. Stop switch tested. For high-risk classification: Annex IV documentation, FRIA and deployer duties under Art. 26 complete.

Gate C · Oversight & evidenceOversight persons trained, stop exercised, change register active, evidence file per agent created.
Phase 04

Operations

The agent runs in your operations. Ongoing: evaluation report, policy review, model and tool changes checked against Art. 25, incidents followed up. Every new use case starts again in phase 01 — on the same platform, with the same rings.

Outcome · Operating evidenceEvaluation, policy review and change register, kept current in the evidence file.
06 · AI Act

What the agent does
determines the duty.

For agents, classification is not the end but the start: the decisive task is a complete inventory of what the agent does externally — which systems it touches, which data flows, which people are affected. From that follows which article applies and which ring satisfies it.

Action → duty → implementationExcerpt · only the regulation text is binding
What the agent does
Article
What is required
Ring · implementation
Talks to customers or employeesChat, voice, email on behalf of the company
Art. 50(1) · 50(3)
Notice that an AI is interacting; marking of generated content. In force since 2 August 2026.
Ring 03 · 05Notice in every interface; evidence by screenshot and configuration in the file.
Makes or prepares decisions in Annex III areasHR, credit, critical infrastructure, insurance
Art. 6 · 26 · 27
High-risk deployer duties: operation per instructions for use, oversight, input data, FRIA. From 2 December 2027.
Ring 02 · 05No autonomy without FRIA; oversight person named; approval required in the gateway.
Calls tools, writes data, triggers payments
Art. 12 · 26(6)
Automatic logging; the deployer keeps logs for at least six months.
Ring 04Trace per tool call, immutable storage, retention extended under sector law.
Acts without individual approvalBounded autonomy, multi-agent
Art. 14 · 26(1)–(2)
Effective human oversight: able to understand, intervene, stop.
Ring 03 · 05Policy with limits, escalation, stop switch; exercise documented.
Receives a new model, new tools, a new purpose
Art. 25 · 3(23)
A substantial modification or change of purpose can turn the deployer into a provider.
Ring 05Change register; reassessment before rollout; A/B test and evaluation as evidence.
Runs on a purchased foundation modelAzure OpenAI, Bedrock, OpenAI API
Art. 53 · 55
Duties sit with the model provider; the deployer needs its downstream documentation.
Ring 01Model cards, terms of use, DPA and sub-processors per model in the file.

Secureskies does not provide legal advice. The mapping is our technical reading of the regulation text, the Commission guidelines on Art. 50 and the draft guidelines on high-risk classification of 19 May 2026; borderline cases go to your legal department or law firm. The full classification and the twelve modules that go with it are in the field AI Act & AI Governance.

Which agents already act
in your account or subscription?