Agent action
Permission & route
Mode
Evidence
Deploy a new resource to the architecture modelStorage account, App Service plan, private endpoint in the landing zone
Terraform module from the approved catalogue; PR; Azure Policy checks EU region, tags, private endpoint, customer-managed key
Autonomous when policy passes
Plan and apply log, policy result on the PR
Configure or update a WAF ruleFront Door or Application Gateway WAF policy, custom rules, managed rule sets
Terraform change in a PR; required reviewer from the security team; no direct access to the policy
Approval only
PR with rationale, review comment, apply log
Scale App Service or AKSWithin 2–10 instances, business hours
PR with changed capacity; auto-merge when the policy is met; outside the limits it escalates
Autonomous within limits
Trace with limit check, merge log
Diagnosis and analysisKQL in Log Analytics, Resource Graph, metrics, cost analysis
Reader roles; no write rights; result as comment or ticket
Autonomous
Query and result in the trace
Open a ticket, report a cost anomalyServiceNow, Azure DevOps work item, Teams channel
Connector with write access to the ticketing system only
Autonomous
Ticket ID in the trace
Change an RBAC assignmentGrant a role, extend a group, Key Vault access
Blocked for the agent; humans only, through Privileged Identity Management, time-limited
Blocked
Proposal as a ticket; change in the Entra audit log
Rotate keys or secretsKey Vault, connection strings
Only through an approved runbook, triggered with approval
Approval only
Runbook run with approver in the log
Change production dataDatabase, storage holding customer data
Blocked; no tool in the gateway
Blocked
Attempt is logged and escalated
Autonomous — within the policy Approval only — a person merges Blocked — no tool, no right
AgentReader on the subscription, Log Analytics Reader, read access to the repository. Writes only to a branch. No Contributor, Owner or User Access Administrator role.
PipelineIts own managed identity with Contributor on the target resource groups; sign-in through workload identity federation, no stored secrets. Executes approved plans only.
HumansOwner and RBAC changes only through Privileged Identity Management, time-limited and justified. Named reviewers for WAF, network and identity.