Actions outrun permissions
The prototype can call tools, but nobody has defined what it may read, change, approve, retry, or never do.
Peak Consulting is testing an Azure-based productionization service for companies whose agent prototypes are blocked by security, data access, evaluation, deployment, cost, observability, or unclear operating ownership.
Scope and prices are working hypotheses requiring separate buyer evidence.
Agentic systems are not only models and prompts. They combine business workflow, data, tools, authorization, application behavior, evaluation, telemetry, cost, and human intervention.
The prototype can call tools, but nobody has defined what it may read, change, approve, retry, or never do.
New prompts, tools, models, and indexes are judged by a few conversations rather than representative tests and release thresholds.
Tracing, privacy, cost, escalation, rollback, and disablement are unresolved when the workflow reaches real users.
The opening project productionizes one funded use case with named owners and reversible or human-approved actions. Additional agents and tool domains are separate decisions.
$15k–$25k working range
Assess the workflow, Foundry architecture, models, data, tools, identity, evaluation, tracing, privacy, cost, human approvals, and incident controls.
Output: target architecture, risk register, evaluation plan, control boundaries, and roadmap.
$35k–$65k one workflow
Implement client-owned Azure/Foundry environments, deployment, approved knowledge and tools, evaluations, tracing, cost controls, approval, rollback, and runbooks.
Acceptance: the bounded workflow passes release gates and operates with a tested kill switch.
$8k–$15k/mo working range
Review traces and feedback, improve behavior through versioned changes, manage cost/latency, refine approval thresholds, and transfer ownership.
Not unlimited agent development or autonomous ownership of the business process.
Microsoft Foundry supplies models, agents, evaluations, and governance capabilities. The workload still needs business boundaries, application controls, Azure foundations, and an operating system.
The agent may propose an action. An external authorization control decides whether that identity may execute it, and a human approves consequential actions.
— Initial autonomy boundaryWho owns the result, who uses it, and what improves?
What may the agent do, never do, and escalate?
Which sources, identities, sensitivity, freshness, and retention apply?
Are permissions minimal, inputs validated, actions auditable, and retries safe?
Which representative cases and thresholds block a weak release?
How are injection, abuse, unsafe outputs, and prohibited actions handled?
Are environments, IaC, network, secrets, policy, and capacity repeatable?
Can owners trace, alert, intervene, roll back, and disable the workflow?
What are latency and model/tool cost per completed task?
Who signs off, supports the release, and reviews measured value?
| Phase | Human decision | Engineering output | Acceptance evidence |
|---|---|---|---|
| Week 0–1 | Workflow, owners, prohibited actions, and success cases | Charter, risk register, evaluation dataset v1 | Business, technical, and security owners approve boundaries |
| Week 2 | Foundry, project, identity, and network decisions | IaC foundation and isolated non-production environment | Environment deploys repeatably |
| Week 3 | Model, grounding, and data access | Model and knowledge integration | Source access, freshness, and grounding tested |
| Week 4 | Tool and action boundaries | Least-privilege tool integrations | Unauthorized and malformed actions fail safely |
| Week 5–6 | Quality, safety, trace, and privacy thresholds | Automated evaluations, tracing, and dashboards | Weak release is blocked; trace access/retention reviewed |
| Week 7 | Intervention and failure controls | Human approval, rollback, disablement, and runbooks | Consequential action requires approval; kill switch works |
| Week 8–10 | Bounded release and value review | Production launch, tuning, cost controls, handoff | Owner can operate, inspect, and stop the workflow |
Agent traces may contain prompts, responses, retrieved context, tool calls, intermediate steps, personal information, latency, tokens, and errors. Enable tracing deliberately; redact sensitive data; restrict access; and define retention before production.
Current references: Microsoft Foundry architecture, Foundry landing-zone baseline, tracing and data handling, and Agent Service transparency guidance.
Identity, network, IaC, CI/CD, observability, cost, recovery, and client ownership remain the common operating core.