Establish a Central Azure AI Governance Hub

Updated

Operate Azure API Management and Azure API Center as shared governance services, then onboard secure AI workloads through explicit publication, identity, network, and telemetry boundaries.

This Build-tier topic applies the Azure governance-hub structure illustrated by the Foundry Citadel reference architecture. Azure API Management provides runtime mediation while Azure API Center provides design-time asset discovery and assessment. Explicit onboarding connects an independently secured AI workload to those shared services. Workload construction, agent identity, runtime protection, enterprise governance, and security operations remain in their existing topics. Citadel is an adaptable reference architecture, not a standalone product or mandatory topology.

How to address Establish a Central Azure AI Governance Hub

  1. Establish Shared AI Gateway and Asset Governance

    Operate Azure API Management and Azure API Center as shared platform services for runtime mediation, AI asset discovery, consumption controls, assessment evidence, and gateway telemetry across AI workload spokes.
  2. Onboard a Foundry Workload to the Governance Hub

    Connect a Foundry workload spoke to shared governance by registering its AI assets, publishing approved runtime endpoints through API Management, authorizing hub-to-spoke paths, and correlating gateway and workload telemetry.

Control coverage

Control coverage for Establish a Central Azure AI Governance Hub — where its 10 capabilities land across your security control domains and the AI surfaces they protect. Select any control domain to reveal the capabilities behind it.
Control domain
Agents
Users
Infrastructure
Endpoints
Data
Coverage
Governance
5

Organisational and technical controls for managing the lifecycle of AI models, agents, and workloads — including inventory, policy, and accountability frameworks.

Agent Security
4

Controls that secure AI agents, their tools, plugins, and external connections — including MCP server trust boundaries, tool permission scoping, prompt injection defences, and runtime behaviour constraints for autonomous and assistive agents.

Identity & Access
2

Controls that ensure only authenticated and authorized principals can access AI models, APIs, data pipelines, and management planes.

Monitoring
2

Continuous observability of AI workload behaviour, usage, and anomalies through logging, metrics, and alerting — enabling detection of drift, misuse, and security events.

Network Protection
2

Controls that secure the network paths used by AI workloads — including private endpoints, egress filtering, secure web gateways, and traffic inspection to prevent data exfiltration and lateral movement.

Supply Chain
2

Controls that protect the integrity of AI model supply chains — covering model provenance, dependency vetting, third-party plugin and connector risk, and safeguards against tampered or poisoned models and training data.

AI Safety
1

Guardrails that keep generative AI outputs and inputs within safe, policy-aligned bounds — including content filtering, prompt shields, and groundedness evaluation.

Discovery
1

Capabilities for discovering and inventorying AI assets, workloads, shadow AI usage, connected applications, and data sources — providing visibility as the foundation for securing what you can see.