Establish a Central Azure AI Governance Hub
Operate Azure API Management and Azure API Center as shared governance services, then onboard secure AI workloads through explicit publication, identity, network, and telemetry boundaries.
This Build-tier topic applies the Azure governance-hub structure illustrated by the Foundry Citadel reference architecture. Azure API Management provides runtime mediation while Azure API Center provides design-time asset discovery and assessment. Explicit onboarding connects an independently secured AI workload to those shared services. Workload construction, agent identity, runtime protection, enterprise governance, and security operations remain in their existing topics. Citadel is an adaptable reference architecture, not a standalone product or mandatory topology.
How to address Establish a Central Azure AI Governance Hub
-
Establish Shared AI Gateway and Asset Governance
Operate Azure API Management and Azure API Center as shared platform services for runtime mediation, AI asset discovery, consumption controls, assessment evidence, and gateway telemetry across AI workload spokes. -
Onboard a Foundry Workload to the Governance Hub
Connect a Foundry workload spoke to shared governance by registering its AI assets, publishing approved runtime endpoints through API Management, authorizing hub-to-spoke paths, and correlating gateway and workload telemetry.Onboard a Foundry Workload to the Governance Hub Azure API CenterAzure API ManagementMicrosoft FoundryAzure MonitorDesign-Time AI Asset Catalog Agents Infrastructure AI Asset Assessment Evidence Agents Infrastructure AI Runtime Gateway and Access Mediation Agents Infrastructure Gateway AI Traffic Observability Agents Infrastructure MCP and A2A API Gateway Governance Agents Infrastructure Identity and Access Boundary Infrastructure Agents Network Isolation Infrastructure Application Insights Agent Observability Agents
Control coverage
Governance5
Organisational and technical controls for managing the lifecycle of AI models, agents, and workloads — including inventory, policy, and accountability frameworks.
Agent Security4
Controls that secure AI agents, their tools, plugins, and external connections — including MCP server trust boundaries, tool permission scoping, prompt injection defences, and runtime behaviour constraints for autonomous and assistive agents.
Identity & Access2
Controls that ensure only authenticated and authorized principals can access AI models, APIs, data pipelines, and management planes.
Monitoring2
Continuous observability of AI workload behaviour, usage, and anomalies through logging, metrics, and alerting — enabling detection of drift, misuse, and security events.
Network Protection2
Controls that secure the network paths used by AI workloads — including private endpoints, egress filtering, secure web gateways, and traffic inspection to prevent data exfiltration and lateral movement.
Supply Chain2
Controls that protect the integrity of AI model supply chains — covering model provenance, dependency vetting, third-party plugin and connector risk, and safeguards against tampered or poisoned models and training data.
AI Safety1
Guardrails that keep generative AI outputs and inputs within safe, policy-aligned bounds — including content filtering, prompt shields, and groundedness evaluation.
Discovery1
Capabilities for discovering and inventorying AI assets, workloads, shadow AI usage, connected applications, and data sources — providing visibility as the foundation for securing what you can see.