Skip to content

Governance and tenancy

Built in your tenancy, answerable to a person.

The parts of this that matter to a technology reviewer are the same parts that matter to the team using it. Nothing here is a concession made for procurement: it is how the thing is built.

The posture

Six commitments, each of them checkable.

Not principles. Properties of the build, which is why they can be verified rather than believed.

You own the subscription

The build lives in your Azure subscription, on your existing identity system. The data is yours, the billing is yours, and the whole thing can be removed from your tenancy without asking anyone.

Australian data residency

Data stays in Australia. Nothing routes through a third-party service outside your tenancy, and the residency position is something a technology reviewer can verify rather than take on trust.

Every agent has an identity

Not a shared service account. Each agent authenticates as itself, holds the narrowest authority that does its job, and appears in your directory like any other principal.

Boundaries, written before the build

What an agent may do, what it must hand back to a person, and what it may never touch. Recorded before any code, in a sheet you can read without being a technologist.

An audit trail as a matter of course

Every action lands in a record: what acted, under whose authority, with what outcome and at what cost. It is how a governance conversation stops being a matter of opinion.

Standard cloud line items

Your procurement team recognises what appears on the bill, because it is Azure consumption on your own subscription rather than a licence for something they have never bought before.

Tenancy

Inside your subscription, on your directory.

There is no ARK360 platform that your data passes through. The build is deployed into your own subscription and authenticates against your own directory, which is what makes removal a decision you can take on your own.

Your tenant is the boundaryA single boundary drawn around your Azure subscription. Inside it: Entra ID identity, data resident in Australia East, Copilot Studio as the entry tier, and agents authenticated through Azure AI Foundry so billing and governance stay yours. Nothing outbound is autonomous.YOUR AZURE SUBSCRIPTIONEntra IDyour identityData · Australia Eastyour residencyCopilot Studioentry tierAgents via AI Foundryyour billing, your governanceNothing outbound is ever autonomous. Drafts are prepared for a person; a person sends.

Governance

Bounded authority, written before any code.

An agent with unclear authority is a risk nobody can size. The governance sheet is written first: what it may do, what it must hand back, what it may never touch, and how that is enforced rather than merely intended.

The governance loopThe person delegates bounded authority to the system. The system prepares and acts within those bounds. Every action returns through the audit trail and evaluations to the person, who stays in command.The personalways in commandThe systemprepares and acts in boundsDELEGATED, BOUNDED AUTHORITYAUDIT TRAIL · EVALUATIONS · HAND-BACKCOST ENVELOPE

The chassis

What is used, and what it means for you.

The technology choices, stated as consequences rather than as a stack.

The ARK360 delivery chassis and what each component means for the buyer
ComponentWhat it means for you
Azure subscriptionYou own the subscription and the data. I build inside it and can be removed from it.
Entra IDIdentity and access are your directory, your policies, your joiners and leavers. Agents are principals in it like anything else.
Data residencyData resident in Australia. Nothing routes through third-party services outside your tenancy.
Copilot StudioThe entry tier for governed assistants inside Microsoft 365, where your teams already work and the licensing already sits.
Azure AI FoundryDeeper agentic builds authenticate through Foundry, so billing and governance stay inside your tenancy rather than beside it.
Reusable integrationsConnections to your systems of record are built once as governed integrations and reused, rather than rebuilt per project.
Outbound actionsNothing outbound is ever autonomous. Drafts are prepared for a person; a person sends.

Common questions

The things a reviewer asks first.

Who owns the data?
You do. The build lives in your own Azure subscription on your existing identity system, so the data, the billing and the access control are yours. ARK360 can be removed from your tenancy without asking anyone.
Where does it run, and where does the data go?
In your tenancy, in Australia. Data stays in Australia and nothing routes through a third-party service outside your tenancy. It is a position a technology reviewer can verify rather than take on trust.
What can an agent do on its own?
Only what is written down before the build starts. Each agent holds the narrowest authority that does its job, and the conditions under which it must hand back to a person are recorded in a governance sheet. Nothing outbound is ever autonomous: drafts are prepared for a person, and a person sends.
How do I know what an agent actually did?
Every action lands in an audit record: what acted, under whose authority, with what outcome and at what cost. That record is what turns a governance conversation from a matter of opinion into a matter of fact.
What does procurement see on the bill?
Standard cloud line items. It is Azure consumption on your own subscription rather than a licence for something your procurement team has never bought before, which is usually the difference between a short approval and a long one.
What happens when the engagement ends?
The build stays where it is, because it was always in your subscription. The specification, the governance sheet and the decision records are yours and were written to be read by somebody who was not there at the time.
  • Two decades of enterprise Microsoft delivery
  • Federal government, civil construction, property and development
  • You own the tenancy and the data
  • Data resident in Australia
  • A human always in command