Governance and tenancy
Built in your tenancy, answerable to a person.
The parts of this that matter to a technology reviewer are the same parts that matter to the team using it. Nothing here is a concession made for procurement: it is how the thing is built.
The posture
Six commitments, each of them checkable.
Not principles. Properties of the build, which is why they can be verified rather than believed.
You own the subscription
The build lives in your Azure subscription, on your existing identity system. The data is yours, the billing is yours, and the whole thing can be removed from your tenancy without asking anyone.
Australian data residency
Data stays in Australia. Nothing routes through a third-party service outside your tenancy, and the residency position is something a technology reviewer can verify rather than take on trust.
Every agent has an identity
Not a shared service account. Each agent authenticates as itself, holds the narrowest authority that does its job, and appears in your directory like any other principal.
Boundaries, written before the build
What an agent may do, what it must hand back to a person, and what it may never touch. Recorded before any code, in a sheet you can read without being a technologist.
An audit trail as a matter of course
Every action lands in a record: what acted, under whose authority, with what outcome and at what cost. It is how a governance conversation stops being a matter of opinion.
Standard cloud line items
Your procurement team recognises what appears on the bill, because it is Azure consumption on your own subscription rather than a licence for something they have never bought before.
Tenancy
Inside your subscription, on your directory.
There is no ARK360 platform that your data passes through. The build is deployed into your own subscription and authenticates against your own directory, which is what makes removal a decision you can take on your own.
Governance
Bounded authority, written before any code.
An agent with unclear authority is a risk nobody can size. The governance sheet is written first: what it may do, what it must hand back, what it may never touch, and how that is enforced rather than merely intended.
The chassis
What is used, and what it means for you.
The technology choices, stated as consequences rather than as a stack.
| Component | What it means for you |
|---|---|
| Azure subscription | You own the subscription and the data. I build inside it and can be removed from it. |
| Entra ID | Identity and access are your directory, your policies, your joiners and leavers. Agents are principals in it like anything else. |
| Data residency | Data resident in Australia. Nothing routes through third-party services outside your tenancy. |
| Copilot Studio | The entry tier for governed assistants inside Microsoft 365, where your teams already work and the licensing already sits. |
| Azure AI Foundry | Deeper agentic builds authenticate through Foundry, so billing and governance stay inside your tenancy rather than beside it. |
| Reusable integrations | Connections to your systems of record are built once as governed integrations and reused, rather than rebuilt per project. |
| Outbound actions | Nothing outbound is ever autonomous. Drafts are prepared for a person; a person sends. |
Common questions
The things a reviewer asks first.
- Who owns the data?
- You do. The build lives in your own Azure subscription on your existing identity system, so the data, the billing and the access control are yours. ARK360 can be removed from your tenancy without asking anyone.
- Where does it run, and where does the data go?
- In your tenancy, in Australia. Data stays in Australia and nothing routes through a third-party service outside your tenancy. It is a position a technology reviewer can verify rather than take on trust.
- What can an agent do on its own?
- Only what is written down before the build starts. Each agent holds the narrowest authority that does its job, and the conditions under which it must hand back to a person are recorded in a governance sheet. Nothing outbound is ever autonomous: drafts are prepared for a person, and a person sends.
- How do I know what an agent actually did?
- Every action lands in an audit record: what acted, under whose authority, with what outcome and at what cost. That record is what turns a governance conversation from a matter of opinion into a matter of fact.
- What does procurement see on the bill?
- Standard cloud line items. It is Azure consumption on your own subscription rather than a licence for something your procurement team has never bought before, which is usually the difference between a short approval and a long one.
- What happens when the engagement ends?
- The build stays where it is, because it was always in your subscription. The specification, the governance sheet and the decision records are yours and were written to be read by somebody who was not there at the time.
- Two decades of enterprise Microsoft delivery
- Federal government, civil construction, property and development
- You own the tenancy and the data
- Data resident in Australia
- A human always in command