Playbooks
You need to configure a specific control, verify it is working, or respond to an examiner request. This layer contains 316 per-control implementation playbooks (79 controls × 4 types), plus governance operations, compliance procedures, and ready-to-deploy advanced solutions. Content is updated continuously as Microsoft portals and capabilities change.
The fastest route to any control's implementation steps is the Control Explorer — find your control, then jump directly to its portal walkthrough, PowerShell setup, verification, or troubleshooting guide.
Who uses this: Power Platform Admins · SharePoint Admins · Compliance Analysts · Security Operations · Implementation Teams
Quick Start: Common Admin Tasks
Jump directly to the right playbook for your immediate goal.
| I need to… | Start here | Playbook type |
|---|---|---|
| Block an unapproved agent in M365 or restrict publishing | 1.1 Portal Walkthrough | Portal |
| Restrict who can create or publish agents tenant-wide | 1.1 PowerShell Setup | PowerShell |
| Enable Managed Environments governance controls | 2.1 Portal Walkthrough | Portal |
| Set DLP policies for agent data access | 1.5 Portal Walkthrough | Portal |
| Set up audit logging and retention for agent conversations | 1.7 Portal Walkthrough | Portal |
| Build the agent inventory (register existing agents) | 3.1 Portal Walkthrough | Portal |
| Automate agent inventory discovery across all planes | 3.1 PowerShell Setup | PowerShell |
| Prepare for a FINRA, SEC, or OCC exam | Audit Readiness Checklist | Compliance |
| Assemble examination evidence from portal exports | Evidence Pack Assembly | Compliance |
| Respond to an AI governance incident | AI Incident Response Playbook | Incident |
| Decommission an agent securely | Agent Decommissioning | Lifecycle |
| Promote an agent to a higher-governance zone | Agent Promotion Checklist | Lifecycle |
| Monitor for unauthorized agent sharing continuously | Unrestricted Agent Sharing Detector | Advanced |
| Configure human-in-the-loop approvals for agent actions | Human-in-the-Loop Triggers | Advanced |
Control Implementations
The core of this layer — 316 per-control playbooks. Every control has four standard playbooks:
| Playbook type | What it covers |
|---|---|
| Portal Walkthrough | Step-by-step admin-center configuration |
| PowerShell Setup | Automation scripts and module setup |
| Verification & Testing | How to verify the control is working |
| Troubleshooting | Common issues and resolutions |
Browse all control implementations →
Tip: Navigate to any control in the Control Catalog, then click "Implementation Guides" to jump directly to its four playbooks.
Playbook Categories
Getting Started
Phase-based implementation guides for new deployments.
| Playbook | Purpose |
|---|---|
| Phase 0: Governance Setup | Initial governance structure and core controls |
| Phase 1: Minimal Viable Controls | Production readiness controls |
| Phase 2: Hardening | Advanced security and monitoring |
Governance Operations
Day-to-day governance procedures and templates.
| Playbook | Purpose |
|---|---|
| Governance Operating Calendar | Scheduled governance activities |
| RACI Governance Template | Role assignment template |
| Action Authorization Matrix | Approval requirements by action type |
| Escalation Matrix | Escalation procedures and contacts |
| Decision Log Schema | Governance decision documentation |
Compliance and Audit
Examination preparation and evidence management.
| Playbook | Purpose |
|---|---|
| Evidence Pack Assembly | Compile examination evidence |
| Audit Readiness Checklist | Pre-examination preparation |
| Examination Response Guide | Responding to examiner requests |
Incident and Risk
Incident response and risk assessment procedures.
| Playbook | Purpose |
|---|---|
| AI Incident Response Playbook | Incident detection and response |
| AI Risk Assessment Template | Agent risk evaluation |
| Remediation Tracking | Issue remediation workflow |
Agent Lifecycle
Agent creation, deployment, and retirement procedures.
| Playbook | Purpose |
|---|---|
| Agent Inventory Entry | Register new agents |
| Per-Agent Data Policy | Agent-specific data handling |
| Agent Promotion Checklist | Zone promotion requirements |
| Agent Decommissioning | Secure agent retirement |
Monitoring and Validation
Ongoing compliance monitoring and health checks.
| Playbook | Purpose |
|---|---|
| Real-time Compliance Dashboard | Dashboard configuration |
| Scope Creep Detection | Monitor for unauthorized expansion |
| Health Check Procedures | Regular validation checks |
| Purview Audit Query Pack | Pre-built audit queries |
| Semantic Index Governance Queries | Knowledge index monitoring |
Advanced Implementations
Complex governance scenarios, specialized patterns, and ready-to-deploy solutions.
Deployable Solutions
Multi-file implementation packages with architecture guides, deployment steps, and audit evidence procedures.
| Solution | Related Controls | Value |
|---|---|---|
| Agent 365 Observability | 3.2, 3.7, 3.9 | Zone-based retention, SIEM/Sentinel export, and regulatory telemetry mapping |
| Agent Blueprint Promotion Gates | 2.3, 2.8 | Approval-gate model for blueprint lifecycle promotion with FINRA/SOX audit trail |
| Agent Usage & Performance Workbook | 3.1, 3.2, 3.7, 3.8 | Azure Monitor Workbook for unified agent activity and governance signal visibility |
| Conditional Access Automation | 1.11, 1.23 | Automated CA policy compliance validation with drift detection and Dataverse audit trail |
| Configuration Hardening Baseline | 1.1, 1.7, 2.1, 2.22 | 32-item cross-portal security checklist for authentication, audit, RBAC, and content moderation |
| Deny Event Correlation Report | 1.5, 1.7, 3.4 | Correlates deny events across DLP, Purview, and App Insights with SHA-256 evidence export |
| Environment Lifecycle Management | 2.1, 2.2, 2.3 | Automated, governed Power Platform environment provisioning with zone classification |
| MCP Server Governance | 1.4, 1.5, 2.17 | FSI governance guidance for Model Context Protocol server integrations |
| Platform Change Governance | 2.3, 2.15 | Dataverse-backed Message Center change management and operationalization |
| SharePoint Copilot Pre-Flight | 4.1, 4.2, 4.7 | Pre-deployment permission audit checklist before assigning Copilot licenses |
| Unrestricted Agent Sharing Detector | 1.1, 1.2, 2.1 | Continuous detection and alerting for unauthorized agent sharing |
Pattern Guides
Single-file guides for specific governance patterns and specialized configurations.
| Guide | Purpose |
|---|---|
| Human-in-the-Loop Triggers | HITL pattern implementation |
| Confidence and Routing | Confidence-based workflows |
| Zone 1 Minimum Explainability | Transparency requirements |
| DSPM for AI Policy Pack | Data security policies |
| Microsoft Audit Reporting Tools | Built-in audit reporting configuration and retention |
Deployable Solutions Repo
Ready-to-deploy Power Platform solutions are available in FSI-AgentGov-Solutions. See the Solutions Index for the complete catalog with control mappings.
Regulatory Modules
Regulation-specific implementation guidance.
| Playbook | Purpose |
|---|---|
| Colorado AI Act Readiness | Colorado AI Act compliance |
| Colorado AI Impact Assessment | Impact assessment template |
| Supply Chain Risk Register | Third-party risk tracking |
Playbook Maintenance
Update Frequency
- Portal walkthroughs: Updated within 2 weeks of Microsoft UI changes
- Scripts: Updated as needed for API changes
- Templates: Updated quarterly or as governance requirements change
Version Tracking
Each playbook includes:
- Last Updated: Date of last content revision
- Tested On: Portal/API version tested against
- Last UI Verified: Date of last screenshot verification
Reporting Issues
If you find outdated content or broken procedures:
- Check the playbook's "Last Updated" date
- Verify against current portal/API
- Report issues via GitHub Issues
Related Sections
- Framework — Governance principles and structure
- Control Catalog — Control requirements and objectives
- Reference — Supporting materials and quick references
Updated: May 2026 | Version: v1.6.2 | UI Verification Status: Current