Introduction

Completed

As agents multiply across Relecloud's tenant, the tools they invoke need the same governance discipline as the agents themselves—an agent that can act on your behalf is only as safe as the tools it's allowed to reach.

One of Relecloud's engineers builds a new customer-support agent in an afternoon. Without asking anyone, it gains the ability to query a live financial database, because a tool that does exactly that already sits available to any agent in the tenant, and nobody on the security team knows it's there, let alone approves it.

The engineer doesn't do anything wrong by their own understanding: the tool shows up on the list of things an agent can use, so they use it.

If a tool nobody reviewed already reaches live financial data, what actually stands between "an agent exists" and "an agent can do anything the tenant technically allows"?

This module walks you through closing that gap in Relecloud's tenant. You review, approve, or block the tools and Bring Your Own (BYO) MCP server requests that determine what an agent can invoke, then take on the ongoing Agent Registry work that keeps the estate current—uploading custom agents, reassigning ownership when a team changes hands, retiring agents nobody needs, and starting or stopping Microsoft Foundry agents. You close the loop by filtering and auditing the agent estate by publisher type and channel, so nothing slips through unnoticed.

By the end of this module, you can govern which tools and MCP servers agents can invoke, and curate and audit Relecloud's agent estate so every agent in the Registry has an owner, an approved toolset, and a documented reason to still exist.