Setting the file. One moment.
Subchapter 3.3
references/guardrails.mdMarkdown2 KBView on GitHub
enforcementMode.generate_query, validate_query, then execute_query for assignments
and resource inventory. Use the Azure Policy API fallback when Resource Graph
does not expose exemptions, compliance state, or definition details.Default assignments as enforced only when the resource is in scope
and not exempt. Report DoNotEnforce as audit-only. Distinguish deny, audit,
modify, append, and deploy effects rather than claiming every assignment
blocks deployment.list_budgets at supported scopes. Build a coverage matrix showing
which subscriptions or resource groups have enforced policy, compliant tags,
and a budget. Do not treat a parent budget as a child budget unless its scope
and filters actually cover that child.Present the effective assignment, source scope, inheritance, exclusions, exemptions, effect, parameters, compliance evidence, tag gaps, budget coverage, affected resources, confidence, and owner action.
An empty Resource Graph result may reflect permissions or scope visibility. State that uncertainty instead of claiming no guardrails exist.