This capstone turns the earlier Northstar reference architecture into an assessed deliverable. The assistant answers from synthetic policy documents, cites exact sources, refuses unsupported claims, blocks cross-tenant retrieval, resists indirect prompt injection, stays within a token/cost budget, and can be disabled without deleting data.
Time: 1–2 days · Cost: Foundry models, AI Search, storage, app hosting, document processing, private network, and logs can charge · Use: synthetic tenants and documents only.
Method note: This capstone assesses one governed system and its evidence rather than one resource operation. Select the appropriate Portal, SDK, CLI, Bicep, or Terraform path from each linked service chapter, then prove the same authorization, grounding, safety, cost, and recovery outcomes.
Upload → validate/scan → extract → chunk → attach tenant/group/source/version → embed → index staging version → retrieval tests → publish → remove old version.
Authenticate → derive trusted tenant/groups → validate question → hybrid search with server-built ACL filter → rerank/trim → model with evidence/schema → citation and safety validation → response → trace/metrics.
Do not combine them into one synchronous request. Ingestion is long-running and retryable.
Create two tenants with five short documents each. Add:
Record expected authorized chunks and answer properties, not only a free-text ideal answer.
Example policy:
Do not copy numerical quality thresholds without calibrating them to user risk.
Model deployment, prompt version, index version, embedding model, code commit, and evaluator dataset version must appear in release evidence.
Present threat model, data flow, access matrix, evaluation report, traces, cost model, recovery plan, and deletion proof. A polished demo without those artifacts is not a governed AI system.
Delete model deployments, Foundry project/resources, AI Search, app hosting, storage, private endpoints/DNS records, identities/role assignments, logs under the lab policy, and synthetic source data. Confirm no keys or connection strings exist in Git history.