The paved road for enterprise agents on Microsoft Agent Framework
MAF Golden Path generates a governed agent in about a minute. Your team writes the business logic. Identity, guardrails, approvals, telemetry, evaluation and deployment come with it, the same way in every agent. Open source, Apache-2.0.
$ copier copy gh:bensunder/maf-golden-path my-agent
Your team writes
- Tools and connectors to your APIs
- Instructions
- Approval rules for risky actions
- Evaluation cases
- Business tests
Every agent inherits
- Entra sign-in and managed identity
- Model access through an AI gateway
- Prompt Shields, PII redaction, tool policy
- Human approvals with an audit trail
- Durable sessions with cross-replica locking
- OpenTelemetry, dashboards and alerts
- Evals, an LLM judge and a deploy quality gate
- Permission-trimmed knowledge with citations
- Teams, web chat and an operations console
- Bicep, azd and OIDC pipelines
The left lane is all your team maintains. The rest is versioned packages owned by a platform team, upgraded in one place.
Stop rebuilding the plumbing before the first real feature
Every team building an enterprise agent rebuilds sign-in, model access, injection defenses, PII handling, approvals, sessions, tracing, evaluation and deployment. The kit moves that work into packages, so teams only write what makes their agent different.
Estimated platform work saved per agent team, plus 1 to 3 days per downstream API. The estimate is in the repo.
To generate a service that passes its own tests offline, with no model needed.
In production, a misconfigured agent refuses to run: no managed identity, no gateway, no Prompt Shields, no start.
See it running
Every agent ships with an operations console. On a single server, it also becomes an agent factory: admins create, connect and launch governed agents from the browser.
The console reads health, evaluations, approvals and security posture from the running agent, not from documentation.
Risky actions wait for a person
A refund, a record update or anything else that changes data pauses until someone approves it, in the chat, the console or Teams. The decision is audited.
Personal data is redacted before the model sees it, so the email in this request never reaches the model or the logs.
New agents in minutes, from the browser
Create agent generates a project from the template, runs its evals as a quality gate, builds it and starts it. A failed build is rolled back.
Start from scratch or from one of 30 legal specialist templates, built with Microsoft Agent Framework or LangGraph. Every one inherits the same controls.
The controls an enterprise review asks for
Identity and access
- Entra sign-in
- Managed identity in production
- On-behalf-of API access
- Session ownership checks
- Permission-aware retrieval
- Signed, delegated agent-to-agent calls
Security
- Prompt Shields, fail-closed
- Tool output scanned for injection
- PII redaction before the model
- Tool allow and deny lists
- Per-session token budgets
Human control
- Approval-required tools
- Separation of duties with Entra roles
- Audit trail for every decision
- Approvals in chat, Teams and the API
Operations
- OpenTelemetry on every span
- Application Insights or LangSmith
- Spend, error and injection alerts
- Live evals gate every deploy
- NIST mapping with live evidence
Production policy is enforced at startup, not by review. With the environment set to production, an agent refuses to start unless it uses managed identity, goes through the AI gateway, runs Prompt Shields, requires a signed-in user and keeps message content out of telemetry.
Run it on Azure, or on your own server first
Generate a service, deploy to Azure
copier copy gh:bensunder/maf-golden-path my-agent cd my-agent pip install -e ".[dev]" && pytest # green offline azd up # when you're ready
Try the whole platform on one Linux server
git clone --branch v0.10.2 \ https://github.com/bensunder/maf-golden-path.git cd maf-golden-path/deploy/vps cp .env.example .env python3 agentctl.py platform --admins you@contoso.com docker compose up -d --build
Built by WhyAIData
WhyAIData is Ben Sunder's practice for enterprise AI governance and applied architecture. MAF Golden Path is how I'd stand up an agent platform for a Microsoft shop, published so your team can read every line of it.
- Agent platform design on Microsoft Agent Framework and Azure AI Foundry
- Governance that holds up in review: identity, guardrails, approvals, audit, NIST mapping
- Rolling the paved road out to your teams, with your own templates and connectors
Bring the paved road to your teams
If you're standardizing how your organization builds agents, I can help you adopt the kit, adapt it to your platform, or review what you have.
Message Ben on LinkedIn
