# Governed AI Sandbox — Action Plan (HTML)
File: sandbox-action-plan.html · Version: 1.0 · Date: July 2026
An interactive, single-page tracker for executing the governed AI sandbox build. It converts the workshop documentation into 48 dependency-ordered action items, organised into seven sections by tool/platform, with live progress tracking per platform. Intended uses: workshop run-of-show, client build tracking, and printed evidence of completion.
| Section | Code | Items | Scope |
|---|---|---|---|
| Azure Platform & Policy | AZP |
4 | Subscription prerequisites; model allowlist enforcement via Azure Policy |
| Microsoft Foundry | FND |
9 | Account/projects, RBAC per the role-alignment matrix, guardrails, EU Data Zone deployments, evaluator gates |
| Microsoft Entra ID | ENT |
7 | Agent identity plane: attributes, deny-by-default CA, registry, approval runbook, non-EU creator constraints |
| Microsoft Purview | PUR |
9 | DSPM for AI, both DLP paths (Foundry prompt-blocking and M365-Copilot label restriction), retention, Compliance Manager EU AI Act assessment |
| Microsoft Defender | DEF |
5 | AI services plan, prompt evidence, posture recommendations, XDR/Sentinel flow |
| Copilot Studio & Power Platform | CPS |
6 | Audit, Sentinel rules, Agent IDs, Copilot Credits allocation, per-agent caps |
| Validation & Workshop Output | VAL |
8 | The seven enforcement test scenarios plus the sandbox design record |
Every item carries a stable ID (e.g. FND-03, PUR-06) for unambiguous reference in workshop notes, tickets and the design record, a one-line detail with the section reference into the main documentation (e.g. §4.3), and chips flagging release status and commercial model:
GA/PREVIEW— release status of the underlying Microsoft capability (re-verify before client delivery; this domain moves monthly)M365 E5/AZURE METER/COPILOT CREDITS— which meter pays for itOWNER: …— suggested owning team (IT platform, Identity, SecOps, Compliance, Creator)
- Open the file in any modern browser (Edge, Chrome, Firefox, Safari). No server, build step or installation required — it is a single self-contained file.
- Track progress by ticking checkboxes; the left rail updates per-platform counters and the overall completion bar in real time. Section codes in the rail jump to the matching section.
- Record state before closing: checkbox state is held in browser memory only and resets on reload (deliberate — no data is written to disk or browser storage). Use Print / Ctrl+P to produce a dated paper or PDF record; a print stylesheet collapses the page to a clean checklist.
All content lives in one JavaScript array (const DATA = [...]) near the top of the <script> block — sections, items, details and chips are plain data. To add an item, append an object with id, act, det, chips; counters and navigation rebuild automatically on load. Design tokens (colours, fonts) are CSS variables in :root.
- Single HTML file; vanilla JavaScript, no frameworks, no external dependencies except Google Fonts (Space Grotesk / Inter / JetBrains Mono) — the page degrades gracefully to system fonts offline.
- No localStorage/sessionStorage, no cookies, no network calls beyond fonts: safe to email or host on an intranet without review overhead.
- Colour palette and typography follow the engagement's teal design system for consistency with the Word deliverables.
- The tracker is a working aid, not the authority — item wording compresses other documentation; based on docx (with its Microsoft Learn references and limitations register) is the defensible source.
- Preview-flagged items (
ENT-03,ENT-05,FND-05,AZP-04,DEF-03,CPS-03,VAL-07) depend on Microsoft preview features whose behaviour and availability may change without notice.