Agent report card
Can an agent use Microsoft Azure through API resource management?
Grade B: Only part of the applicable terms is machine-readable.
Microsoft / active
Five-stage assessment
Where agent autonomy holds and where it breaks
First break: Evaluate
Evaluate
LimitedOnly part of the applicable terms is machine-readable.
An ARD declaration has not been established.
An agent can discover the product and funnel from the tested public entrypoints.
Eligibility can be decided from explicit public criteria.
Pricing or the absence of a charge is explicit and machine-readable.
Evidence and actions
ARD declaration unknown
missing: unknownAn ARD declaration has not been established.
Decidable eligibility
supported: freshEligibility can be decided from explicit public criteria.
Azure public legal documentation explicitly sets forth criteria and agreements governing subscription eligibility, purchase terms, and service usage.
Machine discovery
supported: freshAn agent can discover the product and funnel from the tested public entrypoints.
Azure REST API reference documentation defines machine-discoverable REST endpoints and request/response specifications for service management.
Readable pricing
supported: freshPricing or the absence of a charge is explicit and machine-readable.
Azure provides explicit, machine-readable pricing breakdown links and cost details by product.
Structured terms limited
supported: freshOnly part of the applicable terms is machine-readable.
Azure terms of service and legal agreements are available in stable web HTML documentation across linked pages.
What would improve this stage
- Publish complete applicable terms in a stable machine-readable document.
Sign up
ReadyA stable signup entrypoint is available.
Machine-operable signup has not been established.
Whether CAPTCHA blocks signup has not been established.
Whether phone verification is required has not been established.
A scoped, revocable machine identity flow is documented, including explicit human authorization boundaries.
Evidence and actions
CAPTCHA-free signup unknown
supported: freshWhether CAPTCHA blocks signup has not been established.
The retained page metadata and content do not provide evidence on whether a CAPTCHA was encountered or absent during signup.
Machine-operable signup unknown
supported: freshMachine-operable signup has not been established.
The available captured content for the signup page contains only generic page titles and does not demonstrate machine-operable form controls.
Phone-free signup unknown
supported: freshWhether phone verification is required has not been established.
Retained evidence from the signup page is insufficient to determine whether phone or SMS verification is required.
Stable signup entrypoint
supported: freshA stable signup entrypoint is available.
A stable HTTP entrypoint for Azure sign up is available and returns the sign up page context.
Supported identity flow
supported: freshA scoped, revocable machine identity flow is documented, including explicit human authorization boundaries.
Microsoft Entra ID documents scoped, revocable machine identity support via service principal objects and managed identities, including consent and permission boundaries.
Pay
ReadyThe required price or no-charge status is explicit before commitment.
Machine-operable checkout has not been established.
A supported payment rail has not been established.
Whether sales intervention is required has not been established.
Evidence and actions
Explicit price
supported: freshThe required price or no-charge status is explicit before commitment.
Azure pricing provides explicit pay-as-you-go pricing information and cost details across products prior to commitment.
Machine-operable checkout unknown
supported: freshMachine-operable checkout has not been established.
Retained evidence shows the Azure sign-up page load but does not establish a complete machine-operable checkout process.
Sales-free purchase unknown
supported: freshWhether sales intervention is required has not been established.
The retained sign-up page evidence does not provide enough detail to verify if sales intervention is required during sign-up.
Supported payment rail unknown
supported: freshA supported payment rail has not been established.
Supported payment rails cannot be established from the minimal account sign-up title evidence provided.
Provision
ReadySuccessful onboarding automatically activates usable access.
Usable credentials or delegated access are delivered through a documented flow.
Provisioning exposes machine-readable progress, terminal states, and reconciliation.
The provisioning delay has a documented and observed bound.
Evidence and actions
Automatic activation
supported: freshSuccessful onboarding automatically activates usable access.
Azure Resource Manager REST API enables resource deployment directly via HTTP PUT requests with Bearer access tokens without manual intervention.
Bounded provisioning delay
supported: freshThe provisioning delay has a documented and observed bound.
Asynchronous operations return explicit wait intervals in the Retry-After response header to schedule status checks.
Credential delivery
supported: freshUsable credentials or delegated access are delivered through a documented flow.
Service principals and workload identities are created automatically upon app registration or programmatically via Microsoft Graph, Azure CLI, or PowerShell.
Machine-readable provisioning status
supported: freshProvisioning exposes machine-readable progress, terminal states, and reconciliation.
Asynchronous Resource Manager operations expose machine-readable statuses such as InProgress, Running, Succeeded, Failed, or Canceled along with provisioningState values.
Operate
LimitedRecovery is available only for some failure modes or requires human intervention.
An agent protocol interface has not been established.
A documented API or tool interface is available for operation.
Authentication is documented and usable within an agent authorization boundary.
Limits, structured errors, retry behavior, and idempotency semantics are documented where applicable.
Evidence and actions
Agent protocol interface unknown
missing: unknownAn agent protocol interface has not been established.
API or tool access
supported: freshA documented API or tool interface is available for operation.
Azure REST APIs provide documented HTTP methods and endpoints for managing Azure resources.
Delegated recovery limited
supported: freshRecovery is available only for some failure modes or requires human intervention.
Azure support options offer incident resolution and support requests, but recovery and escalation pathways rely on human support plans and manual interaction.
Documented limits and errors
supported: freshLimits, structured errors, retry behavior, and idempotency semantics are documented where applicable.
Azure Resource Manager documents async operation status tracking, Retry-After headers, and structured error payloads.
Usable authentication
supported: freshAuthentication is documented and usable within an agent authorization boundary.
Microsoft Entra ID service principals and managed identities provide documented non-interactive machine authentication for Azure resources.
What would improve this stage
- Provide delegated credential rotation, revocation, retry, and recovery paths without requiring unrestricted human intervention.
What works
- Sign up: A stable signup entrypoint is available.
- Pay: The required price or no-charge status is explicit before commitment.
- Provision: Successful onboarding automatically activates usable access.
What blocks agents
- Evaluate: Only part of the applicable terms is machine-readable.
- Operate: Recovery is available only for some failure modes or requires human intervention.
Improve the report
Correct it, rerun it, or improve the funnel
Every request carries the exact profile revision, projection, declaration, and Catalog release.
Method, policy, and immutable identifiers
Complete, fresh evidence for the core service lifecycle first applies hard stage severity, then grades the share of applicable evidenced signals that are constrained. Optional blocker probes affect the grade when established and remain visible as unknown when public evidence cannot establish them.
Any incomplete, contradictory, unsupported, or non-fresh required evidence produces an unrated profile. A failed Evaluate, Sign up, or Pay stage derives D; a failed Provision or Operate stage derives F; otherwise constrained-signal ratio derives A+ through C.
- Profile ID
- arp_01kzd4bb9sf13ma4xaxb73d82x
- Revision
- sha256:62a34d48bda1936910a64cddc8ad25775e9f8976611d12fc065461207a9ea977
- Projection
- sha256:00aaf3010b800a0e21f701bd158786d5f9317308ca7eebf3746447d9c466fe59
- Policy
- service-lifecycle-2026-08-08-calibrated: sha256:334e56852b5c38e178fcea839cfba680fb82dd96693842d933776baed21d63df
- Base Catalog release
- sha256:5082ec07047a2324648f569d234cc64342ce2707b2f3d77fde8fc06af517cee6