Docs / AMS / Rollout / How to run Mindset
View as MarkdownHow to run Mindset
The operating model for a fleet of agents. Where Mindset sits beside your other tools, who does what, the conventions to write down and the habits that keep it in shape.
After this page, your team has an operating model for Mindset: who owns what, the conventions you write down, and the daily, weekly and monthly checks that keep a fleet of agents in shape. To get the first agent live, see Roll out Mindset.
Where Mindset sits beside your other tools
Most companies already own the tools around Mindset:
| Layer | What it answers | Who usually provides it |
|---|---|---|
| Access | Who may use which model | Your identity provider and your AI vendors' admin consoles |
| Discovery | What agents exist that nobody sanctioned | Tenant admin tooling, data loss prevention, threat detection |
| Execution | What a sanctioned agent may do, and what it did | Mindset |
| Surface | Where people meet the agent | The Mindset Hub, your own product (embedded), or Claude and other MCP clients |
Mindset is where the agents that touch real systems are built, run, recorded and improved. The same words mean different things across these products, so check the glossary before a meeting with your Microsoft or Claude admins.
Conventions your team keeps
Mindset enforces a lot on its own: every outside call goes through a named operation, credentials stay on the connection, an agent can never approve an operation, and every run is recorded. See What Mindset enforces for you. Three things it can't enforce, so write them down:
- Each agent has a named owner and a backup. An org agent has no owner field. Put the owner and backup in the agent's description, in the same format every time, for example
Owner: Priya Shah. Backup: Tom Ellis. - Personal tools stay personal. Don't register or review them. A policy that governs somebody's meeting-notes helper won't be taken seriously on the agent that touches bank details.
- Agents nobody uses get switched off. Anything that hasn't run in thirty days is a question. Turn its Available switch off (it then shows as Unavailable), or delete it.
Who does what
| Job | Who | How often |
|---|---|---|
| Build an agent | Anyone who knows the process | When needed |
| Decide which operations exist on a system | The person accountable for that system | Once per system, then on change |
| Approve write operations | A named person in the function that owns the outcome. Finance approves finance writes | When a new write operation appears, if an admin turned auto-enable off. See Approve what an agent can do |
| Decide whether an untested operation goes live | An org admin, with Go live untested. See Test before it goes live | When activation is refused |
| Watch the fleet | One named Mindset owner, and a backup | Daily |
Daily, weekly and monthly habits
Everything here comes from Govern in AMS: Monitor (Cost, Performance, Resources, Topology), Log (every session, in order), Optimize (acceptance tests and experiments) and Audit. Monitor has an agent docked on the left that you can ask in plain words.
| When | Who | What to look at |
|---|---|---|
| Daily, ten minutes | Mindset owner | What failed. What is waiting on a person. What ran and changed nothing |
| Weekly, thirty minutes | Owner and backup | New agents and new operations. On Topology, anything an agent called that it wasn't granted |
| Monthly, an hour | Add security and a system owner | Cost by agent and model on Monitor → Cost. Agents marked Never used on Monitor → Resources, and agents that have gone idle. Which agents hold write operations, and on what |
| Quarterly | Add leadership | Time saved against your own baseline. Owners and backups reconfirmed. Unused agents switched off |
Put the monthly hour in the diary before the first agent goes live.
Things to know about the record:
- Never used and idle are different. An agent that has never run has a trigger problem. One that used to run and stopped has a different one.
- Granted against called. Topology shows what each agent was granted and what it actually called. A call with no current grant is worth looking at the same day.
- Getting the record out. There is no CSV export of runs. A single session downloads as JSON from the Log. For everything else, turn on the OpenTelemetry export in Settings → Governance.
- Two numbers Mindset can't give you. Time saved against the manual way, and how many people can now do what only one could before. Capture the baseline before the agent goes live, because nobody can reconstruct it afterward.
What can go wrong
- Nobody holds the review. The habits above decay first. The usual failure is that the monthly review never gets scheduled, and the first one happens after an incident.
- An agent's risk changes after launch. It starts reaching a new system, starts calling other agents, or runs far more often than it used to. Look again when any of those happen, not only at the start.
- A connected system changes under a live agent. A new credential or base URL makes its operations untested, so the next version that puts them live is refused until they succeed again. See When a connected system changes.
You're done when
- Every agent's description names an owner and a backup.
- One named person owns the daily check, and the monthly hour is in the diary.