Observability and AMBA Reference
Use Azure Monitor Baseline Alerts (AMBA) as the default monitoring baseline for new Azure SRE Agent implementations unless the customer has a stronger existing standard.
Core Pattern
- Use AMBA to identify recommended Service Health, Resource Health, Activity Log, Metric, and Log Search alert categories.
- Classify each alert before automation: investigate, notify, digest, tune, suppress, or candidate for later autonomy.
- Create SRE Agent response plans only when the alert has a meaningful investigation path or safe remediation proposal.
- Tune thresholds to workload SLOs and business criticality.
- Use Review mode by default and enable reinvestigation cooldown for recurring Azure Monitor alerts.
- Review noisy alerts and AAU cost before scaling response-plan coverage.
- Query Application Insights
customEventsfor agent audit events before promoting AMBA-triggered workflows to Autonomous.
Policy-Deployed AMBA Checks
When AMBA is deployed by Azure Policy/ALZ patterns, verify:
- initiative and assignment scope
- assignment effect and disabled policies
- managed identity and remediation permissions
- action groups and alert processing rules
- exclusions, overrides, and resource selectors
- compliance/remediation state
- whether bulk remediation is being proposed as a production write action
Terraform/AVM Guidance
When using AMBA Terraform/AVM patterns:
- Keep customer-specific overrides outside upstream module source.
- Review plan output for policy assignments, action groups, alert rules, managed identities, and notification routing.
- Treat BYO managed identity, BYO notifications, telemetry settings, and exclusions as explicit design decisions.
- Validate management-group versus subscription scope before deployment.
SRE Agent Mapping
- Service Health/Resource Health: impact assessment and stakeholder digest.
- Activity Log delete/update: change validation, blast radius, rollback recommendation, KT DA/PPA if production-impacting.
- Metric alerts: resource triage, trend analysis, scaling/remediation proposal, and threshold tuning.
- Log Search alerts: fleet investigation, KQL summary, pattern detection, and knowledge capture.
Agent Audit Checks
Before expanding AMBA-to-response-plan coverage, review these audit signals:
AgentToolExecutionvolume by tool and custom agent.ModelGenerationtoken trend for AAU and context growth.IncidentActivitySnapshotcounts for assisted versus mitigated incidents.ApprovalDecisionoutcomes for unsafe or low-confidence remediation proposals.
Use the audit results to identify noisy alerts, expensive investigations, weak response-plan prompts, and workflows that are not safe for Autonomous mode.