Step-by-step guide: automatically discover AI assets from Azure AI Foundry and govern them in watsonx.governance

The challenge
Organizations are racing to build, deploy, or embed AI agents into their workloads resulting unmanaged, ungoverned AI that leaves the organization exposed to unidentified and unmitigated risks. Traditional governance approaches that rely on self-attestations from agent builders or use case owners only capture what people choose to report -- and that is rarely the full picture. To address this, we released AI Asset discovery capability in Watsonx.governance (learn more here).
This is a step-by-step guide on how you can discover AI assets from Azure AI Foundry.
In this walk-through, we will cover two key tasks:
- Configuring Automatic AI Asset Discovery (administrator role)
- Governing Discovered Shadow AI Assets (AI risk manager, governance practitioner role)
Pre-requisite
- watsonx.governance Governance Console instance (as-a-service, AWS) with the Model Risk Governance module enabled. If you don’t have one, sign-up for a trial here.
- You or another user with administrator access (to connect to the agent platform)
- Access to an instance of Azure AI Foundry
Configuring Automatic AI Asset Discovery
Step 1: Configure AI enabled semantic similarity (one-time setup)
AI asset discovery uses AI-enabled semantic similarity to assess whether similar assets already exist in the Governance Console Inventory.
You only need to set this up once.
Once you have launched watsonx.governance Console, please following these steps:
- Navigate to gear icon on the right-hand upper corner, click on Integrations to expand the menu, then select ‘Agent Configuration'
- Configure a foundation model.
- In the Foundation model section, select a foundation model, such as GPT 5 mini from OpenAI.
- Enter the API key to authenticate the connection to the model.
- Configure an embeddings model
In the Embeddings model section, select a model, such as Amazon Titan Text Embeddings V2 from AWS.
- Click Region and select the region where the model is deployed.
- Enter your AWS Access key and Secret key.
D. Ensure the Integration toggle is on (indicated by green)
E. Click Test Connection to verify the connection, then Click Save
Once Configuration saved success message displays, your set-up is complete.
Step 2: Connect to an Agent Platform
- Navigate to gear icon on the right-hand upper corner, click on Integrations to expand the menu, then select Agent Platform
- Click New connection.
- Click on Azure AI Foundry
- Type a name and description for the platform connection (the name must be unique across all of your platform connections) and add the required information (API key, URL)
- Ensure the Integration toggle is on (indicated by green), then click ‘Save’
Once you’ve completed the set-up steps, the system will automatically start discovering AI agents and the tools, MCP servers, foundation model, collaborator agents in its design and populate that in watsonx.governance Governance Console
Governing Discovered Shadow AI Assets
Once you’ve completed the initial set-up, results of the scan are automatically populated in the pre-configured AI Discovery tab in the Home page.
Each discovered result in the table is assigned ‘Shadow’ status until you take action to govern it. Select a result from the table and click Govern from the side panel.
Onboard as new
This will create new records for AI agent, Use Case, and any foundation model, tools, MCP servers in the Inventories and associated these records
- Select the discovered asset from the table which will open a side panel showing details on the related foundation model, tool(s), MCP server(s), collaborator agent(s) discovered.
- Click Govern
- The default selection is Create as new object record, click Next to see the related foundation model, tool(s), MCP server(s) and click Govern to onboard as new
This will automatically create entries in the Inventories for Use Case, Agent, foundation model, tool(s), MCP server(s) if discovered pre-populated with the name, description, and agent platform collected during the scan, and connect these items so you can the relationships easily in the governance graph. Your existing workflows run automatically, based on how they are configured.
Link to an Existing Asset in Governance Console
If the system found similar AI agents that already exist in Watsonx.governance Inventory, it will show ‘Governance match’ and associated ‘Match confidence’ in the table.
You can govern them either by onboarding as new (described above) or linking to existing record in the governed Inventory.
- Select the discovered asset from the table which will open a side panel showing details on the related foundation model, tool(s), MCP server(s), collaborator agent(s) discovered.
- Click Govern
- Select Link to existing agent record, then select the AI agent in the existing inventory that you wish to link it to and click Next
- For the foundation model, tools, MCP servers discovered in the agent design, review the presented matches and either:
- Proceed with the suggested matches,
- Choose different existing objects, or
- Onboard related assets as new objects even while linking the primary agent to an existing record.
- If no match is found, the system will automatically create a new record in the Inventory when you govern it.
Once complete, you’ll see an in-app notice and the Status in the AI Discovery table changes from Shadow to Governed
The AI asset discovery scan automatically runs daily.
Once an asset is Governed, any future changes detected by scans are automatically synchronized to the corresponding agent record in Governance console, and related asset objects are updated accordingly.
You’ll now be able to see AI agents and its foundation model, MCP servers, tools in IBM watsonx.governance!
For more information, see the IBM watsonx documentation: Configuring automatic AI asset discovery and Governing discovered shadow AI assets.
#watsonx.governance
#community-stories2