docs: publish WI-11 resolution and verified release operations
- update architecture and preserve the historical investigation
- add release evidence, proof images, and an operations runbook
- distinguish verified outcomes from remaining readiness limits
🛠️ - Generated by Copilot
docs(wiki): add copy-paste instructions and sample Playground prompts for manual agent workaround
Add manual-agent workaround proof and expand RBAC 401 evidence
- Document a portal-native agent (threat-assessment-manual-poc) created
manually in the same Foundry project, proving chat and MCP tool-calling
both work with zero 401 errors, isolating the hosted-agent bug to the
LangGraph/Blueprint-identity runtime path.
- New Manual-Agent-Workaround page: step-by-step reproduction, findings,
and screenshots of a full get_device_risk + list_vulnerabilities MCP
tool-call round trip returning correct mock data.
- RBAC-401-Investigation: add broadened-RBAC test-and-rollback results
(Cognitive Services Contributor / OpenAI Contributor / Azure AI
Administrator, all failed, all rolled back), MCP-server-independently-
verified-healthy note, and screenshot evidence of the raw
openai.AuthenticationError 401 across three agent versions (17, 19, 31).
- Architecture: add environment screenshot gallery (resource group,
Foundry project, Agents list, agent detail, Traces tab requiring App
Insights).
- Home: link the new Manual Agent Workaround page.