Skills Matrix¶
Capability-to-evidence map
This matrix maps AzAWSLab capabilities to engineering notes, evidence routes, and public-safe evidence indexes. It helps reviewers move from capability area to implementation detail without searching the repository manually.
How to read this matrix¶
| Column | Purpose |
|---|---|
| Skill | The capability demonstrated in the platform. |
| Evidence signal | The concrete implementation signal a reviewer should look for. |
| Engineering note | The technical page that explains the design and implementation. |
| Proof route | The proof dashboard or evidence index that links to repository evidence. |
Release 1 Hybrid Workplace¶
| Skill | Evidence signal | Engineering note | Evidence route |
|---|---|---|---|
| Hybrid identity architecture | Active Directory, Entra ID, Entra Connect, pilot identity scope, Conditional Access, MFA, and identity operations. | Hybrid Identity | Release 1 evidence |
| Conditional Access and access control | MFA, policy result visibility, compliant-device context, sign-in review, and access enforcement signals. | Hybrid Identity | Release 1 Evidence Index |
| Exchange Hybrid and Microsoft 365 operations | Exchange Hybrid, Microsoft 365 operations, collaboration service validation, and workplace administration. | Exchange Hybrid and M365 Services | Release 1 evidence |
| Modern endpoint management | Intune, Autopilot, compliance policy, BitLocker, Windows LAPS, Defender controls, and managed-device lifecycle signals. | Modern Endpoint Management | Release 1 Evidence Index |
| Information protection and data governance | Microsoft Purview, sensitivity labels, DLP, retention, and user-visible policy behavior. | Modern Endpoint Management | Release 1 evidence |
| Microsoft Graph PowerShell operations | Scripted pilot user state, managed device state, Microsoft Graph connection and consent validation, and controlled administrative action. | Graph and PowerShell Operations | Release 1 Evidence Index |
| Monitoring and operational visibility | Sign-in review, audit-log visibility, Conditional Access result review, device compliance checks, alert review, and Graph-connected checks. | Monitoring and Operational Visibility | Release 1 evidence |
| Microsoft workplace recovery operations | BitLocker recovery, stale or duplicate device cleanup, trust-break handling, rebuild, and re-enrollment evidence. | Modern Endpoint Management | Release 1 Evidence Index |
Release 2 Delivery Engineering¶
| Skill | Evidence signal | Engineering note | Evidence route |
|---|---|---|---|
| Terraform state boundary design | Multiple Terraform roots separate platform networking, management, AKS, AVD, shared services, governance, workloads, and AWS branch responsibility boundaries. | Terraform State Boundaries | Delivery evidence |
| Remote state and ownership discipline | Root-specific state boundaries, controlled plan/apply behaviour, and blast-radius separation. | Terraform State Boundaries | Release 2 Evidence Index |
| GitHub Actions OIDC | Workflow-controlled Azure authentication without routine long-lived deployment credentials. | GitHub Actions OIDC | Delivery evidence |
| CI/CD delivery governance | Plan, review, apply, workflow evidence, and pipeline guardrails. | GitHub Actions OIDC | Release 2 Evidence Index |
| Code traceability | Documentation, source, workflow records, and repository evidence connected to reviewable platform claims. | Code Traceability | Delivery evidence |
Release 2 Network Engineering¶
| Skill | Evidence signal | Engineering note | Evidence route |
|---|---|---|---|
| Hybrid and multi-cloud network architecture | Azure hub-spoke networking, route control, VPN, IPSec, BGP, AWS branch integration, and route validation evidence. | Hybrid Multi-Cloud Networking | Network evidence |
| Azure Firewall and route control | Forced routing, route tables, hub inspection context, and network boundary evidence. | Hybrid Multi-Cloud Networking | Release 2 Evidence Index |
| Secure transmission and inspection | FortiGate NVA, Azure Firewall, inspection path, routing, and validation signals. | Secure Transmission and Inspection | Network evidence |
| Hybrid BGP multi-cloud transit | BGP, IPSec, AWS branch routing, cross-cloud route validation, and transit-path signals. | Hybrid BGP Multi-Cloud Transit | Release 2 Evidence Index |
| Multi-vendor routing and branch integration | Azure, AWS branch, route propagation, route filtering context, and validated reachability. | Hybrid BGP Multi-Cloud Transit | Network evidence |
Release 2 Platform Services¶
| Skill | Evidence signal | Engineering note | Evidence route |
|---|---|---|---|
| Private AKS platform delivery | Private AKS pattern, controlled access, Kubernetes manifests, network policy context, and validation signals. | Private AKS Platform | Platform evidence |
| Kubernetes source and validation | Kubernetes manifests, support objects, and platform validation evidence. | Private AKS Platform | Release 2 Evidence Index |
| AVD secure workspace | Azure Virtual Desktop, FSLogix, private access orientation, privileged access separation, and secure workspace governance. | AVD Secure Workspace | Platform evidence |
| Private platform integration | AKS and AVD architecture, internal access paths, route context, and inspected private platform communication. | Private AKS and AVD Architecture | Platform evidence |
Release 2 Operations Engineering¶
| Skill | Evidence signal | Engineering note | Evidence route |
|---|---|---|---|
| Ansible and AWX automation control plane | Ansible source, AWX control-plane evidence, inventories, job templates, execution records, and governed runbooks. | Automation Control Plane | Operations evidence |
| Source-controlled operational automation | Playbooks, inventories, operational runbooks, and controlled execution model. | Automation Control Plane | Release 2 Evidence Index |
| Azure Monitor and Sentinel operations | Azure Monitor evidence, Sentinel context, alert validation, and operational visibility. | Monitoring, Backup and Resilience | Operations evidence |
| Defender for Cloud operations | Defender for Cloud, recommendations, posture visibility, and security operations context. | Monitoring, Backup and Resilience | Release 2 Evidence Index |
| Backup and disaster recovery | Recovery Services Vault, backup policies, BCDR planning, soft-delete handling, immutability, and validation signals. | Monitoring, Backup and Resilience | Operations evidence |
| Operational resilience validation | Monitoring, backup, recovery, deletion protection, and documented resilience checks. | Monitoring, Backup and Resilience | Release 2 Evidence Index |
AI Operations and Innovation¶
| Skill | Evidence signal | Engineering note | Evidence route |
|---|---|---|---|
| AI Operations Enclave governance | Policy-mediated tool use, evidence capture, Kubernetes support context, and human approval boundaries in the AI Operations Enclave, evidenced through O6. | AI Operations Enclave | AI evidence |
| O6 evidence model | O6 evidence folder, policy boundaries, namespace lifecycle, cleanup validation, and operational governance context. | AI Operations Enclave | Release 2 Evidence Index |
| Companion local AI lab | Local-first multi-agent infrastructure workflow, RAG, provider routing, validation hooks, tool permissions, and human review boundaries. | Companion Project | AI evidence |
Platform Evolution¶
| Skill | Evidence signal | Engineering note | Evidence route |
|---|---|---|---|
| Multi-cloud Kubernetes roadmap | Release 3 roadmap for multi-cloud Kubernetes, GitOps, DevSecOps, observability, and resilience. | Release 3 Roadmap | Release 3 roadmap evidence |
| Roadmap discipline | Release 3 is presented as future direction, not completed implementation evidence. | Release 3 Roadmap | Release 3 documentation |
Reviewer usage¶
| Reviewer | How to use this matrix |
|---|---|
| Recruiter | Scan the Skill column to identify coverage across Microsoft 365, Azure, networking, automation, Kubernetes, AVD, resilience, and AI operations. |
| Hiring manager | Use the Evidence signal column to assess implemented capability rather than generic familiarity. |
| Technical reviewer | Follow the Engineering note and Evidence route columns to inspect implementation context and evidence routes. |
| Security architect | Trace identity, endpoint, network inspection, private access, backup, and AI governance across the release lifecycle. |
| DevOps / SRE reviewer | Start with Delivery Engineering, Operations Engineering, and AI Operations and Innovation. |