# Agent Estate Review

Canonical URL: https://celest.dev/agent-estate-review

For teams running agents on Microsoft

## Your Microsoft agents are real. The seams around them are too.

Your agents already live across Copilot Studio, Microsoft 365, Power Platform, Azure, GitHub, and Azure DevOps. Celest shows you what exists, who owns it, and where things break across them.

[Request an Estate Review](mailto:founders%40celest.dev?subject=Agent%20Estate%20Review&body=Hi%20Celest%20team%2C%0A%0AI%27d%20like%20to%20explore%20an%20Agent%20Estate%20Review.%0A%0AOrganization%20%28optional%29%3A%0AMy%20role%3A%0AWhat%20made%20this%20relevant%20now%3A%0AWho%20else%20should%20join%20if%20we%20continue%3A%0AHow%20did%20you%20find%20Celest%3A%0A) · [Explore the demo](https://demo.celest.dev/reviews) · [See what you receive](#start-with-a-read-only-agent-estate-review)

## Review boundary

- Read-only first — see the estate before action
- Authority stays explicit — action waits for a real decision

## Illustrative lifecycle view

Illustrative record:

- Agent: Renewals Copilot
- Status: Published · 214 assigned users
- State: Finding

Illustrative facts:

| Field | Value |
| --- | --- |
| Identity | Studio ↔ Entra joined |
| Owner | unknown |
| Tools | 4 connectors · 1 MCP |
| Cost | source unavailable |

Governed lifecycle:

| Stage | Status | Output |
| --- | --- | --- |
| 01 Discover | Live | EvidenceSnapshot |
| 02 Diagnose | Live | Finding |
| 03 Propose | Next | LifecyclePlan |
| 04 Approve | Authority gate | AuthorityDecision |
| 05 Execute | Roadmap only | bounded action |
| 06 Verify | Roadmap only | ExecutionReceipt |
| 07 Reconcile | Roadmap only | fresh state check |

Roadmap only: Stages 05–07 show the broader operating model after approval. This read-only Estate Review stops at discovery, diagnosis, proposal, and authority.

The control plane earns autonomy. It does not assume it.

## Why Celest

### Microsoft is building the platform. You still own the seams.

Celest exists because we ran into this ourselves. An agent can cross Entra, Microsoft 365, Copilot Studio, Power Platform, Azure, GitHub, and Azure DevOps, while ownership, tools, usage, spend, and risk stay scattered across them. Each admin surface is truthful about its slice and blind to the whole.

## Microsoft source records joined into one canonical agent record

Source records:

| Source | What it holds | Example gap |
| --- | --- | --- |
| Entra ID | identity · permissions | owner not recorded |
| Copilot Studio | agent · tools · state | spend unavailable |
| Microsoft 365 | assignment · usage | source unknown |
| Power Platform | maker · environment | lineage incomplete |
| GitHub | code · reviews | runtime unlinked |
| Azure DevOps | work · release state | agent join missing |

Canonical join:

| Field | Value |
| --- | --- |
| Record | `agent:042` |
| Source observations | 6 source observations |
| Identity | Renewals Copilot · Studio + Entra |
| Owner | unknown · no accountable sponsor |
| Lifecycle | published · assigned · idle 41d |
| Cost | unknown · billing source unavailable |
| Source health | 5 / 6 available |

Celest turns scattered admin truth into one accountable view.

## The real comparison

### “Doesn’t Microsoft already do this?”

Pieces of it — and that is the problem. Agent governance on Microsoft is real, but it is distributed across more than a dozen admin surfaces, each with its own scope, licensing, maturity, terminology, and admin boundary. Each one answers its own question truthfully. None of them answers the question you actually have: _what do our agents look like as one estate?_

Microsoft surfaces that each hold part of agent governance:

| Surface | Slice of governance |
| --- | --- |
| Microsoft 365 admin center + Agent 365 | registry · access · observability |
| Entra | agent identity · lifecycle · Conditional Access |
| Purview | data compliance · DLP · audit |
| Defender | threats · posture · incidents |
| Power Platform admin center | environments · makers · connectors |
| Copilot Studio | agent definitions · channels · analytics |
| SharePoint Advanced Management | content access · oversharing |
| Security Dashboard for AI | AI-specific security posture |
| Foundry | model + agent runtime telemetry |
| Fabric | data estate + capacity signals |
| GitHub Copilot | coding agent usage + policy |
| Security Copilot | security workflow agents |
| Dynamics 365 | business-process agents |

Agent 365 is an important part of that picture — not the whole answer. Celest joins these surfaces into one accountable record per agent, with evidence, unknowns, and next steps attached. And the better Microsoft’s primitives get, the more Celest can join: every new admin surface is more evidence for the estate, not a replacement for it.

## Start with a read-only Agent Estate Review.

A fixed-scope, read-only review for teams that already feel the sprawl. We gather the evidence, show what actually exists, name what is still unknown, and turn it into a practical operating plan.

Review facts:

| Fact | Detail |
| --- | --- |
| 2 weeks | Fixed scope |
| Read-only | Least privilege |
| Actionable | 30 / 60 / 90-day plan |

[Request an Estate Review](mailto:founders%40celest.dev?subject=Agent%20Estate%20Review&body=Hi%20Celest%20team%2C%0A%0AI%27d%20like%20to%20explore%20an%20Agent%20Estate%20Review.%0A%0AOrganization%20%28optional%29%3A%0AMy%20role%3A%0AWhat%20made%20this%20relevant%20now%3A%0AWho%20else%20should%20join%20if%20we%20continue%3A%0AHow%20did%20you%20find%20Celest%3A%0A)

## What you get

1. A normalized inventory of agents, owners, tools, and environments
2. Findings on overlap, gaps, risk, usage, and unknowns
3. An executive readout your team can actually act on
4. A prioritized 30 / 60 / 90-day operating plan

[See a sample readout](https://celest.dev/agent-estate-review/sample)

## The product

### Don’t take the narrative’s word for it.

The public demo runs the same review surface on a clearly labeled illustrative estate — no login, no connectors, nothing leaves the page. Open it, click through a finding, and check whether the evidence separation is real. Then read the matching sample readout.

Product proof points:

- One accountable record per agent — Mandate, owner, authority, tools, risk, and activity — joined from the systems that actually hold them.
- Unknowns stay unknown — Coverage, freshness, collector state, and known limitations are separate fields — missing evidence is a named gap, never a silent zero.
- The human stays the authority — Findings arrive as proposals with evidence attached. Approval is a decision a person makes, not a default the system takes.
- From signal to receipt — Finding, evidence, proposed work, approval, work item, and receipt stay separate — so approval never implies execution.

The demo estate is fictional and labeled as such. [Explore the demo](https://demo.celest.dev/reviews) · [Read the sample readout](https://celest.dev/agent-estate-review/sample)

## Why us

### We built this by living the problem.

Dillon created Amplify Flutter at AWS, then took the original Celest through Y Combinator as “the Vercel of Flutter.” Celest started with the same instinct it has now: remove the gap between what people mean to do and what the cloud makes painful.

Now the builders are humans plus agents, and Microsoft is assembling the substrate where they work. We are building Celest by running straight into these seams ourselves, which is why the product starts with accountability instead of magic.

Today that means a live Estate Review API, a signed-in review surface, a public demo that does not fake liveness, and a headless Microsoft path that stays clearly experimental until it earns more trust. Live means a mature capability Celest is prepared to contract, deliver, operate, and stand behind.

[See Celest's YC W24 origin](https://www.ycombinator.com/companies/celest) · [Read the source-backed methodology](https://celest.dev/learn/agent-estate-review)

> The agents are real. The operating model has to be too.

## A deeper Celest path

### Bring us the seams your estate can't explain.

Two weeks from scattered Microsoft records to one accountable operating picture and a plan.

[Request an Estate Review](mailto:founders%40celest.dev?subject=Agent%20Estate%20Review&body=Hi%20Celest%20team%2C%0A%0AI%27d%20like%20to%20explore%20an%20Agent%20Estate%20Review.%0A%0AOrganization%20%28optional%29%3A%0AMy%20role%3A%0AWhat%20made%20this%20relevant%20now%3A%0AWho%20else%20should%20join%20if%20we%20continue%3A%0AHow%20did%20you%20find%20Celest%3A%0A) · [Start here](https://celest.dev/#start)
