Sample readout · Agent Estate Review
What two weeks
actually hands you.
This is the shape of a Celest Agent Estate Review readout, shown on a small fictional estate so you can see every moving part. The records are illustrative; the structure, evidence rules, and plan are the real deliverable.
- Illustrativefictional records, labeled throughout
- Read-onlyleast-privilege observation only
- 3 agentsprimary platforms: Copilot Studio · Teams · Foundry
- 2 weeksfixed scope, fixed deliverables
01 · Executive readout
The estate in one honest paragraph.
The readout opens with what a leadership team can act on: what exists, what is healthy, what needs a decision, and — equally important — what the evidence could not establish. Nothing below is a guess; every number names its source coverage.
Readout summary. All three agents in this estate have a named, accountable sponsor. One finding needs a decision: Manny's delivery lookup carries write scope it has never used. Two estate-wide facts could not be established — cost and an authoritative activity trail — and this report names them as unknowns rather than filling them with reassuring zeros.
02 · Canonical records
One accountable record per agent.
Each agent's identity, owner, authority, lifecycle, and cost are joined from the systems that actually hold them. Where a source cannot answer, the record says so — an unknown is a named gap, never a silent default.
agent:scout3 source observations- Identity
- Scout Copilot Studio + MCP
- Owner
- Dillon R. accountable sponsor
- Authority
- Read, suggest, route no source mutations
- Lifecycle
- Active last observation 8 min ago
- Cost
- unknown billing source not connected
- Source health
- 94% coverage
agent:harold3 source observations- Identity
- Harold Teams + SharePoint
- Owner
- Dillon R. accountable sponsor
- Authority
- Draft and escalate no policy decisions
- Lifecycle
- Active 42 conversations this week
- Cost
- unknown billing source not connected
- Source health
- 89% coverage
agent:manny3 source observations- Identity
- Manny Foundry + Outlook + Power Platform
- Owner
- Dillon R. accountable sponsor
- Authority
- Read status, propose work no direct execution
- Lifecycle
- Active 184 observed connector calls in 30 days
- Cost
- unknown billing source not connected
- Source health
- 96% coverage · 1 finding
03 · Findings & unknowns
Findings carry their evidence.
Unknowns stay unknown.
A finding exists only where the required evidence exists. Where it doesn't, the report says "unknown" and names what would establish the fact. That discipline is what makes the rest of the report safe to act on.
Manny's delivery lookup can write to a shared list
A connector used by the delivery agent has write access, but this workflow only needs to read status.
- Agent
- Manny · Delivery operations
- Tool
- Delivery status lookup
- Connector
- SharePoint · Celest Operations
- Observed permission
Sites.ReadWrite.All- Observed connector activity
- 184 calls / 30 days · 0 list items created or edited
- Evidence state
- Observed · partial coverage (91%) · sampled connector activity
- Known limitation
- Permission history and connector activity are sampled
A read-only scope would preserve the workflow and shrink the blast radius. Proposed work: replace Sites.ReadWrite.All with Sites.Read.All and run a smoke test against the delivery-status list — handed to a human as work item CEL-184. Nothing executes from the review itself.
Named unknowns in this estate
- Cost is unknown — not $0. No billing source is connected, so spend is a named gap with an owner and a 30-day action, not a reassuring zero.
- Estate-wide activity is not established — not "no activity." The activity collector is not an authoritative audit log. Scoped records can still carry labeled observations from their own evidence source; the report does not claim a complete estate-wide activity history.
- Permission history is partial — not "no drift." Sampled history at 91% coverage means drift outside the sample is a possibility the plan addresses, not a risk the report hides.
04 · Operating plan
A 30 / 60 / 90 your team can actually run.
Every plan item traces to a finding or a named unknown, and every consequential action waits for a human decision. This is the excerpt a team would take into its first week.
-
30 days
- Decide on CEL-184: reduce Manny's delivery lookup to read-only, with a smoke test against the delivery-status list.
- Connect the billing source so agent cost moves from unknown to observed.
- Establish an authoritative activity trail so "what did agents do" becomes answerable.
-
60 days
- Set a sponsor review cadence for Harold's policy escalations (1 unresolved thread at review time).
- Raise connector permission coverage from 91% to ≥ 95% and record the remaining limitation.
- Confirm every agent's authority statement still matches what its tools can do.
-
90 days
- Repeat the estate review on a schedule instead of as a one-off project.
- Decide which recurring findings graduate to governed execution with verification and receipts.
- Retire or re-own anything that still has no accountable sponsor.
05 · Coverage & proof
Every claim names its source.
The readout closes with the evidence itself: which sources supported which facts, how fresh they are, and what their known limitations are. Origin, coverage, evidence state, collector status, freshness, scope, and limitation stay separate — that separation is the product.
This sample is illustrative. The same structure — inventory, findings, unknowns, plan, proof — is what a read-only Estate Review produces against your real Microsoft estate. Read the source-backed methodology
See it on your estate
Your agents are real.
The readout should be too.
Two weeks from scattered Microsoft records to one accountable operating picture and a plan.