Celest
Sections
Explore the demo

Sample readout · Agent Estate Review

What two weeks
actually hands you.

This is the shape of a Celest Agent Estate Review readout, shown on a small fictional estate so you can see every moving part. The records are illustrative; the structure, evidence rules, and plan are the real deliverable.

  • Illustrativefictional records, labeled throughout
  • Read-onlyleast-privilege observation only
  • 3 agentsprimary platforms: Copilot Studio · Teams · Foundry
  • 2 weeksfixed scope, fixed deliverables

01 · Executive readout

The estate in one honest paragraph.

The readout opens with what a leadership team can act on: what exists, what is healthy, what needs a decision, and — equally important — what the evidence could not establish. Nothing below is a guess; every number names its source coverage.

3agents foundCopilot Studio · Teams · Foundry
3 / 3have an accountable sponsoridentity joined across sources
1open findinghigh · least privilege
2 / 3sources availableactivity collector not established

Readout summary. All three agents in this estate have a named, accountable sponsor. One finding needs a decision: Manny's delivery lookup carries write scope it has never used. Two estate-wide facts could not be established — cost and an authoritative activity trail — and this report names them as unknowns rather than filling them with reassuring zeros.

02 · Canonical records

One accountable record per agent.

Each agent's identity, owner, authority, lifecycle, and cost are joined from the systems that actually hold them. Where a source cannot answer, the record says so — an unknown is a named gap, never a silent default.

canonicalagent:scout3 source observations
Identity
Scout Copilot Studio + MCP
Owner
Dillon R. accountable sponsor
Authority
Read, suggest, route no source mutations
Lifecycle
Active last observation 8 min ago
Cost
unknown billing source not connected
Source health
94% coverage
canonicalagent:harold3 source observations
Identity
Harold Teams + SharePoint
Owner
Dillon R. accountable sponsor
Authority
Draft and escalate no policy decisions
Lifecycle
Active 42 conversations this week
Cost
unknown billing source not connected
Source health
89% coverage
canonicalagent:manny3 source observations
Identity
Manny Foundry + Outlook + Power Platform
Owner
Dillon R. accountable sponsor
Authority
Read status, propose work no direct execution
Lifecycle
Active 184 observed connector calls in 30 days
Cost
unknown billing source not connected
Source health
96% coverage · 1 finding

03 · Findings & unknowns

Findings carry their evidence.
Unknowns stay unknown.

A finding exists only where the required evidence exists. Where it doesn't, the report says "unknown" and names what would establish the fact. That discipline is what makes the rest of the report safe to act on.

High

Manny's delivery lookup can write to a shared list

A connector used by the delivery agent has write access, but this workflow only needs to read status.

Agent
Manny · Delivery operations
Tool
Delivery status lookup
Connector
SharePoint · Celest Operations
Observed permission
Sites.ReadWrite.All
Observed connector activity
184 calls / 30 days · 0 list items created or edited
Evidence state
Observed · partial coverage (91%) · sampled connector activity
Known limitation
Permission history and connector activity are sampled

A read-only scope would preserve the workflow and shrink the blast radius. Proposed work: replace Sites.ReadWrite.All with Sites.Read.All and run a smoke test against the delivery-status list — handed to a human as work item CEL-184. Nothing executes from the review itself.

Named unknowns in this estate

  • Cost is unknown — not $0. No billing source is connected, so spend is a named gap with an owner and a 30-day action, not a reassuring zero.
  • Estate-wide activity is not established — not "no activity." The activity collector is not an authoritative audit log. Scoped records can still carry labeled observations from their own evidence source; the report does not claim a complete estate-wide activity history.
  • Permission history is partial — not "no drift." Sampled history at 91% coverage means drift outside the sample is a possibility the plan addresses, not a risk the report hides.

04 · Operating plan

A 30 / 60 / 90 your team can actually run.

Every plan item traces to a finding or a named unknown, and every consequential action waits for a human decision. This is the excerpt a team would take into its first week.

  1. 30 days
    • Decide on CEL-184: reduce Manny's delivery lookup to read-only, with a smoke test against the delivery-status list.
    • Connect the billing source so agent cost moves from unknown to observed.
    • Establish an authoritative activity trail so "what did agents do" becomes answerable.
  2. 60 days
    • Set a sponsor review cadence for Harold's policy escalations (1 unresolved thread at review time).
    • Raise connector permission coverage from 91% to ≥ 95% and record the remaining limitation.
    • Confirm every agent's authority statement still matches what its tools can do.
  3. 90 days
    • Repeat the estate review on a schedule instead of as a one-off project.
    • Decide which recurring findings graduate to governed execution with verification and receipts.
    • Retire or re-own anything that still has no accountable sponsor.

05 · Coverage & proof

Every claim names its source.

The readout closes with the evidence itself: which sources supported which facts, how fresh they are, and what their known limitations are. Origin, coverage, evidence state, collector status, freshness, scope, and limitation stay separate — that separation is the product.

Agent configuration snapshotCelest Dev · Microsoft estate · observed 09:24 UTCComplete · collector ready · limitation: no live connector calls
Connector permission inventoryPower Platform · delivery · observed 09:32 UTCPartial · 91% · limitation: permission history and connector activity are sampled
Activity collectorCelest Dev · recent events · freshness not reportedUnavailable · not established · limitation: not an authoritative audit log

This sample is illustrative. The same structure — inventory, findings, unknowns, plan, proof — is what a read-only Estate Review produces against your real Microsoft estate. Read the source-backed methodology

See it on your estate

Your agents are real.
The readout should be too.

Two weeks from scattered Microsoft records to one accountable operating picture and a plan.

Request an Estate Review Explore the demo Back to Estate Review