CELEST Agent Estate Review · Public Specimen
Doc № CEL-2026-0726 Classification: Public Prepared: July 2026 Rev B: the rebirth

Celest · Y Combinator W24 · reborn July 2026 Confirmed fact

The agent-native control plane for the Microsoft cloud.

Enterprises are deploying AI agents faster than anyone can answer for them. Celest lets enterprises and their agents discover, govern, and safely operate agents and workflows across Microsoft 365, Copilot Studio, GitHub, and Azure DevOps. Evidence before action; explicit authority; receipts that close the loop.

Celest mark: a cloud whose right lobe forms a bird, with a four-point star
Fig. 0 · the mark: the cloud, made canonical.

Reading key — every claim in this document is stamped with its evidence level

Confirmed fact

Public record or directly inspected evidence establishes the claim.

Current proof

Implemented and tested in our development boundary today. Not yet a production service.

Hypothesis

A belief we are actively validating with customers and partners.

Roadmap

Intended work. Not shipped, and not presented as shipped.

We would rather be checkable than impressive. The same discipline is the product: an estate you can trust is one where every state, decision, and action carries its evidence.

Sheet 02 · Exhibit AThe operating condition

One agent. Five admin centers. No single answer.

Microsoft is assembling an agent platform across Entra, Microsoft 365, Copilot Studio, Power Platform, GitHub, and Azure DevOps. Each product exposes useful state, but the operating lifecycle crosses their boundaries. Confirmed fact

Which records refer to the same agent? Who owns it, what can it touch, what does it cost, is it failing, and who may act on that? Today those answers are stitched together by scarce specialists in spreadsheets and tickets, or skipped. As agent count and autonomy grow, the seams become the operational and security bottleneck. Hypothesis

Synthetic example illustrative record · hover or focus a source to see what it contributes, and what it cannot seeillustrative record · each source is truthful about its slice, and blind to the rest

contributes ↓

Entra ID

Object
svc-quotebot-prd
Permissions
Graph · Sites.Read.All
Owner
— not recorded
Cost
— out of scope
contributes ↓

M365 Admin

App
QuoteBot
Assigned to
Sales-EMEA (214)
Model
— not visible
Source
— not visible
contributes ↓

Copilot Studio

Agent
Quote Assistant
Tools / MCP
4 connectors · 1 MCP
State
Published
Spend
— unattributed
contributes ↓

Power Platform

Environment
prod-emea
Connections
Dataverse · SP · HTTP
Maker
l.moreau (left org)
Lineage
— unknown
contributes ↓

GitHub

Repo
contoso/quotebot
Checks
CI ✓ · review required
Runtime id
— unlinked
Deployed?
— unknown

Five partial records. Zero accountability. Each surface is truthful about its slice and blind to the rest.

Celest joins them into one canonical record with provenance: every field traceable to its source, every gap kept honestly unknown. This is the state that agents and humans can safely act from.

Current proof

Canonical record — agent/quotebot join provenance · source health 5/5
Identitysvc-quotebot-prd ↔ Quote Assistant ENTRACPS
Ownerl.moreau · departed org · sponsor unassigned PP
Reach214 users · Sales-EMEA M365
Capability4 connectors · 1 MCP · Sites.Read.All CPSENTRA
Sourcecontoso/quotebot · CI ✓ GH
Costunknown · billing source unavailable, kept unknown (not zero)
FindingF-SAMPLE: production agent, 214 users, no accountable owner ENTRAPPM365CPSGH

Illustrative agent record; no customer data appears in this document. “Unknown is not zero”: missing or unhealthy source data stays unknown and can never justify a cost, risk, or deletion decision.

Sheet 03 · Operating procedureKnowing → doing

From knowing to doing, with receipts.

The gap worth owning is not another inventory screen. It is the transition between evidence and verified action: performed today by hand, or not at all. Celest makes that transition a governed procedure that humans and agents can operate.

STEP 1Discover Evidence snapshots across every surface, with source health and provenance recorded. Current proof
STEP 2Diagnose Deterministic, evidence-backed findings: ownership, lifecycle, capability, cost, risk. Current proof
Read-only boundary: today’s product stops here, by design the product earns autonomy
STEP 3Propose Inspectable plans: proposed work, predicted effects, required authority. Roadmap
STEP 4Approve Explicit human or policy authority: an inspectable decision, never a vibe. Roadmap
STEP 5Execute Bounded, provider-native mutations. Reversibility scales the authority required. Roadmap
STEP 6Verify An API success response is not an outcome. Fresh observation, immutable receipt. Roadmap
STEP 7Reconcile The originating finding closes against observed state, or reopens loudly. Roadmap

Every consequential action will leave one of these.

Identity, scope, authority, provider operation, observed outcome. Agents become safe operators when their actions are this inspectable. So do we.

Synthetic example Roadmap

Evidence before action Unknown is not zero Authority is data Receipts close the loop The product earns autonomy

Sheet 04 · Findings of the present reviewSubject: Celest, as Customer Zero

We reviewed ourselves first. Here is what is real.

Celest operates on Celest — the first estate under review is our own. These findings state exactly what exists today, at the evidence level we would demand from anyone else.

RefFindingEvidence
F-01 Canonical contracts exist as a dependency-free boundaryVersioned collection runs, agent snapshots, identity & join provenance, findings, acknowledgements. Current proof
F-02 Read-only Estate Review API, fail-closedScoped sync, inventory, detail, findings, and acknowledgement; Microsoft-facing routes stay read-only. Current proof
F-03 Entra-authorized, tenant- and environment-scoped accessClaims-derived tenant policy with exact environment enforcement in the Dev host. Current proof
F-04 Durable Dataverse persistence behind the APIFive-table schema, relationships, alternate keys, and an application-user boundary proven in Dev. Current proof
F-05 Hosted Azure control plane passing live checksDigest-pinned Container Apps revision: health, readiness, workload identity, protected sync, Dataverse readback. Current proof
F-06 A signed-in Power Apps Code App on the same APIOne solution-owned connector, truthful live provenance, no fixture fallback. Current proof
F-07 Agentic GitHub stewardship as the product laboratoryAgent workflows review pull requests and reconcile post-merge issues with scoped evidence and safe outputs. Current proof
F-08 Headless Copilot Studio authoring & publicationEntra OAuth, model/tool discovery, agent creation, save, and publish exercised end to end.Experimental · quarantined: private, session-bound contracts; excluded from the product API Current proof
F-09 Azure DevOps lifecycle adapterThe strategic enterprise provider: articulated, not implemented. Roadmap
F-10 Multi-tenant commercial serviceOnboarding, billing, support, SLAs: not built. The wedge ships first. Roadmap
Disclosure. The examined deployment is a bounded development environment, not a production service. No customers, revenue, or usage are claimed anywhere in this document: none exist yet. We publish what is proven and stamp what is not; that discipline is the company.
Sheet 05 · Engagement termsThe first offer

First engagement: the Microsoft Agent Estate Review.

A two-week, fixed-scope, read-only review of your Microsoft agent estate. Software gathers and normalizes the evidence; we sit with you to turn findings into an operating plan. Repeated delivery steps become product, and the review grows into recurring, managed AgentOps. Hypothesis

You provide

  • A bounded tenant & environment scope
  • Supported, read-only access to the relevant Microsoft sources
  • Stakeholder interviews: platform, security, and business owners
  • Optional: licensing, Copilot Credit, GitHub, Azure DevOps evidence

You receive

  • A normalized agent inventory with source & join provenance
  • Ownership, lifecycle, tool/MCP, usage, cost, and risk findings
  • An executive posture report that distinguishes zero, false, unknown, and unavailable
  • Prioritized proposed work with evidence and expected outcomes
  • An authority & operating-model workshop, and a 30/60/90-day AgentOps plan
Duration: two weeks Access: read-only, least privilege Scope: fixed Data: identifier-minimized reporting Pricing: on request
Request an Agent Estate Review Or write directly: dillon.andre.nys@gmail.com. You get a scoping sheet back, not a sales sequence.
Sheet 06 · Opinion of the preparerWhy this founder, again

A letter on the rebirth.

To the reader —

At AWS I created Amplify Flutter, and watched developers lose their momentum in the seams between application and cloud. In 2024 I took Celest through Y Combinator as “the Vercel of Flutter” — one language, one toolchain, no seams. Confirmed fact

The actor has changed. It is no longer a developer alone in an IDE; it is an organization of humans and AI agents operating the Microsoft cloud together. The seams moved up a layer: identity, authority, evidence, cost, work. And they are widening exactly as fast as enterprises deploy agents.

The insight did not change at all: remove the seams between what a builder intends and what the cloud requires. Celest is reborn as that layer for the Microsoft enterprise: the control plane where evidence precedes action, authority is data, and every consequential act leaves a receipt.

We run Celest on Celest, we publish our evidence levels, and we will earn autonomy the same way we ask agents to: one verified action at a time.

Dillon Nys Founder, Celest · previously Amplify Flutter at AWS · Y Combinator W24

End of specimen · the full review is prepared per estate

The Microsoft estate is becoming agent-native. Operate it with evidence.

Request an Agent Estate Review dillon.andre.nys@gmail.com