Celest

Control plane · v0.1 · agent-native

Evidence becomes
governed action.

Celest is the agent-native control plane for the Microsoft cloud. Discover every agent across Copilot Studio, Microsoft 365, GitHub, and Azure DevOps — then run one canonical lifecycle from evidence to approval to a verified receipt. The same loop, for the humans and agents operating the estate.

Every claim on this page is labeled by evidence. Live · read-only Experimental Roadmap

The rebirth

You knew Celest as
the Vercel of Flutter.

In YC W24, Celest let Flutter developers declare their backend in Dart and deploy it like magic — removing the seams between what a builder intends and what the cloud requires. The insight holds. The layer changed.

The builder is now a human-plus-agent organization. The cloud narrowed from generic infrastructure to the Microsoft substrate where enterprise identity, communication, work, code, data, and automation already live. Same founder. Same instinct. One layer up.

  • Flutter developers forced across fragmented cloud toolchains. Operators and agents forced across fragmented Microsoft control planes.
  • Cloud Widgets made infrastructure declarative. Canonical plans, authority, and receipts make operations inspectable.
  • Generated clients connected app code to the cloud. API, MCP, CLI, and UI adapters connect agents to governed capability.
  • Hid accidental complexity, never the developer's intent. Normalizes Microsoft complexity without erasing provider-native power.

The problem

One agent, scattered across
a dozen admin centers.

Microsoft is assembling an agent platform across Entra, Microsoft 365, Copilot Studio, Power Platform, Foundry, Agent 365, GitHub, and Azure DevOps. Each surface knows a sliver. None of them knows the agent.

Copilot Studioagent · “Contoso Renewals Copilot”
Entra IDservice principal · a91f…e4
Power Platformenv · Prod-EU · maker unknown
Copilot Creditsspend · unattributed
GitHubrepo automation · 2 workflows
Securityoversharing · not evaluated
canonical agent:ap-3f7c · joined from 6 sources
Identity
Contoso Renewals Copilot ↳ Studio + Entra
Owner
unknown ↳ no maker record
Lifecycle
published · assigned · idle 41d
Cost
unknown ↳ credits unattributed
Risk
unknown ↳ oversharing not evaluated
Source health
2 sources degraded

The highest-value gap is not another inventory screen. It is the transition between knowing and doing — today performed by scarce specialists, improvised in spreadsheets and tickets, or skipped. As agent count and autonomy rise, that becomes the bottleneck.

The lifecycle

From knowing to doing —
one governed loop.

The interface is replaceable. The durable product is the canonical lifecycle and the evidence it accumulates. Every consequential step has an inspectable actor, scope, decision, and policy basis — and closes with a receipt, not an API “success.”

  1. 01
    Observation

    A change or scheduled sweep triggers the loop.

  2. 02
    Evidence snapshot

    Immutable, with source health and provenance.

    EvidenceSnapshot
  3. 03
    Finding

    A deterministic finding or an agent decision.

    Finding
  4. 04
    Proposal

    Proposed actions and their predicted effects.

    LifecyclePlan
  5. 05
    Authority

    Explicit approval or a policy-based decision. The gate.

    AuthorityDecision
  6. 06
    Execution

    Provider-native mutation within bounded scope.

  7. 07
    Receipt

    An immutable record of what actually happened.

    ExecutionReceipt
  8. 08
    Reconcile

    Fresh observation closes the finding — or reopens it.

Evidence before action.

Unknown is not zero.

Authority is data.

Receipts close the loop.

What's true today

We hold ourselves to the same
evidence standard we sell.

Unknown is not zero. Here is exactly what is built, what is experimental, and what is still roadmap — no invented traction. The current MVP is a read-only Dev deployment, not a multi-tenant production service.

Capability Evidence What's established
Canonical contracts Live Versioned collection runs, agent snapshots, identity & join provenance, findings, acknowledgements — a dependency-free boundary.
Read-only AgentOps composition Live Joins registry, Power Platform, usage, tools, MCP policy, risk, and source health into sanitized snapshots. Acquires no credentials; mutates nothing.
Estate Review API Live A fail-closed API for scoped sync, inventory, detail, findings, and local acknowledgement. Every Microsoft-facing route is read-only.
Entra & environment authorization Live Validates Entra access; enforces claims-derived tenant plus exact environment policy on the Dev host.
Durable Dataverse persistence Live Five-table schema, relationships, alternate keys, canary roles, application-user boundary — empty-estate round trip proven in Dev.
Unified Power Apps Code App Live Signed-in app calls the protected API through one solution-owned connector and renders truthful live provenance — no fixture fallback.
Hosted Azure control plane Live A digest-pinned Container Apps revision passed health, readiness, workload identity, protected sync, and Dataverse readback. A bounded Dev deployment.
GitHub review & issue stewardship Live Agentic workflows review PRs and reconcile post-merge issues with scoped evidence — the product laboratory, not yet a general adapter.
Copilot Studio authoring & publish Experimental Headless research exercised OAuth, model/tool discovery, Foundry-compatible calls, create/configure/save/publish. Some contracts are private and quarantined.
Browser extension Experimental A compatibility adapter that proved native-chat interception and catalog reconnaissance. Not the product center; never a required credential path.
Azure DevOps lifecycle adapter Roadmap The provider strategy is articulated; no adapter is implemented yet. We do not present it as shipped.
Multi-tenant commercial service Roadmap The architecture anticipates tenant partitioning. Onboarding, billing, support, SLAs, and production operations are not built.

The map

The Microsoft AI
Operations Stack.

Five layers of operating outcome around one canonical estate. We lead with AgentOps — the registry, lifecycle, authority, and receipt layer — and expand outward from there.

LicenseOpsSeats, adoption, utilization, renewal evidence.Native usage → review & decisions.
CreditOpsAttribute Copilot Credits and service spend; budgets and alerts.Join cost to agents, owners, outcomes.
GuardOpsReadiness, oversharing, identity, policy, and risk gaps.Evidence-backed findings & governed remediation.
the wedgeAgentOpsDiscover, own, observe, deploy, and manage agents through their lifecycle.The canonical registry, lifecycle, authority & receipt layer.
WorkflowOpsTransform business processes with agents and Power Platform.Repeatable delivery & outcome verification.

Start here

The Agent Estate Review.

A two-week, fixed-scope engagement. Read-only. Software gathers and normalizes the evidence; together we turn fragmented registry, cost, security, and ownership signals into an operating plan — then become the recurring AgentOps layer underneath it.

Inputs

  • A bounded tenant / environment scope
  • Supported read access to relevant Microsoft sources
  • Interviews with platform, security & business owners
  • Optional licensing, credit, GitHub & Azure DevOps evidence

Outputs

  • Normalized agent inventory with source & join provenance
  • Ownership, lifecycle, tool, MCP, usage, cost & risk findings
  • A posture report that distinguishes zero, false, unknown & unavailable
  • Prioritized work with evidence and expected outcomes
  • An authority & operating-model workshop
  • A 30/60/90-day AgentOps plan

Then it expands

  • Recurring managed Estate Review
  • LicenseOps & CreditOps reporting
  • GuardOps & identity remediation
  • Governed work-item creation
  • Lifecycle execution after explicit control gates

Why this founder · why now

Built the platform.
Now Customer Zero.

Dillon created Amplify Flutter at AWS, watched developers struggle with the seams between application and cloud, and built the original Celest around that pain — through YC W24. He now operates Microsoft as both a builder and an administrator, running a real tenant.

Celest is Customer Zero for the agent-native operating model it sells: agent identity and sponsorship, permission tiers, findings, approvals, interventions, and receipts — captured as evidence. The product came from direct reverse-engineering and use, not a market map.

Why the window is open

  • Microsoft is building the substrate — but the customer still owns the seams between products.
  • Agent 365 is positioned as an observability, governance, and security trust layer.
  • Copilot Credits make agent usage an operating-cost concern, not just a seat concern.
  • GitHub ships agentic workflows; Azure DevOps holds a huge installed base with no equivalent.

Microsoft will improve its native dashboards. Celest wins on cross-surface workflow, evidence continuity, customer policy, provider breadth, and speed — not on a temporary private endpoint.

The loop is open.

Celest is taking a small number of design partners for the first paid Estate Reviews. If you run a Microsoft-centric estate — or serve one as a partner — and agent sprawl is becoming your problem, let's talk.