Surya Agent Platform · Built on Microsoft
Your people. Your agents. A foundation ready for both.
A configured and operated Microsoft environment where your team can build, deploy and run AI agents. Surya establishes the identity, data access, environments and operating controls. You decide what your agents do.
For healthcare and manufacturing organizations, including their administrative and regulated operations, that want their own teams building agents on the Microsoft tools they already trust.
Your Microsoft tenant stays yours: your administrators keep ownership and can revoke Surya's access.
Your agents
Owned by you
Business agents and workflows
Surya Agent Platform
Operated by Surya
Microsoft agent foundation
- Identity and access
- Approved data and connections
- Build, test and live environments
- Release, telemetry and cost controls
In your Microsoft tenant · Copilot, Copilot Studio, Power Platform, Entra, SharePoint, Purview where licensed
Physical foundation
Optional, bought separately
Devices, sites and equipment
Or your existing equivalent environment
/ The product
What you are buying
A configured environment in your own Microsoft tenant, with Surya responsible for operating the agreed platform baseline.
A configured environment
Identity, permissions, approved knowledge, connections and separated build, test and live environments, set up to a written baseline in your tenant.
An operating responsibility
Surya keeps the contracted baseline working: access reviews, platform changes, available telemetry, capacity and spend visibility, and escalation to Microsoft.
A team ready to build
Your administrators and makers are onboarded with runbooks and a validated reference scenario, so they can build the agents your business needs.
/ What's included
Six workstreams. Each with outputs you can check.
Quantities and entitlements for each workstream are set in your written schedule before work starts.
01
Supported environment and licensing baseline
We inventory your tenant and licenses, confirm a supported Microsoft commercial-cloud profile and agree which Microsoft 365 Copilot, Copilot Studio and Power Platform capabilities are in scope.
You receive
- Tenant and license inventory
- Agreed capability list
- Roles, capacity and billing ownership recorded
- Your tenant ownership and admin revocation confirmed
02
Identity and permissions
Maker, operator and user groups, approved admin access and agent or connection identities using supported options, all on least privilege.
You receive
- Group and role design you approve
- Approved admin access
- Agent and connection identities
- Tested access denial
03
Data and connection readiness
Named, approved SharePoint and Teams knowledge locations and supported connectors, with scoped permission and oversharing corrections for those locations.
You receive
- Named knowledge locations and connectors
- Scoped permission corrections
- A named data owner for each location
- Retention and data-policy controls where licensed
Scoped to the named locations. Not estate-wide cleanup, file migration or content curation.
04
Build, test and live foundation
Separated development, test and production environments for the supported workloads, with a solution and configuration lifecycle and clear release ownership.
You receive
- Dev, test and production environments
- Solution and configuration lifecycle
- Documented release approvals
- Repeatable configuration record
Promotion support varies by agent type and Microsoft capability; it is recorded for each workload.
05
Operability
An inventory of in-scope agents and their owners, the Microsoft platform telemetry and alerts available for them, and a defined path for incidents and vendor escalation.
You receive
- Agent and owner inventory
- Available telemetry and agreed alerts
- Capacity and spend visibility
- Incident, vendor escalation and change review
Spend alerts are not a hard spending cap, and custom agents expose only the telemetry they emit.
06
Team enablement and acceptance
Bounded onboarding sessions for your administrators and makers, runbooks and knowledge handover, plus a repeatable validation agent run in test.
You receive
- Admin and maker onboarding sessions
- Runbooks and knowledge handover
- Validation agent in a non-production environment
- Acceptance evidence pack
The validation agent proves the platform. It is not your business workflow or a library of prebuilt production agents.
/ Built on Microsoft
The Microsoft stack, and what each part does here.
Azure services and custom engineering are available only through separately validated scope. Copilot and agent capabilities need the appropriate Microsoft licenses or capacity; an existing Microsoft 365 plan does not include all of them, and feature and connector availability varies by cloud.
- Microsoft 365 Copilot
- The licensed employee experience for people who have it.
- Copilot Studio and Power Platform
- Where your team builds supported agents and automation.
- Microsoft Entra
- Who and what can access each agent, connection and environment.
- SharePoint
- The approved knowledge your agents may use.
- Microsoft Purview
- Retention, labeling and data-policy controls, where licensed.
/ From first year to ongoing operation
Establish it in year one. Keep it ready as you grow.
Two defined phases for the same agreed footprint. Both scopes and fees are agreed in writing before work starts.
Year one
Establishment and enablement
A 12-month phase that establishes the foundation, readies permissions and data, enables your team and stabilizes operation.
- The six workstreams delivered to the written schedule
- Onboarding sessions and runbooks
- Validation agent and acceptance evidence
- Monthly platform review
- Operation of the baseline from the day it goes live
Ongoing
Steady-state platform operation
A separately defined phase, at a lower fee, that keeps the same footprint current and ready as Microsoft and your team move forward.
- Configuration and change control for the baseline
- Access and permission reviews
- Platform incident handling and Microsoft escalation
- Capacity and spend oversight
- Quarterly owner review
The move to ongoing operation follows agreed acceptance and stabilization. If prerequisites are delayed, we replan together; there is no automatic extension or extra charge unless both sides agree.
Microsoft licenses, usage and credits, third-party products and any expansion are itemized separately. Pricing is set in your written proposal.
/ Responsibilities
Who owns what.
Microsoft
The software, cloud services, models and product capabilities, under your Microsoft agreements.
Surya
Configures and operates the contracted baseline: identity, approved data and connections, environments, release process, available telemetry and spend visibility. Supports faults in that foundation.
Your organization
Your agents and the workflows they run, business logic, prompts and content quality, decisions and approvals - built by your team or a workflow builder you choose. Agent behavior and custom code stay with their owner.
/ Illustrative examples
Examples of agents your team could build.
These are illustrations of customer-built agents, not features Surya ships. People stay in charge of clinical, regulatory and production decisions.
Example
Approved-policy assistant
Answers staff questions from approved policies and procedures, citing the source.
Example
Internal request triage
Sorts routine service and facilities requests and routes them to the right team.
Example
Operational document drafting
Drafts and summarizes shift notes, meeting records and operating documents for a person to finish.
Example
Quality and admin preparation
Gathers the material for quality or administrative work so a person can review and decide.
/ Physical businesses
Connected to how your sites actually run.
Agents are only as useful as the devices, access and sites they reach. Surya Endpoint, Surya Fabric and Surya Standby can supply that physical foundation, each bought on its own. If an equivalent environment already exists, Agent Platform works with it. Nothing is bundled, and no other purchase is required.
Agent Platform on its own does not include equipment logistics, lockers, network rebuilds or Surya Control. Surya Foundation remains Endpoint, Fabric and Standby, and does not include Agent Platform unless it is bought separately.
/ Acceptance
Know when your foundation is ready.
Acceptance is a set of checks we run with you, recorded in the handover pack.
- Owners recorded for the platform, each environment and each knowledge location
- Access granted and denied as designed, with tested denial
- Approved knowledge connected and reachable only by the right people
- Validation agent running in test
- Controlled release and disable demonstrated where the capability supports it
- Telemetry and cost review completed
- Runbooks handed over
- Exception list signed by both sides
/ Questions
Agent Platform questions
What is included?
Six workstreams to a written schedule: environment and licensing baseline, identity and permissions, data and connection readiness, build-test-live environments, operability, and team enablement with acceptance. Counts and entitlements are set in the schedule before work starts.
We already have a Microsoft tenant and an IT team. Does that work?
Yes. Agent Platform is built in your existing tenant, which you keep. We agree roles with your team, and your administrators keep ownership and can revoke Surya's access.
Does Surya build our agents?
Your team, or a workflow builder you choose, builds and owns the business agents. Surya establishes and operates the foundation, enables your makers and provides a validation agent to prove the platform. Building specific business agents can be scoped separately.
Will Microsoft charge extra?
Usually, yes. Copilot licenses, Copilot Studio capacity or credits and other Microsoft usage are billed under your Microsoft agreements or itemized separately in your quote. We confirm billing ownership during the baseline workstream.
How does the first year lead to ongoing operation?
Year one establishes, enables and stabilizes the platform. After agreed acceptance and stabilization, a separately defined, lower-fee ongoing phase keeps the same footprint operated. Both are agreed before work starts.
How is this different from Surya Endpoint and agent operations?
Surya Endpoint operates your workstations, identity lifecycle and device access. Agent operations describes how Surya runs its own products with AI and people. Agent Platform is the environment where your team builds and runs its own agents.
Which Microsoft clouds are supported?
The standard offer uses a supported Microsoft commercial-cloud profile. Government clouds and specific features or connectors are qualified separately, because availability differs by cloud.
Defense suppliers: cloud, data and feature eligibility are qualified separately for each enquiry.
Start with the foundation. Build what your business needs.
Tell us about your Microsoft tenant, the teams who would build agents and what you want them to work on. Surya returns a supported first scope, prerequisites, who owns what and written commercial next steps.