/ Guide / Platform
Azure infrastructure management, inside a released profile.
Azure infrastructure management on this site means one specific thing: Microsoft 365 and Azure operated to the Surya standard in the tenant you own. It is a supported foundation with a boundary, not an open engagement to run whatever appears in the subscription.
Surya operates the supported technology foundation. The business, its applications, its AI workflows, access decisions and data authority stay with your organization.
/ In the tenant you own
What the supported foundation covers.
- Identity, access, device management, the security baseline and updates, operated to the released profile.
- Device configuration, protection and protected-data recovery for the endpoints inside the purchased scope.
- Identity recovery paths, joiner and leaver handling, and the denial of an unauthorized recovery attempt, tested at acceptance.
- Configuration verification and audit evidence for the actions taken inside the released profile.
The tenant and the licenses are yours. Each released profile has a license and control matrix, so a capability your licenses do not include is named rather than quietly dropped from the baseline.
/ How it is operated
Surya Control operates it, and stops when unsure.
Routine operations run from an allowlisted, tested catalogue under a standing policy, so an engineer does not approve every ordinary execution. Privilege grants, destructive changes and broad policy changes require explicit authorization. An unknown or unsafe condition stops the action, preserves the evidence and raises the product exception path. The identities Surya uses live in your own Microsoft 365 tenant, where your administrator can see, audit and revoke them.
Continuous monitoring is not the same as staffed round-the-clock incident response. Consequential changes, including privilege grants, destructive actions and broad policy changes, require explicit authorization from an accountable owner in your organization.
/ The boundary
Where the foundation stops.
- Arbitrary Azure workloads are not implicitly covered. They require a separately released profile, not a custom statement of work.
- Servers, industrial control systems, medical devices, custom voice systems and specialized peripherals are outside the released profile unless separately qualified.
- Your organization owns the AI workflows, the integrations, the process redesign, the change management and the business outcomes.
- Business-application defects and application development stay with the vendor that owns them.
- AI, cloud and backup consumption is billed to your own accounts by the providers, separately from Surya.
Prerequisites belong to the product you select, and some prerequisites affect the wider Microsoft tenant. Anything that must change first is stated in writing, with the approvals required, before an order is accepted.
The reason for that boundary is the same reason the rest of the product is standardized: a released profile can be operated, tested and recovered the same way at every customer, while a one-off workload cannot. A capability outside the profile is not refused quietly. It is named, and if it belongs in the product it becomes a released profile with its own prerequisites and acceptance tests.
Surya Standby, Surya Endpoint and Surya Fabric are the three product-level buying options. Standby is a complete standalone product on its own, and Endpoint and Fabric are added on top of it, independently, in either order or together. Surya Foundation is Standby, Endpoint and Fabric together. Surya Control is embedded in Endpoint, Fabric and Foundation rather than sold beside them, and is not used by Standby alone.