/ Guide / Platform
Azure infrastructure management, inside a released profile.
Azure infrastructure management on this site means one specific thing: Microsoft 365 and Azure operated to the Surya standard in the tenant you own. It is a governed foundation with a boundary, not an open engagement to run whatever appears in the subscription.
Surya operates the supported technology foundation. The business, its applications, its AI workflows, access decisions and data authority stay with your organization.
/ In the tenant you own
What the governed foundation covers.
- Identity, access, device management, the security baseline and updates, operated to the released profile.
- The platform prepared for Microsoft Copilot Suite: identity, data governance, licensing and device compliance.
- Approved models, connectors, access groups and declared data boundaries under Surya AI Foundation.
- Usage visibility and audit, so AI access behaves as policy says it should.
The tenant and the licenses are yours. Each released profile has a license and control matrix, so a capability your licenses do not include is named rather than quietly dropped from the baseline.
/ How it is operated
Surya Control operates it, and stops when unsure.
Routine operations run from an allowlisted, tested catalogue under a standing policy, so an engineer does not approve every ordinary execution. Privilege grants, destructive changes and broad policy changes require explicit authorization. An unknown or unsafe condition stops the action, preserves the evidence and raises the product exception path. The identities Surya uses live in your own Microsoft 365 tenant, where your administrator can see, audit and revoke them.
Continuous monitoring is not the same as staffed round-the-clock incident response. Consequential changes, including privilege grants, destructive actions and broad policy changes, require explicit authorization from an accountable owner in your organization.
/ The boundary
Where the foundation stops.
- Arbitrary Azure workloads are not implicitly covered. They require a separately released profile, not a custom statement of work.
- Servers, industrial control systems, medical devices, custom voice systems and specialized peripherals are outside the released profile unless separately qualified.
- Your organization owns the AI workflows, the integrations, the process redesign, the change management and the business outcomes.
- Business-application defects and application development stay with the vendor that owns them.
- AI, cloud and backup consumption is billed to your own accounts by the providers, separately from Surya.
Prerequisites belong to the product you select, and some AI Foundation prerequisites affect the wider Microsoft tenant. Anything that must change first is stated in writing, with the approvals required, before an order is accepted.
The reason for that boundary is the same reason the rest of the product is standardized: a released profile can be operated, tested and recovered the same way at every customer, while a one-off workload cannot. A capability outside the profile is not refused quietly. It is named, and if it belongs in the product it becomes a released profile with its own prerequisites and acceptance tests.
Surya AI Foundation can be bought on its own or added as needs grow, subject to its own prerequisites. It is one of the three product-level buying options; Surya Control is embedded in it rather than sold beside it.