Engage
MICROSOFT AZUREagent()tool()data()usersurface()approve()

BUILT ON MICROSOFT AZURE

Internal apps and AI agents on Azure,minus the six weeks of plumbing.

A thin layer over your own Azure tenant. Your teams write the app. Rails deploys it on the right Azure services, puts it in Teams or on the web, and keeps IT in control of every call.

az login && npx rails init

Banner figure: Microsoft Azure assembled block by block in your own tenant, a request as one red block, the Console watching every workload, and the answer arriving in Teams.

Everyone in the building has a version of this pain.

IT lead
“I found the fourth Copilot Studio bot nobody registered.”
CFO
“Why do 340 people need a premium licence to file an expense?”
Developer
“I spent the sprint on app registrations. The app took a day.”
Business owner
“I built it in an afternoon. IT switched it off on Monday.”
Security
“Which of these tools is holding a connection string right now?”
CIO
“We bought Azure. Why does every internal tool live somewhere else?”

Coding agents made everyone a builder. Most tenants have nowhere safe to put what they build. Rails exists so every line above stops being true.

An abstraction over Azure, not a platform beside it.

Everything deploys to Azure, in your tenant. Rails decides which services, wires them together, and puts the app on the right surface. The Console, the first app Rails deploys, shows every workload you run on Azure with its traces, spend, and access rules.

Your teamswrite the app
A developersix primitives
const bot = agent({
  tools: [data("hr.leave")],
})
surface(bot, ["teams"])
A business userwith a coding agent
HR OPERATIONS, IN CLAUDE CODEBuild a leave-balance agent for Teams. Only HR may ask it.
Microsoft Railsthe thin layer
Microsoft Railsnpx rails init · in your tenant
TranslatesSix primitives become the right Azure services, wired together.
PlacesThe app lands on the right surface, with one sign-in.
GovernsIdentity, the gateway, and the audit log ride on every call.
Microsoft Azureyour tenant, nothing else
Twelve standard servicescontoso.onmicrosoft.com
Entra IDwho is asking, on every call
API Managementthe gateway in front of your data
API Centerthe registry of approved tools
Container Appshosts the apps and agents
AI Foundryruns the agents and the models
Durable Functionswaits for a person to decide
Bot Servicesthe Teams surface
Cosmos DBholds the access rules
Key Vaultholds the credentials
Application Insightsevery trace, every token
Log Analyticsthe one audit log
Azure SQLthe first data connector
The Console, the first app Rails deploys, watches every workload here.

Select a primitive. See the Azure underneath.

Six verbs. The whole leave agent is twelve lines, and it is authenticated, governed, audited, approvable, and live in Teams.

You write

1const bot = agent({2  instructions: "Handle leave requests",3  tools: [data("hr.leave"), tool(fileLeave)],4})5 6const fileLeave = tool(async (req) => {7  if (req.days > 5)8    await approve(user.manager, req)9  ...10})11 12surface(bot, ["teams"])

Instructions, a model, and the tools it may use. Nothing to provision.

Azure runs

  • Entra ID
  • API Management
  • API Center
  • Container Apps
  • AI Foundry
  • Durable Functions
  • Bot Services
  • Cosmos DB
  • Key Vault
  • Application Insights
  • Log Analytics
  • Azure SQL

An agent on Azure AI Foundry, hosted in Container Apps, registered in API Center, tracing into Application Insights.

One window on everything you run on Azure.

Observe. Every app and agent, which services it runs on, its traces, and its token spend, read from your own Application Insights. Free, because agent() wired it.

Govern. Who may reach which dataset, as one matrix. Approve new tools before anyone can call them. Read the audit log without opening the Azure portal.

console.contoso.internalpriya@contoso · Entra SSO
WorkloadsData accessRegistryAudit
Everything running on Azure4 workloads · traces and spend read from your own Application Insights
Leave agentHR engineering · Teams
214 traces
38.1k tokens today
Expense approverFinance · Teams · approve() on
96 traces
19.7k tokens today
Vendor lookupProcurement · web
57 traces
11.4k tokens today
Policy questionsOperations · Teams
133 traces
26.0k tokens today
AUDIT · LAST MINUTES
priya@contoso · leave agent read hr.leave as the caller · 1 rowallowed
mark@contoso · leave agent read hr.leavedenied
expense approver · approve() sent to anita@contoso, managerawaiting

Why not just…

…use Power Apps?
Fine for a form. Then the licences arrive per user, the app lives in the vendor's runtime, and the moment a maker needs real code, they are back here.
…use Copilot Studio?
Good for a topic. Rails is for the agents that outgrow one: real code, real data rules, a person in the loop, and no meter per message.
…assemble Azure ourselves?
You can. It is six weeks of specialist work per project, and it drifts. Rails is that assembly, done once, and the Console is the part nobody gets round to building.

The part your platform team will want to see.

Identity on every call

Every request carries an Entra ID token, down to Microsoft Graph and every data source. There is no anonymous path.

One gateway, no secrets in code

API Management sits in front of every dataset. Key Vault holds the credentials. Rows are filtered to the caller.

An audit log complete by construction

Every data call, tool call, and approval lands in Log Analytics with the identity it ran as. Nothing routes around the gateway.

Nothing leaves the tenant

Rails is software you deploy, not a service you subscribe to. Stop using it and every app keeps running on the services beneath it.

Ten minutes, in your own sandbox subscription: register one table, build one agent with a coding agent, watch one user get an answer and another get refused, and read both in the log.

Bring one tool your teams keep asking for. We will put it on Rails, in your tenant, while you watch.

The software factory →← Accelerators
Book a working session

A Damco strategist and a platform engineer. Strategize, build, operate, as with every Damco engagement.