Pillar 1 · ChatAdmin · running today · not yet open for sign-up

ChatAdmin administers Azure by conversation, and changes nothing until you say yes

You say what you want. You do not go and find where it lives. Ask for a resource group, a storage account, a virtual network, a key vault, a Log Analytics workspace or a Container App and ChatAdmin works out the calls, chains the steps and feeds each result into the next. It looks things up without interrupting you. Before it changes anything it stops, shows you the exact call it is about to make, and waits for Approve or Reject. If nobody answers, it declines. Every action goes into an audit trail.

ChatAdmin is designed to execute inside your own Azure subscription — your tenant, your identity, your audit trail, nothing about your estate exported to us. How that works is under where it is designed to run. ChatAdmin is not yet open for sign-up — here is what that means — and if you want to be early, talk to us.

Why a chat, and not another admin portal

The interface is the product decision, not a wrapper around one. This is a comparison of two interaction models, not a claim that one tool is better than another — the Azure and Microsoft 365 admin portals are comprehensive, and ChatAdmin is not.

What a portal is genuinely better at

  • Coverage. Every service, every setting. ChatAdmin knows a handful of resource types, listed in the table below, and nothing else.
  • Discovery. It shows you state you did not think to ask about. A chat only answers the question you asked.
  • Browsing. When you do not yet know what you are looking for, a form beats a sentence.

If you administer Azure all day and know exactly where everything lives, a portal is a fast tool and we are not going to pretend otherwise.

The differentiator

What changes when you can just say it

  • You describe the outcome, not the route. A portal asks you to know which blade the setting lives in. A chat asks you to know what you want. Those are different kinds of knowledge, and only one of them is about the product you are using.
  • Multi-step work stays in one place. Standing up an environment normally means carrying identifiers between blades by hand. ChatAdmin has built a whole environment from a single instruction — network, key vault, storage, Log Analytics workspace, Container Apps environment and the app on top of it — feeding each resource ID forward itself.
  • The record is of the intent, before the fact. Platform logs tell you what happened. ChatAdmin's approval card captures what was asked for, the exact call it produced, and a person's decision — recorded before the change is made rather than reconstructed after it.

The honest summary: a portal is better when you are exploring, and a chat is better when you already know what you want and would rather say it once than click it eleven times. The list of what ChatAdmin covers is the other half of that sentence.

What ChatAdmin does today

Every capability below has been executed against a live Azure subscription — through the chat, behind the approval gate. This list is the whole of ChatAdmin's coverage today: if a resource type is not on it, ChatAdmin does not manage it.

ChatAdmin capabilities. Each has created or changed the real resource type against a real subscription, through the chat, behind the approval gate.
What you can ask for Notes
List resource groups and resources Read-only, so it answers immediately — no approval card, because nothing changes
Create and manage resource groups Behind the approval gate
Storage accounts Behind the approval gate
Virtual networks and subnets Behind the approval gate. Subnets you leave out of the request are removed — a sharp edge worth knowing about
Key vaults Behind the approval gate. It manages the vault; it does not read secrets out of it
Log Analytics workspaces Behind the approval gate
Container Apps and their environments Behind the approval gate. This is the one that shows what the chat buys you — a whole environment chained from one instruction

The approval gate is the product, not a safety wrapper bolted on afterwards

An agent holding cloud credentials is only as good as what it does when nobody is watching. That is the question this design answers first, and everything else is downstream of it.

Running today

Silence means no

Every mutating call stops and raises an Approve / Reject card. The agent loop waits — it does not carry on and reconcile later. If the card is left unanswered for five minutes it is automatically declined and the change does not happen.

Nothing is ever auto-approved. There is no “trusted action” list that skips the card, and no confidence score that lets the model decide it is probably fine.

Verified rather than asserted: an approved change created a real resource group in a real subscription, driven from the browser over the public internet. The decline and time-out paths are covered by the approval-loop tests that ship with the agent.

Reading is free. Changing is not.

Looking up what exists runs straight through — you are not clicking Approve to ask a question. The gate sits precisely where the risk is, so it stays meaningful instead of becoming a habit you click past.

You approve the call, not a summary of it

The card shows the action and its parameters, so you are agreeing to a specific change to a specific resource. Password and key parameters are masked in the card, and capability results redact secrets before anything is returned or logged.

Every action lands in an audit trail

What was asked for, what was approved or declined, and what the platform did — recorded for every action, whether it went ahead or not.

Where ChatAdmin is designed to run: inside your subscription

This is the architectural model, and it is the reason ChatAdmin sits at Level 2 on our ladder. Administering a cloud means acting inside it, so the agent goes to where your resources already are rather than reaching across a boundary to manage them from outside.

The model

Your subscription, your tenant, your identity

  • It executes inside your Azure subscription, not in a service of ours that holds keys to it.
  • Your identity and your role assignment bound what it is able to do, on your side of the line.
  • Your audit trail. The record of what was asked, approved and executed belongs where the resources do.
  • Nothing about your estate is exported to us in order to be administered. The compute comes to the environment; the environment does not come to us.

Availability: not yet deployed for customers — see availability today.

Running today

The same agent, the same approval gate, the same capabilities are running today against a live Azure subscription. It authenticates by managed identity and drives real ARM calls, so the mechanism is real rather than mocked.

Availability today

Two more things a sceptical administrator asks in the first minute

“Where are the credentials?”

There are none in the container. The hosted agent authenticates to Azure by managed identity — the platform hands it a token, so there is no certificate, no client secret and no key file baked into the image to leak, rotate or lose.

The running instance reports its own auth mode, subscription and tool list over an information endpoint, so the claim can be checked rather than taken on trust.

“Can it talk itself into doing something else?”

The limits are enforced outside the model, in the dispatcher that every action has to pass through, not by asking the model nicely in a prompt. Out-of-scope actions are refused before any Azure call is made.

Concretely: it will not reach the commercial Marketplace API, it will not mint or hand back credentials, and it will not disclose secret material — not in a chat reply, not in a tool result, not in the audit log.

It also has a dry-run mode in which it does the whole conversation and the whole approval flow and performs no network calls at all.

Availability today

ChatAdmin is running today, but it is not yet something you can sign up for. Here is what that means for you.

Not yet open for sign-up

  • There is no account, trial or waiting list today. Nothing on this site starts you using ChatAdmin. If you want to be early — or to put the design through its paces before it comes near your subscription — write to us.
  • It is not yet running in customer subscriptions. The capabilities on this page run today behind the approval gate; running them inside your own subscription is the model, and it is not yet available.
  • No uptime, support or availability commitment is offered yet. None should be inferred from the fact that it is running.

Who ChatAdmin is for

  • Azure administrators who do the same five-step build every time a project starts and would rather describe it once than click it again.
  • Small platform teams who need the safety of a change-approval step without standing up a whole change-management process to get it.
  • IT leaders whose objection to agents is not capability but control — and for whom “it runs in our own subscription, it stops and asks, and it declines if nobody answers” is the answer to the real question.

While you wait, there is something you can run right now on the other pillar: Planning Data Auditor, the free check for Microsoft Dynamics 365 Supply Chain Management. It runs in your browser, needs no account and transmits nothing.

ChatAdmin is real. It is just not running in your subscription yet.

ChatAdmin is not yet open for sign-up, and we would rather say that plainly than take a sign-up we cannot yet honour. When it opens, this page changes first.

If you want to be told when it opens, or you would rather argue with the design before it ever comes near your subscription, contact@neopiq.ai reaches a person — and so does 0041 78 223 6716.