Defined implementation

Move your agent from a demo to something customers can actually use.

Host the MCP server, configure Entra sign-in and limit each data connection to the agreed scope. Test the agent, record its activity and prepare the required listing documentation. Submission and platform approval remain separate.

PricePrice fixed after a short scope call.

DeliveryThe proposal names the start date, the change windows and the completion date before anything is agreed.

What you receive · illustrative sample

A public tool needs explicit access boundaries.

Illustrative launch acceptance checklist, not evidence of a deployed client system. The agreed build includes a test environment and an operating owner.

BoundaryValidationOwner keeps
Authentication and permissionsAllowed and denied requests testedAccess model and test record
Tool executionInputs checked; sensitive actions require agreed approvalTool contracts and error examples
Runtime operationRate limits, failure alerts and cost limits testedDeployment and recovery runbook

Meet the person responsible for delivery.

Alwatheq Zboun leads the agreed work. A sample shows the format; the statement of work defines your deliverable and acceptance checks.

Engagement context

When this engagement applies.

The agent works in a demo, and now it has to be reachable by customers: hosted, signed in to, connected to real data, and ready to list.

Scope considerations

  • One agent, one hosted server
  • Entra sign-in, not a shared key
  • You own the model and its behavior

The defined work

Engagement scope.

  1. 01

    The MCP server is built and hosted somewhere it stays up, rather than on a laptop or a personal subscription.

  2. 02

    Your APIs and business data are connected through it, and each connection is scoped to what the agent actually needs rather than to everything it could reach.

  3. 03

    Sign-in goes through Entra using OAuth, so the agent answers as the person asking rather than as itself.

  4. 04

    It is wired into Copilot Studio or Microsoft Foundry, whichever the business is standardizing on, with generative orchestration switched on as that path requires.

  5. 05

    Evaluation and telemetry are turned on against an agreed test set, so what the agent returns can be measured rather than assumed.

  6. 06

    The documentation a public listing or certification asks for is written, and the submission is prepared for you to send.

Acceptance

Completion has an agreed standard.

Done when a test user signs in through Entra, the agent returns only what that account could already reach, and the listing submission is ready to send.

  • The MCP server is reachable at its agreed address and comes back after a restart

  • A test user signs in through Entra and the agent returns only what that user could already reach

  • Every connected API and data source is listed with the permission it was granted

  • Evaluation runs produce a recorded score against the agreed test set

  • The documentation pack is complete and the listing submission is ready for you to send

Commercial basis

Price, scope and timing are considered together.

Engagement price

Price fixed after a short scope call.

The price is agreed in writing before any work starts and before anyone is given access. The call itself costs nothing. What moves the number:

What determines the scope

  • How many APIs and data sources the agent connects to
  • Whether it is going into a public catalog or staying inside your own tenant
  • How much of the evaluation and telemetry has to be built rather than switched on
  • Whether the hosting has to meet a customer requirement about where it runs
  • How much of the security documentation already exists

Delivery calendar

The proposal names the start date, the change windows and the completion date before anything is agreed.

How engagements work

Scope & responsibilities

The full engagement boundary.

Review the exclusions, required client participation, change controls and operational handover for this engagement.

Exclusions
  • Building, training or tuning the model itself
  • Writing the agent prompts or deciding how it should behave
  • Any promise that a catalog or certification review will approve the listing, which is the reviewer decision and not one AZ can make
  • Running the server after handover, unless that is agreed separately
Client responsibilities
  • Own the agent behavior, the prompts and the model choice
  • Provide the APIs and data the agent connects to, and say who may reach each one
  • Name the person who approves the security position before anything is published
  • Provide the tenant and the licensing the hosting and sign-in require
Change and rollback method
  • The server runs somewhere non-production first, and the sign-in path is tested with a real account before anything is published.
  • Data connections are added one at a time, and what each one can reach is checked before the next is added.
  • Nothing is submitted to a public catalog until the documentation and the security position have been approved on your side.
Operational record and handover
  • The hosted MCP server and its configuration, written down
  • The connection list, with the permission granted to each one
  • The sign-in test results, per test account
  • The evaluation scores against the agreed test set
  • The documentation pack, ready to submit

Before you commit

A clear first step.
You stay in control.

Start with the problem and the result you need. The initial fit conversation is free and does not require access to your systems.

Check client feedback on Upwork ↗

Prefer to contract through Upwork? Contact Alwatheq there. Existing Upwork engagements continue through Upwork.

Who will actually do the work?

Alwatheq Zboun leads the scope, technical work and handover. If a specialist collaborator is needed, their role is agreed with you before work starts. Your proposal names the responsibilities and delivery windows.

What happens before you get access?

We agree the scope, fee and completion checks in writing. Access uses named accounts and only the permissions the work requires. Approved access is reviewed and removed at handover.

How do we know the change worked?

Your scope defines the pilot, test cases and acceptance checks. Results and exceptions are recorded. Recovery options and their limits are agreed before production changes; a failed check is addressed before the next approved stage.

Will we need an ongoing retainer?

A defined project can end at handover. Your team receives the agreed configuration records, runbook and walkthrough. Any limited support period is written into the proposal; ongoing support or additional work is a separate agreement.

Discuss the fit ↗Read the delivery process ↗

Discuss this engagement

Put the scope in context.

Describe the problem, systems and deadline. Alwatheq will review the fit and the scope questions before preparing a written proposal.

Plan the Agent Launch