Skip to content

I build thearchitectureyou keep.

Michal Jatczak is a Polish engineer running ITSailor from Malta, a Malta-registered Microsoft Authorized Partner practice for Cloud, Security, and AI architecture.

The operating model is simple: scoped work, client-owned assets, wholesale-first licensing where Pax8 fits, and an Exit Kit another engineer can use on day one.

Or start with a free diagnostic scan
Jurisdiction

Registered in Malta

Michal Jatczak T/A ITSailor, VAT-registered sole trader, MT32760411. EU-wide, remote-first delivery.

Check MT32760411 on the EU VIES register
Microsoft status

Authorized Partner

Partner Location Account 7113951, Malta partner location.

Verify on the Microsoft partner directory
Founder

Polish engineer

Hands-on Microsoft 365, Azure, automation, and AI systems operator.

Commercial route

Pax8 marketplace

CSP Indirect Reseller path for Microsoft 365, Azure, backup, and security licensing.

The founder

Built by an operator, not a sales layer.

Michal Jatczak founded ITSailor from Malta on a specific bet: that one technically-proficient engineer, paired with a stack of specialised AI agents and the right vendor marketplace, can outproduce a 10-person traditional IT consultancy on the work that actually matters - engineering-grade Microsoft 365 hardening, Azure landing zones, automation, and AI agent deployment for regulated EU operators.

The path here matters. Michal started in a large Polish software house, then moved to Malta into a heavily regulated operator - the kind of place where auditors actually open the logs, where a wrong Conditional Access policy gets noticed by Compliance the same day, and where "enterprise-grade security" has to actually work on a Tuesday afternoon, not in a Powerpoint. That insider experience - sitting at the table with executives translating AI into corporate process, while the security clock is running - is what shaped the ITSailor approach.

The portfolio is structured as three Azure-resident products plus a consulting practice that funds product development. SEAWALL is a FinOps engine for AWS and Azure tenants - Terraform modules, Grafana dashboards, and triage SOPs that turn "we're spending too much on cloud" into a remediated PR within an afternoon. HOIST is an autonomous IT-support agent for Tier-0 internal tickets, routed deterministically against a whitelist and paid per resolution. DECKLOG is a knowledge operations layer for Microsoft 365 Copilot agents: corpus cleanup, permission review, and answer-quality evidence across SharePoint, OneDrive, policies, tickets, and contracts.

The licensing and managed stack lives in the Pax8 marketplace - Microsoft 365, Azure, backup, security, and the rest of the modern operator's toolchain sourced at wholesale. No 30% markup, no opaque billing. Every licence is transferable out via the Exit Kit on day one.

The consulting layer is anchored by the Architecture Workshop: two hours live in your tenant, an ITSailor Microsoft 365 Security Baseline assessment, an Azure landing-zone sketch, and a deployable architecture plan with the Terraform and Power Automate flows ready to merge. The next workshop in your inbox costs 10× more, ends with a 100-page PDF, and locks you into the consultancy's tools. ITSailor's wedge is the inverse: a fixed-price diagnostic that ends with deployable code you own, and an Exit Kit that means you never need ITSailor to walk away from a vendor.

Proof before positioning

Three engagements, measured.

Anonymised outcomes from the founder's prior operating roles in regulated industry, stated as such - not ITSailor client engagements. The page leads with them because credibility should be visible before the adjectives arrive.

Identity and endpoint

Intune and Conditional Access that survived audit pressure.

A regulated operator moved from unmanaged BYOD and manual laptop setup to enforceable device compliance, BitLocker, MDM, and Autopilot onboarding.

  • 100% device compliance in 30 days
  • 2 days to 30 minutes hardware onboarding
Lifecycle automation

Offboarding became an execution log, not an email thread.

Power Automate connected HR status changes to Microsoft 365 offboarding: session revocation, mailbox conversion, licence recovery, OneDrive archive, and audit trace.

  • Offboarding runs HR-triggered, with no engineer time
  • Clean access-termination result in the first internal audit after rollout
  • ~€1,500 per month in reclaimed licences
Service desk AI

Tier-1 access requests moved out of the engineer queue.

Jira Service Management, n8n, Slack approval, and internal APIs turned repeat access tickets into a controlled self-service path.

  • 45% lower L1 ticket volume
  • 14 hours to 12 seconds MTTR for simple access requests

Field log

The recurring fires and slow bleeds resolved across the same operating career. If one of these is on your desk right now, it is familiar territory.

  • Exchange hybrid migrations that stalled mid-cutover: mail flow restored first, then the move finished with SPF, DKIM and DMARC done properly.
  • SharePoint permission sprawl: external shares inventoried, ownership reassigned, sensitive libraries locked down without breaking collaboration.
  • Conditional Access rollouts that locked people out: access recovered without dropping the policy, then re-sequenced with proper break-glass accounts.
  • Azure Virtual Desktop login storms: FSLogix profiles fixed and autoscaling introduced before anyone bought more session hosts.
  • Approvals living in inboxes: rebuilt in Power Automate and n8n with an audit trail Compliance can actually open.
  • Azure subscriptions grown by hand: rebuilt as a landing zone with budgets, policy guardrails and Terraform state instead of tribal knowledge.
Operating model

The work is designed to end cleanly.

The Exit Kit is not a nice extra. It is the delivery constraint that shapes how the work is scoped, documented, and transferred.

Scope the real system

We start with the tenant, cloud account, workflow, or support queue that actually exists, then define the smallest useful intervention.

Build where ownership stays yours

Policies, runbooks, Terraform, Power Automate flows, and agent prompts live in client-owned assets, not inside a vendor black box.

Document during the build

Controls, decisions, credentials map, recovery steps, and exceptions are captured as the work happens, not reconstructed at the end.

Hand over with an Exit Kit

Every engagement closes with the information another engineer needs to operate, move, or replace the stack without asking ITSailor.

Next step

Bring the problem. Leave with the next move.

If the brief fits ITSailor, you get a scoped path.If it does not, you get a direct answer and a useful referral.

Architecture Workshop and scoped delivery
NDA offered as standard before any sensitive detail
Read-only first, written access, revocable credentials
AI-assisted delivery with human accountability
Exit Kit handover on every engagement