The same for everyone

Four steps, one working day.

Whatever you decide later, this part is identical. Only two of the four steps need anything from you at all.

  1. 0130–60 min

    First conversation

    A demo on your own questions rather than a generic tour: we open the reporting and look at the things you actually want answered. You bring the questions, we show whether we can answer them. Nothing is granted and nothing is signed.

  2. 02a second conversation

    Scope, roles and expectations

    The practical half. Which parts of the environment are in scope, who operates them today, and what you want the review to settle. This is also where we set expectations, because an independent review only works when it is clear up front who does what with the outcome.

    Agreed here, and written down

    Who receives the report

    Named people, not a mailbox. Findings travel badly when nobody owns them.

    Who decides what gets fixed first

    Priority is a business call, not a technical one. It needs someone who can weigh a risk against a quarter.

    Who does the fixing

    Your team, your operating partner, or us. That is decision two further down this page.

  3. 03same morning

    Read-only consent

    One administrator grants read-only consent on the app registration. No agents, nothing installed, no changes to your configuration, and nothing asked of your users. We read configuration and metadata only, never the body of a message or the contents of a document.

  4. 04same afternoon

    The first report is there

    Every Microsoft 365 domain in one view, hours after consent rather than weeks, with the findings ranked instead of listed. From that point it refreshes daily and starts building history.

From here, two decisions.

Decision one

Who reads it with you.

The reports are yours either way. What you are choosing is whether a specialist stays in the picture after the first one, and how often.

You read it

One review

You take the reporting and run with it. One review conversation to work through the first set of findings, and after that the reports keep refreshing for your team to use at their own pace.

Baseline Review
We read it with you

Continuous oversight

A specialist reads each cycle with you on an agreed rhythm: what changed since last time, what is new, and what deserves the coming weeks. History builds up, so you are looking at movement instead of a snapshot.

Continuous Oversight · Executive Assurance

What a review conversation actually is

An hour, screen shared, with the people who can act on the outcome: usually whoever runs Microsoft 365 day to day, plus whoever owns the budget or the risk. We walk the findings in priority order rather than top to bottom. Afterwards you get the prioritised action list in writing, with the reasoning attached to each item, so it survives being forwarded to somebody who was not in the room.

What each one costs

Decision two

Who closes the findings.

A prioritised list is not a shorter list. Somebody still has to do the work, and that is a separate decision from who reads the report.

Your team, or your operating partner

You take the list

The action list goes internally, or to whoever runs the environment. We stay out of it and the next report simply shows what moved. This is the default, and for plenty of organisations it is the whole answer.

No further engagement
We take the list

We put it right

Remediation is arranged as its own assignment, with a scope, a starting point and an intended result. It needs more than read-only: we get scoped write access for the work that was agreed, and nothing beyond it.

Separate engagement

It is arranged per assignment rather than folded into a subscription, so the review stays independent of whoever does the fixing.

And then it loops

The next report is the proof.

Because the reporting refreshes daily, the following conversation does not start from scratch. Whichever way both decisions went, the same four moves repeat: we read it together, we get the right people in the room, we prioritise, and it gets put right. The next report then shows that it moved.

Why this approach

Separation of duties.

The party that configures an environment is not the party that assesses it. That rule is unremarkable everywhere else, and it exists because nobody is well placed to audit their own work. Not out of ill will, but because you stop seeing what you look at every day.

Microsoft 365 is the exception almost everywhere. Whoever builds it also reports on it, and the evidence sits scattered across admin portals that no single person reads together.

  • You run it yourself. And still nobody independent reads the whole of it.
  • One managed service provider runs it. And still nobody independent reads the whole of it.
  • An MSP runs it alongside your own team. And still nobody independent reads the whole of it.
  • Several suppliers each own a piece of it. And still nobody independent reads the whole of it.

The constant is not who operates the environment. It is that the operator and the assessor are the same party. That is the thing we separate, and it is the only reason this works.

Practical

What it takes to start

One click, once, by an administrator with permission to grant tenant-wide consent. In most tenants that is a Global Administrator. Nothing to install, no agents on endpoints, no changes to your configuration and nothing asked of your users. If a partner runs your environment, they grant it: the review does not need to go around them, and it works better when it does not.

What happens if you stop

Consent is withdrawn in one click from the Entra admin centre, by any administrator, without asking us first. Reporting stops at that moment. What happens to the data already collected is set out in the agreement, and the environment itself is left exactly as it was. The base service never wrote anything to it.

Plan an independent review