One review
You take the reporting and run with it. One review conversation to work through the first set of findings, and after that the reports keep refreshing for your team to use at their own pace.
The long version. What happens before you say yes, what happens on the day itself, and the two decisions that shape everything after it.
Whatever you decide later, this part is identical. Only two of the four steps need anything from you at all.
A demo on your own questions rather than a generic tour: we open the reporting and look at the things you actually want answered. You bring the questions, we show whether we can answer them. Nothing is granted and nothing is signed.
The practical half. Which parts of the environment are in scope, who operates them today, and what you want the review to settle. This is also where we set expectations, because an independent review only works when it is clear up front who does what with the outcome.
Named people, not a mailbox. Findings travel badly when nobody owns them.
Priority is a business call, not a technical one. It needs someone who can weigh a risk against a quarter.
Your team, your operating partner, or us. That is decision two further down this page.
One administrator grants read-only consent on the app registration. No agents, nothing installed, no changes to your configuration, and nothing asked of your users. We read configuration and metadata only, never the body of a message or the contents of a document.
Every Microsoft 365 domain in one view, hours after consent rather than weeks, with the findings ranked instead of listed. From that point it refreshes daily and starts building history.
From here, two decisions.
The reports are yours either way. What you are choosing is whether a specialist stays in the picture after the first one, and how often.
You take the reporting and run with it. One review conversation to work through the first set of findings, and after that the reports keep refreshing for your team to use at their own pace.
A specialist reads each cycle with you on an agreed rhythm: what changed since last time, what is new, and what deserves the coming weeks. History builds up, so you are looking at movement instead of a snapshot.
An hour, screen shared, with the people who can act on the outcome: usually whoever runs Microsoft 365 day to day, plus whoever owns the budget or the risk. We walk the findings in priority order rather than top to bottom. Afterwards you get the prioritised action list in writing, with the reasoning attached to each item, so it survives being forwarded to somebody who was not in the room.
A prioritised list is not a shorter list. Somebody still has to do the work, and that is a separate decision from who reads the report.
The action list goes internally, or to whoever runs the environment. We stay out of it and the next report simply shows what moved. This is the default, and for plenty of organisations it is the whole answer.
Remediation is arranged as its own assignment, with a scope, a starting point and an intended result. It needs more than read-only: we get scoped write access for the work that was agreed, and nothing beyond it.
It is arranged per assignment rather than folded into a subscription, so the review stays independent of whoever does the fixing.
Because the reporting refreshes daily, the following conversation does not start from scratch. Whichever way both decisions went, the same four moves repeat: we read it together, we get the right people in the room, we prioritise, and it gets put right. The next report then shows that it moved.
The party that configures an environment is not the party that assesses it. That rule is unremarkable everywhere else, and it exists because nobody is well placed to audit their own work. Not out of ill will, but because you stop seeing what you look at every day.
Microsoft 365 is the exception almost everywhere. Whoever builds it also reports on it, and the evidence sits scattered across admin portals that no single person reads together.
The constant is not who operates the environment. It is that the operator and the assessor are the same party. That is the thing we separate, and it is the only reason this works.
One click, once, by an administrator with permission to grant tenant-wide consent. In most tenants that is a Global Administrator. Nothing to install, no agents on endpoints, no changes to your configuration and nothing asked of your users. If a partner runs your environment, they grant it: the review does not need to go around them, and it works better when it does not.
Consent is withdrawn in one click from the Entra admin centre, by any administrator, without asking us first. Reporting stops at that moment. What happens to the data already collected is set out in the agreement, and the environment itself is left exactly as it was. The base service never wrote anything to it.