An analyst that reads your signals and tells you what matters.
It reads your Microsoft 365 security signals, works out what actually needs attention, and explains it in plain English — not as another queue of alerts for someone to work through.
Most organisations do not have an alert problem. They have a time problem.
Microsoft 365 already produces a great deal of security signal. Sign-in risk, unusual mailbox rules, consent grants to applications nobody recognises, impossible-travel events, permission changes.
The signal is not the issue. The issue is that in a team of two or three people who also run the helpdesk, nobody has an uninterrupted hour to work out whether any of it matters. So it accumulates, and the genuinely interesting thing sits in the middle of it, indistinguishable from the noise.
Investigates first, then tells you
Reads the signals
Connects to your Microsoft 365 environment and works across the security signals already being generated — identity, mailbox, application consent and permission activity.
Works out what matters
Rather than forwarding an alert, it pulls the surrounding context together and reaches a view about whether something warrants your attention.
Explains it in plain English
You get an explanation a competent IT manager can read and act on, along with what it looked at to get there — not a severity score and a log excerpt.
You can also just ask it things. "Has anyone in finance had a suspicious sign-in this week?" is a reasonable question to put to it, and a reasonable answer is what comes back.
This is not an AI feature bolted onto a dashboard
We already do this. We have built and delivered agentic triage over live customer security data — connecting a security data pipeline to a large language model so an analyst can ask questions in plain language and get grounded, evidenced answers back.
That work runs today in a production environment, on masked data, with the customer's own governance around it. This product packages the same approach for Microsoft 365, where most of the organisations we work with already keep their identities, their mail and their files.
Grounded in your data, not a generic model
Answers reference what it actually looked at in your environment. If it does not know, it says so rather than inventing something plausible.
Built with data governance in mind
We have done this work where sensitive data had to be masked before it went anywhere near a model. That constraint shaped how we build.
What we are not claiming. We have not published detection rates, response times or productivity figures for this product, because we do not yet have evidence we would stand behind. When we have it, we will publish it — with the working. Until then we would rather show you what it does on your own environment than quote a number at you.
Register your interest
We are working with a small number of organisations ahead of general availability. If you run Microsoft 365 and a small team, we would like to talk to you.
No obligation, and we will not add you to a mailing list. We will get in touch when there is something worth showing you.