Operational Graph
Inventory plus activity, not just object lists
The platform keeps tenant-scoped identities, devices, applications, service principals, permissions, owners, audit events, and sign-ins in one operational data layer.
ITDR
Microsoft inventory, Entra logs, detections, incidents, posture findings, remediation workflow, and auditability in one operator console.
What The Platform Helps With
Operational Graph
Inventory plus activity, not just object lists
The platform keeps tenant-scoped identities, devices, applications, service principals, permissions, owners, audit events, and sign-ins in one operational data layer.
Custom Detection
Correlated alerts and incidents built from your tenant data
Recent app changes, credential-theft spray patterns, datacenter sign-in fan-out behavior, and correlated Entra activity are turned into explainable alerts and grouped incidents inside the platform.
Positioning
Not just a scan viewer and not just a raw log screen.
The product now sits across inventory, Entra evidence, custom detection, incident workflow, containment, and posture governance. It is meant to be the operating layer between Microsoft source systems and the team that has to investigate and act.
What A Customer Sets Up
OAuth-based Microsoft ingestion for Graph inventory/activity plus Office 365 Management events and mapped provider alerts.
Dedicated Microsoft 365 posture scans against a curated control benchmark, with normalized findings and remediation context.
Built For MSP Operations
ITDR is structured around how MSPs actually work: a partner admin switches between customer tenants from one session while each customer workspace stays fully isolated. Each role gets exactly the access and tools it needs — nothing shared across tenant boundaries.
Single login, all customers.
Owns one customer workspace end-to-end.
Scoped investigation access per tenant.
Advanced Operations
Custom Detection Rules
Build your own detections on top of ingested tenant data
Operators can author custom detection rules alongside built-in behavioral rules, with a full draft → active → disabled lifecycle. Rules are scoped to the tenant and evaluated against the same normalized evidence the platform already collects.
Automated Playbooks
Structured response workflows triggered by alert conditions
Playbooks define automated response sequences tied to alert severity or type. Approval boundaries, dry-run validation, and capability checks keep automation safe — no arbitrary remote execution.
Microsoft Secure Score
Ranked control recommendations inside the investigation context
Secure Score data from Microsoft is surfaced alongside posture findings and identity context, giving operators a prioritized list of control improvements without switching to a separate portal.
What The Customer Gets
Operational Graph
Inventory plus activity, not just object lists
The platform keeps tenant-scoped identities, devices, applications, service principals, permissions, owners, audit events, and sign-ins in one operational data layer.
Custom Detection
Correlated alerts and incidents built from your tenant data
Recent app changes, credential-theft spray patterns, datacenter sign-in fan-out behavior, and correlated Entra activity are turned into explainable alerts and grouped incidents inside the platform.
Response Workflow
Containment actions where incidents point to real users
Operators can review evidence, open incidents, and run controlled Entra response actions such as revoke sessions, disable user, re-enable user, and group removal.
Posture Governance
Static control debt stays tied to live tenant operations
Posture findings, exceptions, remediation tasks, and workload identity risk context stay in the same workflow instead of becoming a disconnected scan report.
Questions The Product Answers
Practical Operator Flow
Current Strengths
Best Fit
Automation Boundary
The platform is designed around scoped Microsoft actions, approval boundaries, response history, and tenant auditability. It is built to support operator response without turning into unsafe generic remote execution.
Evidence Model
Raw Graph and Office 365 Management payloads are still retained for traceability, but operators work from normalized logs, linked entities, scored alerts, grouped incidents, and response history instead of reading raw JSON by default.