Free AI Readiness Assessment

Is your Microsoft 365 ready for AI? Most aren't.

A brand-new tenant, straight out of the box, does not pass. The Free AI Readiness Assessment runs 112 checks against CIS Benchmarks and the NIST AI Risk Management Framework and scores your tenant 0–100 — every finding opening to the evidence behind it and the fix. Under fifteen minutes, free.

✓ Agentless — nothing installed ✓ Nothing changes without your approval ✓ Every permission listed at consent ✓ Under fifteen minutes
Also available on Microsoft Marketplace →
1 Free Assessmentyour Score, today → 2 Fix & re-scan3 free scans per tenant → 3 AIRM keeps you readyfrom $149/tenant/mo
Questions first? Book 30 minutes →
Sabiki AI Readiness assessmentA default M365 tenant
34/ 100

CRITICAL

If you connected an AI agent, MCP server or app today, it could reach and move sensitive data right now. A brand-new tenant, straight out of the box, does not pass.

Settings
31%
Data protection
0%
Data exposure
19%
Identities
56%

Illustrative scan of a default-configuration Microsoft 365 tenant. 98/112 checks returned a result. 0% of the score is self-attested.

What Sabiki Security does

One platform. Start free, stay ready.

Sabiki Security makes AIRM — the platform that gets Microsoft 365 organisations ready for AI, and keeps them that way. Two offerings, one journey:

STEP 1 · FREE

AI Readiness Assessment

Find out if you're ready to switch AI on.

Sabiki AI Readiness assessmentA default M365 tenant
34/ 100

CRITICAL

If you connected an AI agent, MCP server or app today, it could reach and move sensitive data right now. A brand-new tenant, straight out of the box, does not pass.

Settings
31%
Data protection
0%
Data exposure
19%
Identities
56%

Illustrative scan of a default-configuration Microsoft 365 tenant. 98/112 checks returned a result. 0% of the score is self-attested.

What it isA readiness gate — 112 checks against CIS Benchmarks & NIST AI RMF, scored 0–100
What you getYour score and band, every finding with its evidence and fix, a prioritised worklist
How oftenThree free scans per tenant — baseline, progress, proof
CostFree. The report is yours to keep.
Get your free AI Readiness Score →
STEP 2 · SUBSCRIPTION

AIRM — the platform

Stay ready, every day after.

AIRM dashboard card — Sabiki NHI Risk Score 66, 431 identities found, 419 need review, 8 need a human
What it isContinuous behavioural monitoring of every agentic identity — an anomaly engine scoring activity across seventeen behavioural signals, with human-approved remediation
What you getThe things only visible in motion: the dormant agent that wakes, the agent reaching into mailboxes it never touched, the agent acting through another agent
How oftenContinuous. The Score you earned stays earned.
CostFrom $149/tenant/month · free trial from your Readiness dashboard
Explore AIRM →

Security lead? AIRM has its own free front door — the Sabiki NHI Risk Score™: every non-human identity in the tenant, scored 0–100, in about five minutes. Get your free score →

Why readiness comes first

AI doesn't create your risk. It inherits it.

Copilot — and every agent like it — operates with the permissions, sharing settings and data controls that already exist in your tenant. A file that is overshared today becomes a file the assistant can surface on request tomorrow. An open consent setting today becomes a path for an agent to enter the tenant tomorrow. Deployment doesn't create these conditions. It makes them reachable at speed and at scale.

And AI works at machine speed — it doesn't wait or sleep, and it registers its own identities that act with standing permissions around the clock: a new actor in your tenant with no human in the loop. It can reach and move data through channels you never had to police — a stale "anyone" SharePoint link, an over-permissioned agent, mailbox auto-forwarding, a quietly-consented third-party app. A misconfiguration that was low-risk yesterday is now reachable by AI at scale, instantly.

That's why the assessment is a readiness gate, not an inventory tool — and why a default Microsoft 365 tenant, measured against CIS Benchmarks and the NIST AI Risk Management Framework, does not pass.

How it works

Consent. Scan. Score.

01

Sign up & connect

Create your free account and connect one Microsoft 365 tenant. Agentless — nothing installed. Every permission is listed on the consent screen before anything connects.

02

Run your scan

112 checks against CIS Benchmarks and the NIST AI Risk Management Framework — assessed from what your tenant actually shows, not a questionnaire. Nothing is self-attested; nothing changes without a person approving it.

03

Get your Score

A 0–100 score and band in your Readiness dashboard, plus the full report: every finding scored by severity and weight, each opening to the evidence and the fix. Yours to keep — whether or not you ever pay us anything.

then

Fix, re-scan, prove it

You have three free scans per tenant: your baseline, your progress, your proof. Watch the Score move as you remediate — and when you want it watched continuously, Explore AIRM is one click from your dashboard.

The report

A score the board understands. Evidence the auditor accepts.

✓One score, 0–100, with a band — CRITICAL to STRONG. Legible to a board in five seconds, measured against CIS Benchmarks and NIST AI RMF.
✓Your top blockers, ranked — with the specific finding behind each, not generic advice.
✓Nothing self-attested — every point of the score is measured from the tenant, and the report says exactly which checks could not run.
✓Framework crosswalk — findings mapped to the governance frameworks your auditors ask about.
Download the sample report (PDF) →

Sample: Northwind Trading, a fictional demo tenant. The product, the checks and the numbers are real. The company and the identity names are not.

Inside the report

Northwind Trading — AI Readiness 34 / 100 · CRITICAL

AI agents with no owner9
Copilot data exposure paths14
Ungoverned OAuth consents37
Governance controls in place18 / 31
Days to "ready", on the plan60
After the Score

The assessment finds the gaps. AIRM closes them — and keeps them closed.

A score is a moment in time. The tenant changes the day after: new AI agents appear, consents sprawl, owners leave. That is why your Readiness dashboard carries one more button — Explore AIRM. One click starts your trial of the platform that watches the tenant continuously, so the Score you earned stays earned.

Report finding

"9 AI agents have no owner"

The assessment names them once.

AIRM → assigns ownership and flags every new unowned agent, continuously.
Report finding

"37 ungoverned OAuth consents"

The assessment counts them once.

AIRM → scores each one's blast radius and routes the 8 that need a human decision.
Report finding

"Score: 34 — CRITICAL"

The assessment scores you once.

AIRM → re-scores every scan, so the board sees the Score move.
Start the AIRM trial from your Readiness dashboard. Subscriptions from $149/tenant/month — every tier includes both dashboards, all 11 framework mappings, and unlimited re-scoring. See AIRM pricing →
For MSPs & MSSPs

Run it across your whole client book.

  • Free assessment on every client tenant — unlimited scanning across your book, three scans per client tenant. The discovery artefact that starts the AI conversation.
  • White-label the report — your logo on the document the client's board reads.
  • The report is free — remediation is your revenue. Every gap in the report is a scoped, billable fix you deliver, then AIRM subscriptions at 25–40% partner margin keep it closed.
  • One console, every tenant — multi-tenant by design, GDAP-compatible, PSA integrations.
Become a partner — register free →
The partner motion
1 · Assess free — every client tenant, scored.
2 · Present the Score — the QBR slide writes itself.
3 · Sell the fix — remediation is your billable work; AIRM subscriptions recur.
4 · Prove it quarterly — the Score moves; the client sees why they pay you.
“We paid for an assessment last year and I thought we were covered. The free Sabiki report found things that engagement never looked at… There was a list of applications reading mail that I had never seen and could not account for. I got more out of this than I got out of the work we paid for.”

Michael Barbara · Owner, Perfecto Foods

Straight answers

Before you connect a tenant.

Is it really free? What's the catch?

Yes — sign-up, three scans per tenant, and the scored report are free, and the report is yours whether or not you ever pay us. The business model is simple and stated: fixing the gaps is where money changes hands — through your MSP's remediation work, or through AIRM, our subscription platform, which you can trial from your Readiness dashboard. Both are offered, never required.

Why three scans?

Because one number proves nothing. Scan one is your baseline. Fix what the plan tells you, scan again — that's your progress. Scan three is your proof, the before-and-after your board actually believes. When you want the Score watched continuously instead of on demand, that's AIRM.

What can it change in my tenant?

Nothing without a person approving it. The assessment reads identity and permission metadata — not your emails, files or documents — through delegated Microsoft Graph permissions, listed in full on the consent screen. Access is revocable in the Microsoft Entra admin centre at any time.

How is this different from the NHI Risk Score?

Two products, two questions. The AI Readiness Assessment answers "are we ready to switch AI on?" — 112 checks, scored 0–100. The Sabiki NHI Risk Score™ answers "what's already running that nobody owns?" — every non-human identity, scored 0–100. Run either first; they meet at AIRM.

How is this different from Microsoft Secure Score?

Secure Score remains a useful control — it grades configuration against a checklist, for a world where the identities signing in are people. It doesn't ask whether the tenant is ready for AI: it carries no line item for a non-human identity, or for whether your sharing posture is safe to expose to an assistant. A good Secure Score and an unsafe AI deployment are not mutually exclusive — we see the combination regularly.

Where does the data live?

The platform runs on Microsoft Azure, Southeast Asia (Singapore), with findings stored in MongoDB Atlas in the same region. Customer tenant data stays in Singapore, is never used to train models, and is never shared with any third-party AI provider.

Free · agentless · ~10 minutes

Know your Score before you switch AI on.

Every week you wait, more agents appear in the tenant with nobody watching them. Get the number, get the plan, decide from evidence.

No credit card · Three free scans per tenant · Nothing installed · Nothing changes without your approval