Getting started

See and score every non-human identity in a client tenant.

AIRM runs an agentless, agentless assessment through the Microsoft Graph API, a full inventory of every non-human identity, AI agents and Copilots included, with a scored NHI Risk report. We recommend a Global Admin completes the one-time connection.

✓ Microsoft Graph, consent-listed✓ Agentless, nothing installed✓ Global Admin recommended for setup✓ Revoke anytime
Register free → How it works →
How it works

Register, add a tenant, get a scored report.

AIRM is a platform, not a one-click scan from this website. You create an account, add a client tenant and approve access; AIRM does the rest. If it finds risk, you act on it with a local Sabiki partner (your existing IT provider if you have one).

1

Register

Create your free Sabiki platform account, no credit card.

2

Add a client tenant

Inside the platform, add the Microsoft 365 tenant you want to assess.

3

grant consent

Approve the Microsoft Graph consent screen, every permission listed. We recommend a Global Admin completes this one-time connection, it’s GDAP-compatible and agentless, and AIRM can’t change anything.

4

AIRM assesses the tenant

It inventories every non-human identity, AI agents and Copilots included, about 60 minutes.

5

Get your scored report

Your Sabiki NHI Risk Score, findings and blast-radius, within 24 hours.

6

Act with a partner

If it finds risk, remediate with a local Sabiki partner (your existing IT provider if you have one) and, if you want, move to continuous monitoring.

What access we request

Delegated Microsoft Graph scopes, listed in full at consent, inventory-focused. A Global Admin is recommended to approve the connection.

PermissionWhyAccess
Directory.Read.AllList users, apps & service principals (the non-human identities)READ
Application.Read.AllSee app registrations, agents & their granted scopesREAD
AuditLog.Read.AllSpot stale / unused credentialsREAD
What your report shows, illustrative sample
387
Non-human identities found
6
AI agents with high blast radius
61%
Over-permissioned
1 in 5
Belong to ex-vendors/staff
FindingDetailSev
Agent with mailbox + app-management rightsMail.ReadWrite + Application.ReadWrite.AllCRITICAL
Service principal, credential 2.3 yrs oldNever rotated; owner left the companyCRITICAL
14 app registrations, no ownerOrphaned after past integrationsHIGH

Discovery is a point-in-time snapshot. Behavioural signals & anomaly detection activate with AIRM Continuous (after a 7-day baseline).

Answers, instantly, no call needed

Everything a prospect self-checks before granting access.

The same knowledge base powers every answer in the product and the docs.