The platform · one control plane

The control plane for every non-human identity in Microsoft 365.

AIRM discovers, understands, governs and improves every non-human identity, AI agents included in a Microsoft 365 tenant. Independent of Microsoft, agentless, human-approved change, built for MSP scale. Here's what's inside.

Get your Sabiki NHI Risk Score →Watch the demo
Discover & Understand

Find every non-human identity, and know its real risk.

Non-Human Identity Discovery

Continuously discover and monitor every non-human identity in your Microsoft 365 tenant: service principals, app registrations, OAuth-connected apps, connectors, Copilots and AI agents.

  • Automatic discovery, no manual inventory
  • Classified by type: AI agent, automation, legacy app, Microsoft first-party
  • Owner assignment & accountability
  • Credential-age monitoring with expiry alerts
AIRM · Identity Inventory
Identities · 412 totalAuto-discovered
Copilot Studio agent
svc-copilot-prod
AGENT
Terraform Cloud
rotated 2.3 yrs ago
AUTOMATION
Legacy connector
no owner
UNOWNED

Non-Human Identity Security

Score every identity on two independent axes, what it’s doing now, and how bad it would be if compromised. A quiet app with dangerous permissions is your biggest threat.

  • Behaviour Risk band (static · behavioural · anomaly)
  • Blast-radius band from granted permissions
  • Credential monitoring & unowned-identity detection
  • Known-rogue service-principal detection
AIRM · Risk Scoring
svc-copilot-prod · riskCRITICAL
Behaviour risk72 / 100
Blast radius88 / 100
Quiet app, dangerous scope
Application.ReadWrite.All

Anomaly Intelligence Engine

Our proprietary, scan-over-scan behavioural engine builds a fingerprint for every identity and gets sharper the longer it runs, the moat a point-in-time tool can’t replicate.

  • 17 anomaly signals monitored per identity
  • Permission-scope drift detection on approved agents
  • Approved-AI-gone-rogue detection
  • Accumulated intelligence, scan over scan
AIRM · Anomaly Engine
17 signals · 30-day baselineDrift detected
Permission-scope driftApproved agent added Mail.Send since last scan.
Govern & Improve

Act on it, prove it, and raise the score.

Blast Radius Analysis

Map exactly what an attacker would reach from any compromised identity, built from actual granted permissions, not assumed activity. Populated from day one.

  • Built from real granted permissions, not historical activity
  • Populated from day one, no baseline wait
  • Per-identity reachable data, mailboxes & tenants
AIRM · Blast Radius
Blast radius · svc-copilot-prodCRITICAL
AgentR/WDirAppsMail
If compromised, an attacker couldRead & send mail · grant app roles · modify directory settings.

Identity Graph

Visualise trust relationships and lateral-movement paths across the tenant, Graph, Attack Paths and Temporal views, Crown-Jewel highlighting, SVG export for board reports.

  • Graph, Attack Paths & Temporal views
  • Crown-Jewel highlighting
  • SVG export for board reports
AIRM · Identity Graph
Identity graph · trust pathsLive
AgentR/WDirAppsMail
GraphAttack pathsTemporalCrown-jewels

Compromise Simulation

Run a permission-aware attack model against any identity, a 0-100 blast score, human-readable attacker actions, reachable data types, and scoped remediation. No live data touched.

  • 0-100 blast score per identity
  • Human-readable attacker actions
  • Scoped remediation, no live data touched
AIRM · Compromise Sim
Compromise simulationBlast score
87
out of 100 · no live data touched
Reaches 3 tenants, 1.2k mailboxes
Assign admin role to any user
Read & exfiltrate mail

Compliance Mapping

Map every finding to 11 frameworks (EU AI Act, DORA, ISO/IEC 42001, NIST AI RMF and more) and generate branded, per-framework, audit-ready reports.

  • 11 frameworks incl. EU AI Act, DORA, ISO 42001
  • Per-framework, audit-ready reports
  • Branded evidence pack for auditors & insurers
AIRM · Compliance
Compliance mapping · 11 frameworksAudit-ready
EU AI ActGAP
DORAPASS
ISO/IEC 42001PASS
NIST AI RMFREVIEW

Alerting & Integrations

P1, P5 smart alerts straight into your PSA (ConnectWise, HaloPSA, Autotask), plus webhooks to SIEM, Slack and Teams, no middleware, deduplicated, per tenant.

  • P1, P5 smart alerts into your PSA
  • ConnectWise, HaloPSA, Autotask
  • Webhooks to SIEM, Slack & Teams, deduplicated
AIRM · Alerting
Alerts & integrationsP1
Critical NHI over-permissioned
#48213 · pushed to ConnectWise
New agent granted app roles
#48214 · assigned
ConnectWiseHaloPSATeamsSIEM
In the product

419 NHIs to review. 8 need a human.

AIRM decides what matters. You decide what happens.

AIRM does the triage before your team ever opens the tenant. It ranks by publisher trust and permission reach, batches the safe ones, and surfaces the handful that actually carry risk. Then it stops, and waits for a person.

Run it with the team you already have. A level one technician can clear a tenant. Your senior person gets pulled in for the eight that matter, not the four hundred that don't.
One tenant, one scan
Identities foundAI apps, service accounts, connectors
431
Need reviewNot approved, or nobody owns them
419
AIRM sorts themBy publisher trust, permission reach and ownership
Need a humanCan change your data, or nobody owns them
8
Routine, approve togetherTrusted publisher, owned, limited reach
411
One tenant · one scan · 13 Jul 10:01 — both screens below are the same moment
OperatorDecide what to do
Operator
🔔9A. Chen ▾
431identities

Here's what's running in Northwind Trading

13 AI apps and 421 other identities. 419 need review, not yet approved or ownership not assigned.
AI appsNHIs
These need review 419 not approvedList allGroup
Critical0
Threat-intel matches, or unverified apps that can reach your whole tenant. Act on these first.
Open →
Needs attention8
Apps that can change your data, or that have no accountable owner. Worth reviewing.
Open →
Routine411
Trusted publishers with an owner and limited reach. The safe batch, most operators approve these together.
Approve all 411
Open one of the eight
PP
PnP-Provisioning-SvcUnverifiedMedium risk
Acts for userswrite Groupsread Directoryread UsersOrg-wide consentNo owner
LookOwnerDisableApprove
  • The triage is already done.Sorted by publisher trust, permission reach and whether anyone owns it. The judgement call a security analyst would make, made before your technician logs in.

  • 411 decisions become one click.Trusted publisher, has an owner, limited reach. Batched on purpose, not to save you the reading.

  • The decision is still yours.Look, assign an owner, disable, approve. AIRM recommends. Your administrator decides, and clicks.

AnalystProve why
Analyst
🔔9A. Chen ▾
9 alerts require your attention9 HighView alerts →
Tenant postureFull posture →
66
Needs attention
Overall health
AI agent posture10monitored
91Behaviour & anomaly healthAcross 10 AI agents
34Management actionsOwners, approvals, alert response
NHI posture15monitored
92Behaviour & anomaly healthAcross 15 NHIs
47Management actionsOwners, approvals, alert response
Blast radius exposure · Critical
Top unapproved exposures
Connector Hub, OutlookCritical
Prospect EngineunclassifiedCritical
InboxGuard 365Critical
Non-human identity risk
Total NHIs
421
Monitored
Unowned NHIs
7
No responsible owner
Critical blast
1
High + Critical band
Orphaned creds
0
Expired secrets on record
Top 5 attack path risksView all →
  • Score the tenant, 0 to 100.An independent index of non-human identity risk. Cross-vendor, scored the same way in every tenant, and defensible in front of a client.

  • Blast radius: what it could actually reach.Not what the permission is called. What the identity can touch if it is wrong, or abused.

  • This is where the eight came from.Every grouping the operator sees is derived here. Same platform, same data, one level down. Open it when a client asks you to prove it.

OperatorAnalyst
The question What do I do?Show me what needs a decision, in the order it needs one. Why does it matter?Show me the evidence, the reach, and what changed since the last scan.
Who opens it Your service desk. Daily.A level one technician, or the one person who runs IT. Your senior tech or vCISO. When it counts.An escalation, a client question, a board pack, an audit.
Who acts A person. Always.AIRM never changes a tenant. Your technician approves, owns or disables. A person. Always.Evidence to decide with. The decision itself never leaves your team.
What you leave with A clean queue.Approved, owned, or disabled. The tenant is in a known state. An answer you can defend.A score, a blast radius, and the trail that produced them.
Power stays with your team

Nothing moves in your tenant unless a person clicks.

AIRM ranks, groups and recommends. It does not act. The judgement is automated so the decision does not have to be, and the decision belongs to your administrator.

  • Nothing changes on its own.AIRM cannot change a tenant on its own. It reads through Microsoft Graph and reports.

  • Every action is a click a human makes.Approve. Assign an owner. Disable. Four buttons, one person, one accountable decision.

  • Agentless. Revoke at any time.Nothing is installed. Consent can be withdrawn, and AIRM goes dark.

Where we won't cheat

"Verified" means verified. It does not mean safe.

A verified publisher means the identity behind an app is confirmed. It says nothing about what the app does with the access you grant it, and we will not let a green tick pretend otherwise. The trust label and the risk score are two different things, on purpose.

Northwind Trading is a fictional demo tenant. The product, the scan and the numbers are real. The company and the identity names are not.