The control plane for every non-human identity in Microsoft 365.
AIRM discovers, understands, governs and improves every non-human identity, AI agents included in a Microsoft 365 tenant. Independent of Microsoft, agentless, human-approved change, built for MSP scale. Here's what's inside.
Find every non-human identity, and know its real risk.
Non-Human Identity Discovery
Continuously discover and monitor every non-human identity in your Microsoft 365 tenant: service principals, app registrations, OAuth-connected apps, connectors, Copilots and AI agents.
- Automatic discovery, no manual inventory
- Classified by type: AI agent, automation, legacy app, Microsoft first-party
- Owner assignment & accountability
- Credential-age monitoring with expiry alerts
Non-Human Identity Security
Score every identity on two independent axes, what it’s doing now, and how bad it would be if compromised. A quiet app with dangerous permissions is your biggest threat.
- Behaviour Risk band (static · behavioural · anomaly)
- Blast-radius band from granted permissions
- Credential monitoring & unowned-identity detection
- Known-rogue service-principal detection
Anomaly Intelligence Engine
Our proprietary, scan-over-scan behavioural engine builds a fingerprint for every identity and gets sharper the longer it runs, the moat a point-in-time tool can’t replicate.
- 17 anomaly signals monitored per identity
- Permission-scope drift detection on approved agents
- Approved-AI-gone-rogue detection
- Accumulated intelligence, scan over scan
Act on it, prove it, and raise the score.
Blast Radius Analysis
Map exactly what an attacker would reach from any compromised identity, built from actual granted permissions, not assumed activity. Populated from day one.
- Built from real granted permissions, not historical activity
- Populated from day one, no baseline wait
- Per-identity reachable data, mailboxes & tenants
Identity Graph
Visualise trust relationships and lateral-movement paths across the tenant, Graph, Attack Paths and Temporal views, Crown-Jewel highlighting, SVG export for board reports.
- Graph, Attack Paths & Temporal views
- Crown-Jewel highlighting
- SVG export for board reports
Compromise Simulation
Run a permission-aware attack model against any identity, a 0-100 blast score, human-readable attacker actions, reachable data types, and scoped remediation. No live data touched.
- 0-100 blast score per identity
- Human-readable attacker actions
- Scoped remediation, no live data touched
Compliance Mapping
Map every finding to 11 frameworks (EU AI Act, DORA, ISO/IEC 42001, NIST AI RMF and more) and generate branded, per-framework, audit-ready reports.
- 11 frameworks incl. EU AI Act, DORA, ISO 42001
- Per-framework, audit-ready reports
- Branded evidence pack for auditors & insurers
Alerting & Integrations
P1, P5 smart alerts straight into your PSA (ConnectWise, HaloPSA, Autotask), plus webhooks to SIEM, Slack and Teams, no middleware, deduplicated, per tenant.
- P1, P5 smart alerts into your PSA
- ConnectWise, HaloPSA, Autotask
- Webhooks to SIEM, Slack & Teams, deduplicated
419 NHIs to review. 8 need a human.
AIRM decides what matters. You decide what happens.
AIRM does the triage before your team ever opens the tenant. It ranks by publisher trust and permission reach, batches the safe ones, and surfaces the handful that actually carry risk. Then it stops, and waits for a person.
Here's what's running in Northwind Trading
The triage is already done.Sorted by publisher trust, permission reach and whether anyone owns it. The judgement call a security analyst would make, made before your technician logs in.
411 decisions become one click.Trusted publisher, has an owner, limited reach. Batched on purpose, not to save you the reading.
The decision is still yours.Look, assign an owner, disable, approve. AIRM recommends. Your administrator decides, and clicks.
Score the tenant, 0 to 100.An independent index of non-human identity risk. Cross-vendor, scored the same way in every tenant, and defensible in front of a client.
Blast radius: what it could actually reach.Not what the permission is called. What the identity can touch if it is wrong, or abused.
This is where the eight came from.Every grouping the operator sees is derived here. Same platform, same data, one level down. Open it when a client asks you to prove it.
| Operator | Analyst | |
|---|---|---|
| The question | What do I do?Show me what needs a decision, in the order it needs one. | Why does it matter?Show me the evidence, the reach, and what changed since the last scan. |
| Who opens it | Your service desk. Daily.A level one technician, or the one person who runs IT. | Your senior tech or vCISO. When it counts.An escalation, a client question, a board pack, an audit. |
| Who acts | A person. Always.AIRM never changes a tenant. Your technician approves, owns or disables. | A person. Always.Evidence to decide with. The decision itself never leaves your team. |
| What you leave with | A clean queue.Approved, owned, or disabled. The tenant is in a known state. | An answer you can defend.A score, a blast radius, and the trail that produced them. |
Nothing moves in your tenant unless a person clicks.
AIRM ranks, groups and recommends. It does not act. The judgement is automated so the decision does not have to be, and the decision belongs to your administrator.
Nothing changes on its own.AIRM cannot change a tenant on its own. It reads through Microsoft Graph and reports.
Every action is a click a human makes.Approve. Assign an owner. Disable. Four buttons, one person, one accountable decision.
Agentless. Revoke at any time.Nothing is installed. Consent can be withdrawn, and AIRM goes dark.
"Verified" means verified. It does not mean safe.
A verified publisher means the identity behind an app is confirmed. It says nothing about what the app does with the access you grant it, and we will not let a green tick pretend otherwise. The trust label and the risk score are two different things, on purpose.