The safest thing you'll connect to a tenant.
AIRM is designed to be the lowest-risk integration in a client tenant: agentless, human-approved, and reversible in one click. Nothing is installed, no business content is read, and nothing changes unless a human explicitly acts. Here is exactly how it works.
How AIRM connects
- Agentless. Nothing is installed in the tenant or on any endpoint. AIRM connects through the Microsoft Graph API.
- Change-controlled. AIRM requests delegated Graph permissions, listed in full at consent. It changes nothing without a person approving the action.
- GDAP-compatible. Designed for MSP delivery through Granular Delegated Admin Privileges, without standing access where it isn't needed.
- Microsoft Verified Publisher. Sabiki's publisher identity is verified with Microsoft. A Global Admin approves a one-time consent.
What AIRM can access, and what it can't
AIRM reads identity and permission metadata only: users, applications, service principals, OAuth grants, role assignments, and sign-in and audit metadata. It does not read mailboxes, files, chats, or any business content. It cannot create, modify or delete anything in the tenant unless you explicitly choose to act on a finding.
The permissions we request
| Permission | Why | Access |
|---|---|---|
Directory.Read.All | List users, apps and service principals (the non-human identities) | READ |
Application.Read.All | See app registrations, agents and their granted scopes | READ |
AuditLog.Read.All | Spot stale or unused credentials | READ |
What we store
AIRM stores the identity inventory and risk findings needed to produce the report and the Sabiki NHI Risk Score™. It does not store your emails, files or business content.
Revoke access at any time
Go to the Microsoft Entra admin centre → Enterprise applications → Sabiki AIRM → revoke. Access ends immediately. You stay in full control.
Hosting & data residency
AIRM and the customer portal run on Microsoft Azure, in the Southeast Asia region (Singapore). The identity inventory and the risk findings are stored in MongoDB Atlas, a managed database service, running on Azure in the same Singapore region. Your tenant data stays in Singapore.
Azure holds ISO/IEC 27001, ISO 27018 and SOC 1, SOC 2 Type 2 and SOC 3. MongoDB Atlas holds ISO/IEC 27001:2022, ISO 27017, ISO 27018, SOC 2 and CSA STAR. Both publish their reports in their own trust centres, and both are named on our sub-processor page. These are our providers' certifications, not ours. Sabiki's own SOC 2 audit is underway, and we will not claim a certification before it exists.
Certifications & attestations
Sabiki AIRM is a Microsoft Verified Publisher, which means Microsoft has confirmed the identity of the publisher behind the application. That is a statement about who we are, not a certification of the product, and we will not present it as one.
A SOC 2 audit is presently underway. This page will be updated when the report is issued. We will not claim a certification before it exists, and we will not ask you to take that on trust in the meantime.
What we can point at today is architecture rather than paperwork: AIRM is agentless, makes no change without human approval, stores identity findings rather than your content, and can be revoked from the Entra admin centre at any time, ending access immediately.
Sub-processors
A current list of sub-processors and the purpose of each is maintained and provided on request, and to every customer before a tenant is connected.
Security questions before you connect a tenant?
Talk to us directly, or run the free Sabiki NHI Risk Score on any Microsoft 365 tenant and see exactly what AIRM does.
Free AI Readiness Score →