What needs attention now
Open gaps ranked by importance, with the evidence and business impact beside each one.
Free · read-only · no card
A read-only view of what is strong, what is exposed, and what to fix first.
Start your assessment
Work email now. Read-only approval next.
Read-only by designKinervo observes. It cannot change tenant settings.
Microsoft approvalAccess is granted on Microsoft's own consent screen.
A report you can sendClear for owners, useful for the people fixing the issue.
Revoke any timeRemove the enterprise app directly in Entra.
Your deliverable
A visual, private report turns tenant evidence into a clear decision: what matters now, and what happens next.
Open gaps ranked by importance, with the evidence and business impact beside each one.
Control-result drift between scheduled evidence snapshots, separated into improvement, regression and review.
Important sign-in, mailbox and permission indicators pulled out of the background noise.
A short priority list for the owner, backed by enough detail for the IT provider.
Weekly security brief
Northstar & Co.
Week ending 10 August
Read-only monitoring
Posture
78+6
from last week
Sign-in signals
2
recorded in available evidence
Drift
3
control results changed
Priorities
1
action this week
What is assessed
Kinervo reports only what the tenant's permissions and licences allow it to verify. Anything unavailable is labelled—not silently counted as safe.
MFA and sign-in strength
Conditional Access coverage
Admin role exposure
App consent and permissions
Mailbox rules and forwarding
Sign-in and audit indicators
The safe path
You stay in control from the first field to the removal of access.
Enter a work email so Kinervo can prepare the correct organisation-specific Microsoft consent link.
A Global Administrator sees the full read-only permission list on Microsoft's own screen before accepting.
Collection runs automatically. Your private report link is delivered to the work email used at signup.
Kinervo can
Kinervo cannot
Before you approve
No. Kinervo has read-only permissions. It cannot edit a policy, disable an account, remove a rule or make any other tenant change.
Security configuration and the operational evidence needed for the report: identity protections, policies, roles, applications, audit and sign-in information, mailbox forwarding configuration and public domain-authentication records. It cannot read email, files or Teams message content.
The next step can be sent directly to your Microsoft 365 administrator or IT provider, with the permission list and a plain-English explanation.
Nothing is charged automatically because no card is taken. Monitoring stops unless you choose to continue at €199 per month.