Demo. Fictional data for Kestrel Ridge Manufacturing.

Operator console

Select an engagement

Choose a workspace to review or create a new one.

SecureTenant

Evidence-led tenant security, in one calm workspace.

Choose an engagement to review its current assessment, collect new evidence, or prepare an executive scorecard.

New workspace

Create engagement

Advanced workspace identifier

Read-only discovery

Run assessment

The console opens a delegated Microsoft Graph session using read scopes only. Raw evidence is preserved before analysis.

Advanced connection options

Sign-in opens in your browser by default. Device code is for machines without one; Microsoft security defaults block it on tenants created on or after 1 July 2026, so leave it unchecked unless you know the tenant predates that.

Operator-attended discovery

Run practice baseline

This fixed read-only baseline uses the engagement's pinned tenant and per-lane registrations. You will complete browser sign-in separately for each step.

The console runs one fresh PowerShell process per step, stops on the first failure, retains no access tokens, and writes evidence only to this engagement's local folder. COV-007, remediation, deployment, and tenant changes are not part of this action.

Client deliverable

Export scorecard

The scorecard is self-contained and sanitized. It excludes tenant identifiers, evidence paths, raw evidence, internal control IDs, and technical warnings.

Scorecard title

Live change

Apply approved change

This exact current change has recorded written approval. Confirm once to run WhatIf, then apply only if it succeeds. No Change ID retyping is required.

Operator override

Apply All pipeline candidates

The pipeline uses one exact plan-bound consent session, then runs WhatIf, live apply, and asserted readback verification for each listed change in order. Every authoritative calibration, dependency freshness, lockout, and dwell gate is rechecked at runtime, so a candidate may stop before its write. The pipeline stops on the first failure and never rolls back automatically. Manual, generated-credential, non-pending, and unapproved work is excluded.

Manual verification

Record what was checked