Granted reach, attested agent scope and unknown signals are kept visibly separate.
Security & risk
What Aristo may read inside Contoso, what that reading shows, and where the edges are.
AI outside your sanctioned set
A labelled illustrative aggregate showing how third-party AI exposure is governed.
416 people are in this labelled illustrative scenario for AI applications outside the sanctioned set. It demonstrates the aggregate governance view; it is not a claim that Microsoft measured activity in a real tenant.
Evidence & data — People signed into each unsanctioned AI application
Comparison
Every application named here was used by at least 5 people; one used by fewer is counted in the line below and never named. These are sign-in events, not usage — a person who signed in once and left is in this count exactly like a person who uses it daily, because the audit log records the door and not the room.
Source & method
Illustrative-scenario sign-in aggregate
Basis: Labelled estimate
Accessible data
| Application | People |
|---|---|
| ChatGPT | 268 |
| Claude | 148 |
9 further applications are not listed: each was used by fewer than 5 people, so the count is disclosed and the name is withheld.
9 further applications were used by fewer than 5 people each and are not named. The count of applications is disclosed; which ones they were is withheld.
What your agents may reach
The capabilities this estate's agents were attested to touch, counted across all of them.
Evidence & data — Capabilities the agents built here were attested to reach
Comparison
4 agents carry an attestation. An agent can hold more than one capability, so these bars are not a division of the total — they are how many of the same agents each capability applies to.
Source & method
The forge questionnaire, answered by each maker before the agent was built.
Basis: Self-attested
Accessible data
| Capability | Agents | What it means |
|---|---|---|
| Your files | 4 of 4 | Documents inside your tenant, in OneDrive and SharePoint. |
| The public web | 1 of 4 | Outside your tenant — the scope that leaves your boundary. |
An agent may hold more than one capability, so these counts overlap and do not sum to the number of agents.
Security posture
Microsoft's own Secure Score, and what the estate score was computed over.
Your Microsoft Secure Score stands at 88% of the maximum Microsoft computes for a tenant your size. It carries 25% of the estate score.
88/100 security readiness — labelled illustrative scenario. Every pillar of the estate score is available on this run, so nothing has been dropped and no weight has been redistributed.
Explore permissions and data boundariesLive grants, reads not held, agent scope and explicit exclusions
What Aristo is allowed to read, right now
Decoded from the roles claim in your own tenant's token. This is the grant state, not the request.
Scroll sideways for the remaining columns.
| Permission | What it powers | Why it is needed | State live |
|---|---|---|---|
| Organization.Read.All | Read the tenant and its licence position | Supplies the paid-seat count every money figure in this product divides by. | Granted |
| User.Read.All | Read the directory, aggregate only | Supplies the per-team headcount that turns a licence bill into a cost per head. | Granted |
| Reports.Read.All | Read the Copilot usage report | Supplies which seats show genuine activity, which is what separates an active seat from an assigned one. | Granted |
| SecurityEvents.Read.All | Read Microsoft Secure Score | Supplies the security pillar of the Frontier score. | Granted |
| AuditLog.Read.All | Read sign-in audit logs, aggregate only | Supplies which unsanctioned AI tools staff are signing in to, counted and k-floored. | Granted |
| ServiceMessage.Read.All | Read the Message Center | Supplies the roadmap changes targeted at this tenant rather than announced publicly. | Granted |
| CopilotPackages.Read.All opt-in expansion — not required |
Read the Copilot agent catalogue | Lists the agents registered in this tenant that Aristo did not build. | Granted |
| Policy.Read.All opt-in expansion — not required |
Read conditional-access policy | Would let this product say which of your policies apply to Copilot traffic. Not granted here. | Not granted |
| RoleManagement.Read.Directory opt-in expansion — not required |
Read privileged role assignments | Would let this product count how many people hold an administrative role. Not granted here. | Not granted |
Reads Aristo does not hold
Each one names the section it would fill, and what stands there today instead.
Scroll sideways for the remaining columns.
| Consent | What it would light up | What stands there today |
|---|---|---|
| SecurityEvents.Read.All | Microsoft Secure Score — the security pillar of the Frontier score. | The pillar is dropped and the remaining pillars re-weighted. The score still computes; it computes without posture, and says so. |
| AuditLog.Read.All + Directory.Read.All | The unsanctioned-AI signal — how many staff signed into third-party AI apps, counted and k-anonymous. | Both reads answer with a refusal, so the signal reads "not measured" rather than "zero". A zero here would be the most reassuring false statement this product could make. |
| CopilotPackages.Read.All | The Copilot agent catalogue — agents published into your tenant that Aristo did not build. | The catalogue stays dark on the AI agents workspace. Aristo shows the agents it built and the ones your registry reports, and does not guess at the rest. |
What your agents are allowed to reach
The capability scope each agent's maker attested to before Aristo would build it.
Scroll sideways for the remaining columns.
| Agent | Web search | OneDrive & SharePoint | Risk tier |
|---|---|---|---|
| Renewal brief | No | Yes | low |
| Bid librarian | Yes | Yes | medium |
| Month-end checklist | No | Yes | low |
| Onboarding buddy | No | Yes | low |
The data boundary
What Aristo may do inside your tenant, and where what it keeps physically lives.
What this page does not cover
The edge of the map, named — so it is found here rather than in a meeting. 4 surfaces.
Why each of these 4 is not read
- Data-loss policy and label posture. Aristo reads no Purview policy, no sensitivity label and no DLP incident. Showing a posture here would need Microsoft Purview reads this product has never asked for, and it would put a compliance judgement in a product that is not a compliance tool.
- Conditional access and sign-in risk. Entra reports these and Aristo does not read them. The one sign-in signal this product uses is the aggregate unsanctioned-AI count below, and it is deliberately the only one.
- Per-agent Microsoft permissions. Microsoft exposes no per-agent permission inventory. What an agent your people forged is allowed to reach is shown below as its maker's own attestation, which is a different and weaker thing — and is labelled as one.
- Cloud-app discovery beyond sign-ins. Defender for Cloud Apps is not connected to this product. The unsanctioned-AI count is read from sign-in audit logs only, so it sees apps people signed into with a work identity and nothing else.
How each figure on this page is arrived at, and what is not measured
The Secure Score is Microsoft's, read through a consent this page names. The permission table is decoded from the roles claim in your own tenant's app token on each request, so it cannot go stale and cannot flatter. The unsanctioned-AI count comes from your sign-in audit logs, is floored at 5 people, and names an application only when 5 or more people signed into it.
- The security pillar on this run is self-reported — somebody answered for it rather than Microsoft measuring it. The estate score is therefore labelled an estimate wherever it appears.
- Nothing on this page is a composite of the others. There is no single risk number to argue with, because there is no single risk number.