Skip to content
Aristo's read Grounded in page evidence

Granted reach, attested agent scope and unknown signals are kept visibly separate.

Why it matters
An absent read cannot masquerade as a reassuring zero or an invented risk score.
Recommended action
If incomplete grants or unattested reach appear, resolve them before expanding access.

Security & risk

What Aristo may read inside Contoso, what that reading shows, and where the edges are.

There is no Aristo risk score on this page. Every figure below is either Microsoft's own number, a live grant state decoded from your tenant's token, or a count from your own audit logs — nothing here is a weighting somebody chose.

AI outside your sanctioned set

A labelled illustrative aggregate showing how third-party AI exposure is governed.

estimatek ≥ 5

416 people are in this labelled illustrative scenario for AI applications outside the sanctioned set. It demonstrates the aggregate governance view; it is not a claim that Microsoft measured activity in a real tenant.

People signed into each unsanctioned AI application
last 30 days people with a work identity Labelled estimate
ChatGPT
268 people
Claude
148 people
Illustrative scenario
Evidence & data — People signed into each unsanctioned AI application

Comparison

Every application named here was used by at least 5 people; one used by fewer is counted in the line below and never named. These are sign-in events, not usage — a person who signed in once and left is in this count exactly like a person who uses it daily, because the audit log records the door and not the room.

Source & method

Illustrative-scenario sign-in aggregate

Basis: Labelled estimate

Accessible data

People signed into each unsanctioned AI application
ApplicationPeople
ChatGPT268
Claude148

9 further applications are not listed: each was used by fewer than 5 people, so the count is disclosed and the name is withheld.

9 further applications were used by fewer than 5 people each and are not named. The count of applications is disclosed; which ones they were is withheld.

Source: Illustrative-scenario sign-in aggregate As of: 2026-08-29 Illustrative aggregate only. No real sign-in event or person is represented.

What your agents may reach

The capabilities this estate's agents were attested to touch, counted across all of them.

attested
Capabilities the agents built here were attested to reach
current register agents Self-attested
Your files
Documents inside your tenant, in OneDrive and SharePoint.
4 of 4
The public web
Outside your tenant — the scope that leaves your boundary.
1 of 4
Agents attested to reach this capability
Evidence & data — Capabilities the agents built here were attested to reach

Comparison

4 agents carry an attestation. An agent can hold more than one capability, so these bars are not a division of the total — they are how many of the same agents each capability applies to.

Source & method

The forge questionnaire, answered by each maker before the agent was built.

Basis: Self-attested

Accessible data

Capabilities the agents built here were attested to reach
CapabilityAgentsWhat it means
Your files4 of 4Documents inside your tenant, in OneDrive and SharePoint.
The public web1 of 4Outside your tenant — the scope that leaves your boundary.

An agent may hold more than one capability, so these counts overlap and do not sum to the number of agents.

Security posture

Microsoft's own Secure Score, and what the estate score was computed over.

attested

Your Microsoft Secure Score stands at 88% of the maximum Microsoft computes for a tenant your size. It carries 25% of the estate score.

88/100 security readiness — labelled illustrative scenario. Every pillar of the estate score is available on this run, so nothing has been dropped and no weight has been redistributed.

Source: Aristo Frontier scale — security pillar As of: 2026-08-29 A pillar with no reading is dropped and the remaining weights re-normalised. It is never scored zero.
Explore permissions and data boundariesLive grants, reads not held, agent scope and explicit exclusions

Reads Aristo does not hold

Each one names the section it would fill, and what stands there today instead.

Scroll sideways for the remaining columns.

Permissions Aristo has not been granted, what each would light up, and what the product shows in its absence.
ConsentWhat it would light upWhat stands there today
SecurityEvents.Read.All Microsoft Secure Score — the security pillar of the Frontier score. The pillar is dropped and the remaining pillars re-weighted. The score still computes; it computes without posture, and says so.
AuditLog.Read.All + Directory.Read.All The unsanctioned-AI signal — how many staff signed into third-party AI apps, counted and k-anonymous. Both reads answer with a refusal, so the signal reads "not measured" rather than "zero". A zero here would be the most reassuring false statement this product could make.
CopilotPackages.Read.All The Copilot agent catalogue — agents published into your tenant that Aristo did not build. The catalogue stays dark on the AI agents workspace. Aristo shows the agents it built and the ones your registry reports, and does not guess at the rest.
Nothing on this list is switched on by reading this page. Each is an admin consent in Entra, granted once and revocable there at any time.

What your agents are allowed to reach

The capability scope each agent's maker attested to before Aristo would build it.

attested

Scroll sideways for the remaining columns.

Each agent built in this tenant and the capability scope its maker attested to. Self-attested, not measured.
AgentWeb searchOneDrive & SharePointRisk tier
Renewal brief No Yes low
Bid librarian Yes Yes medium
Month-end checklist No Yes low
Onboarding buddy No Yes low
Microsoft exposes no per-agent permission inventory, so this table is the maker's own declaration rather than an observation of the running agent. It is the strongest honest statement available, and it is labelled as what it is.

The data boundary

What Aristo may do inside your tenant, and where what it keeps physically lives.

Read-only, always
Every application permission Aristo holds is a read. It writes nothing into your tenant — no mail, no files, no configuration — and the one write that exists anywhere in the product is an opt-in licence reroute an admin must consent to separately.
Aggregate, always
A leader surface never shows an individual. Teams are blended at 5 people or more before anyone sees them, and the only per-person view in this product opens with that person's own sign-in.
One named region
Everything Aristo stores about you lives in one named Azure region — Azure Central US — inside Microsoft's cloud; nothing is copied to another region, and the data store is geo-redundant with backups every four hours.
Never trained on
Aristo does not use your data to train a model. When an AI answer is requested, the minimum prompt needed for that answer is sent to the AI provider configured for your organisation; Aristo does not retain that prompt or answer as conversation history. Provider processing location, retention and abuse-monitoring terms follow your contracted configuration and are disclosed on the Trust page — this panel does not call third-party processing “inside your tenant”.

What this page does not cover

The edge of the map, named — so it is found here rather than in a meeting. 4 surfaces.

Data-loss policy and label postureConditional access and sign-in riskPer-agent Microsoft permissionsCloud-app discovery beyond sign-ins
Why each of these 4 is not read
  • Data-loss policy and label posture. Aristo reads no Purview policy, no sensitivity label and no DLP incident. Showing a posture here would need Microsoft Purview reads this product has never asked for, and it would put a compliance judgement in a product that is not a compliance tool.
  • Conditional access and sign-in risk. Entra reports these and Aristo does not read them. The one sign-in signal this product uses is the aggregate unsanctioned-AI count below, and it is deliberately the only one.
  • Per-agent Microsoft permissions. Microsoft exposes no per-agent permission inventory. What an agent your people forged is allowed to reach is shown below as its maker's own attestation, which is a different and weaker thing — and is labelled as one.
  • Cloud-app discovery beyond sign-ins. Defender for Cloud Apps is not connected to this product. The unsanctioned-AI count is read from sign-in audit logs only, so it sees apps people signed into with a work identity and nothing else.
How each figure on this page is arrived at, and what is not measured

The Secure Score is Microsoft's, read through a consent this page names. The permission table is decoded from the roles claim in your own tenant's app token on each request, so it cannot go stale and cannot flatter. The unsanctioned-AI count comes from your sign-in audit logs, is floored at 5 people, and names an application only when 5 or more people signed into it.

  • The security pillar on this run is self-reported — somebody answered for it rather than Microsoft measuring it. The estate score is therefore labelled an estimate wherever it appears.
  • Nothing on this page is a composite of the others. There is no single risk number to argue with, because there is no single risk number.