Rolling out Copilot? Run this check first. It reads everything your staff can. →
Before you switch Copilot on, a free read-only scan of what it will surface to your staff: oversharing, anonymous links, broad and org-wide access, and unlabelled content. You get a clear score across six areas, measured against the Glow Cloud M365 Security Framework, plus the exposure findings that matter most. You grant a temporary, read-only role (such as Global Reader) for a scheduled window; we run the scan and retain nothing. Prefer to run it yourself? Use our sealed tool instead.
Request your health-check
No cost. No sales call required.
Or see a sample health-check first, no email needed.
Beyond the free check
Full security assessment
Every control scored across the Glow Cloud M365 Security Framework and 6 platforms, with evidence and a recommended fix.
Sharing deep-dive
Every site ranked by exposure, then every link drilled down to who can reach it and whether it expires.
MFA coverage · Legacy auth · Admin roles · Conditional access
Enrolment · Compliance · Encryption · Unmanaged devices
Link scope & expiry · External access · Org-wide access · Permissions
SPF · DKIM · DMARC · Anti-phishing
Sensitivity labels · DLP · Retention · Oversharing
What Copilot can surface · Broadly shared content · Label coverage
What it surfaces
The free check flags the sites open too widely: anonymous links, org-wide access and guest sprawl, the exact exposure Copilot would surface. Want it mapped link by link, with who can reach what? That is the full assessment.
Melbrooke Ltd · 40 sites · SharePoint & OneDrive
Why it's different
There are really three ways to find this out today: run a free script and interpret it yourself, pay for a governance platform that connects to your tenant and keeps your data in its cloud, or buy a Microsoft add-on and read the dashboards yourself. Ours is the missing fourth: free, focused on what Copilot will expose, and actually delivered. You grant a temporary, read-only role (such as Global Reader) for a scheduled window; we hand you an interactive report of where you stand and what to harden, then your access expires. It reads the settings about your tenant, never the files, mail or messages inside it. The only thing kept is the report we give you, and every read is recorded in your own Microsoft 365 audit log.
Free
Not a paid platform, an E5 add-on, or a consultancy day rate.
Read-only, and revocable
It reads settings about the tenant, never your files or mail. Access is temporary, you can revoke it any time, and every read shows in your own audit log.
Interactive, and explained
A live report you filter and drill into, by platform, domain and severity, plus a readout. Not a static PDF or a raw script to decode.
The report
A raw native score buries the signal under hundreds of granular toggles. Ours surfaces the security-critical configurations, their current state, and what to harden first, so you see your posture in minutes, not a spreadsheet to wade through.
Melbrooke Ltd · June 2026
Critical oversharing is present. Resolve the High items before enabling Copilot.
Top findings
“11 sites open to the whole company.” A real first finding.
After the free check
The free check is the Copilot-readiness slice. If you decide to go further, the paid deep-dive scores every control across the Glow Cloud M365 Security Framework and 6 platforms, then maps sharing site by site and link by link. Here is exactly what that report looks like.
Questions, answered
Yes. It is a free, no-obligation assessment. You keep the report whether or not you go on to work with us.
You grant a temporary read-only role (such as Global Reader) that you can revoke at any time, or you run a sealed script yourself and send us the output. Nothing is installed, and you stay in control throughout.
Six areas: identity and access (MFA, legacy auth, admin roles), devices and Intune, SharePoint and external sharing, email security (SPF, DKIM, DMARC), data protection (labels, DLP, retention) and Copilot readiness. Findings are scored against the Glow Cloud M365 Security Framework.
Yes. We flag the oversharing, broadly shared content and label gaps that Copilot would surface to users, so you can fix them before you switch Copilot on.
No. There is no obligation. If you want help fixing what we find, we can quote a remediation sprint, but the report and the priorities are yours to keep.