Rolling out Copilot? Run this check first. It reads everything your staff can. →
Security & governance
We map who can actually reach every file across SharePoint and OneDrive, trace every external share down to the recipient, and re-run it each quarter to track what changed. Interpreted by a named architect, read-only, and handed to you as a report you own - a config baseline included.
The Glow Cloud M365 Security Assessment has its own home. Full detail, sample reports and how it works live at glowcloudsecurity.com.
Visit glowcloudsecurity.com →The permission & sharing deep-dive
Most audits stop at a misconfiguration. We show you the consequence: every external share, every broken-inheritance file, and a visual map of who can reach which document, through which site and which library, and how they got there - including the access that stops at one library, or at one shared file. It is the oversharing Copilot would surface on day one - found before it does. Nothing else in this space visualises access like this.
Pick a person and see every site and library they can reach, how they got there, and every item where their access breaks from the site default:
One account's real reach: Colin Rathbone lands on 16 sites - mostly through group nesting, two by direct grant - and inside them, 12 files where his access breaks from the site default. This is what a leaver, a contractor, or a busy admin account can actually get to. Static sample; the live report is fully interactive.
Or turn it around and start from a site - every principal that reaches in, with default groups, site admins and direct grants told apart, and membership marked default where it is only inferred, not confirmed:
Default = group membership inferred from the site's nesting, not independently confirmed. Everything routes through the site (it is on the access path); the right column breaks inheritance from it. Static sample; the live report is fully interactive.
Interactive sample
Pick a person and see everything they can reach. Map a site, compare two users, drill into every discrepancy. The full report on sample data, nothing to install.
Run one is the full map. Re-run it each quarter on the retainer and the drift view shows what access changed since last quarter - new grants, escalations, and who can now reach what.
Melbrooke Ltd · SharePoint & OneDrive
Sales (Members)
M365 group
Human Resources
Edit · site
SG-Finance
Security group
Employee Records
Read · unique scope
k.reed (CFO)
Direct grant
CEO Compensation.xlsx
Full · unique scope
Discrepancies
Beyond the score
A configuration score - however it is produced - tells you what is set, not who can reach what. Our value is the layer above: who can actually reach a given file, what is over-shared, and a named architect accountable for what to fix first.
The config baseline is included, done honestly and licence-aware - if you don't own a feature you are not marked down for it, and nothing is a number padded to flatter.
Microsoft-verified publisher · Glow Cloud M365 Security Framework · read-only, always
Framework coverage
87% of controls scored
Most scored automatically · the judgement calls flagged for manual review, each with the exact portal page to check
Microsoft 365 admin center
8/14 auto
Microsoft 365 Defender
15/18 auto
Microsoft Purview
3/4 auto
Microsoft Entra
30/35 auto
Exchange Online
12/12 auto
SharePoint admin
15/15 auto
Microsoft Teams
16/17 auto
Fabric / Power BI
11/11 auto
Your report. Your data. No portal.
We don't keep your configuration in a cloud you have to log into. The assessment runs read-only from our access and produces a single, self-contained report you own and keep. Nothing to subscribe to, nothing to leak.
A one-off assessment is purged after 30 days. Retainer clients keep prior reports only to compute quarter-over-quarter drift, on our own secured storage and deletable on request.
Unlike portal-based governance platforms, your tenant data never becomes a standing dataset in someone else's cloud.
What lands in your inbox
Independent, on the record
"You can't grade your own homework and hand it to your insurer."
A security score you generated about yourself is fine for internal tidying. But the moment someone external needs to trust your posture - a cyber-insurer, an auditor, your board, a client doing due diligence, an acquirer - self-assessment carries no weight.
An independent assessment, run by a named person who is accountable for the findings and carries £1M professional-indemnity cover, is evidence those parties will accept. That independence is structural: an assessment you run yourself can never be independent of you.
Who this is for
The engine
From a free health-check to recurring assurance, each option reads more, and none of them ever writes.
Free
Oversharing exposure and a Copilot-readiness verdict. The free way in.
Read-only · no crawl
Sample · Copilot-readiness verdict →Signature
Who can reach what in SharePoint - and how they got that access, through a group, a share or a direct grant. Site-wide, library-level and single-file reach told apart. Least-privilege, proven.
Read-only · permission crawl
Sample · first run →Sample · what the retainer adds →Reachability
Every site, then every link: who can reach it, at what scope, down to the named recipient, and whether it ever expires.
Read-only · overnight crawl
Sample · per-site →Sample · per-link →Full suite
The reachability map and sharing deep-dive, plus the config baseline, in one run.
Read-only · overnight crawl
Sample · full report →Sample · what the retainer adds →Sample · executive summary →Retainer
The full suite re-run each quarter, with drift on both axes: posture (findings closed, regressed and new) and access (who gained reach, whose level went up). The recurring assurance.
Read-only · quarterly
Sample · posture drift →Sample · reachability drift →Foundation
The included foundation on its own: identity, email, Teams, SharePoint, devices and data protection - assessed honestly and licence-aware.
Read-only · no crawl
Sample · full report →Sample · what the retainer adds →Sample · executive summary →Read-only, app-only
Least-privilege access. We never write to your tenant, ever.
Microsoft-verified publisher
Verified on the consent screen.
£1M professional indemnity
Insured, boutique, accountable.
Your data stays yours
It never lives in a third-party portal.
Sample reports
Melbrooke Ltd is a fictional company generated through the real engine - real reports, drillable in your browser, zero client data.
The health-check costs nothing and shows you exactly what the engine sees.
We never change a thing. Consent is scoped, read-only, and removed when the run is done.
An interactive report you can drill, not a PDF you decode alone - walked through in a readout.
Inside the reports
Clear, interactive reports from one read-only run. The visuals below mirror the Melbrooke Ltd demo: fictional company, real engine.
Melbrooke Ltd · 13 domains · 54 of 160 controls passing
Compliance by domain
Identity, Intune, SharePoint, email, data and auditing, each control marked Pass, Partial, Fail or Manual across the whole Glow Cloud M365 Security Framework, so you see precisely where the gaps are.
Melbrooke Ltd · July 2026
Significant gaps
Multiple high-severity controls are failing. Address the priorities below before enabling Copilot or broad collaboration.
Top priorities
Executive summary
A clear verdict and the High-severity priorities to act on first, so the readout takes minutes, not a wade through a spreadsheet.
Glow Cloud Framework · SPG-AUTH-201 · Account & Authentication
What we found
No all-users MFA Conditional Access policy, and security defaults are off - MFA is not enforced tenant-wide.
Why it matters
Without enforced MFA, a single stolen password is enough to take over an account - the primary path to account takeover and lateral movement.
Recommended action
Enforce MFA for all users via Conditional Access (pilot in report-only first), then disable security defaults.
Evidence · GET /identity/conditionalAccess/policies · GET /policies/authenticationMethodsPolicy
Every finding, in full
Each finding carries its framework control reference, what we found, why it matters, a recommended action and the evidence behind it. See a complete sample report, filterable by platform, domain, type, severity and status.
The sharing deep-dive
Every site ranked by exposure (per-site), then every individual link drilled down to who can reach it, what it exposes and whether it ever expires (per-link), delivered as two separate reports.
Melbrooke Ltd · 40 sites · SharePoint & OneDrive
Melbrooke Ltd · SharePoint & OneDrive
Named to the person, not just the domain: 32 external recipients surfaced across the guest links. Highest risk here - /Finance/Aged Debtors 2026.xlsx, an "Anyone" edit link anyone with the URL can change.
What you get
Run an MSP? The engine white-labels. You own the client, we supply the engine and the report - partner pricing on request.
Talk to us →Point-in-time assessment; not a certification or accredited audit; not legal advice. Assessments can be aligned to recognised industry best practice on request.
Read-only. The whole tenant. One clear report.