IRISAI
Technology at work ISO/IEC 27001:2022 certified

Identity and cloud assurance

Your directory already knows what your asset register doesn’t.

Iris AI is a South African AI and big-data company with eight years of turning high-volume operational telemetry into decisions. We read your Entra ID, Active Directory, Intune and Defender estate as it actually is — then hand you the findings, the fix for each one, and the evidence that closes it.

Every organisation can describe its identity estate. Very few can measure it. The gap between the two is where audit findings, breaches and regulatory exposure live — and it is measurable in days, read-only, without touching a single production system.

Identity and cloud assurance is a read-only assessment of an organisation’s Microsoft identity estate — Microsoft Entra ID, on-premises Active Directory, Microsoft Intune, Microsoft Defender, Microsoft Purview and Exchange Online — that measures the estate as it is actually configured rather than as it is documented, and reports every gap with a prescribed fix and the evidence needed to close it. Iris AI delivers it from Johannesburg, South Africa, mapped to the Auditor-General of South Africa’s IT general control areas and to POPIA obligations.

The scale we work at

R9.1bn of transactions reconciled in a single revenue-assurance engagement
77million transaction records ingested and interrogated from one utility platform
4.5million licensed identities inside the tenants we assess
266million rows in the largest single production table we operate
31.5million endpoint telemetry records captured in eighteen days on one fleet
55+ independent organisations running on a platform we built and support

What one assessment surfaces

Six findings from a single read-only collection run

These came out of one enterprise tenant, on the first pass, with no agent installed and no ability to change anything. Every figure is drawn from the tenant’s own records.

Tenant readout anonymised · one assessed enterprise tenant · first collection run
11.6% of identities can do MFA 21,884 of 189,239 registered for a strong method — against a written policy mandating it. The figure comes from Microsoft’s own aggregate report, so it survives challenge.
1,585/1,693 applications with no owner Nobody is accountable for 94% of the registered applications and service principals in the tenant. There is no one to attest them in an access review.
118/13,574 devices reachable by Group Policy The estate was believed to be domain-joined. It is 62% workplace-joined and 28% cloud-joined. The assumed deployment and hardening channel reaches 0.9% of it.
71 vs 8,532 machines on the register vs in Defender Coverage had been reported against the 71-machine view. The real denominator was two orders of magnitude larger, so every percentage derived from it was wrong.
21% of managed Windows devices encrypted 1,209 of 5,756. Over half of the unencrypted remainder sit on accounts holding personal information — direct POPIA exposure if a device is lost.
4/5 mail domains publishing no DMARC All five route through Microsoft 365 and all five publish SPF. Without DMARC, anyone can send as those domains and nothing rejects it.
Captured in that one run: 402,365 sign-ins · 128,873 directory audit events · 718,000+ unified audit records · 1.6 million evidence rows.

Coverage

What we read across your estate

Six planes, read together. Most assessments look at one and infer the rest — which is exactly how a 71-machine register survives next to an 8,532-machine reality.

Entra ID Users, groups and membership, devices, directory roles and privileged-access settings, conditional-access policies, named locations, authentication-method policy, registered applications, service principals, delegated consent, administrative units, sign-in and audit logs, provisioning logs, risky users and risk detections.
Active Directory On-premises domain posture, hybrid sync health and scope, which objects actually synchronise and which only appear to, and the server estate that domain join still governs — usually the part nobody is managing.
Intune Enrolment and ownership, join type, management channel, compliance state, configuration profiles, encryption status, processor architecture, and the devices that appear in one surface and nowhere else.
Defender Machine inventory, vulnerabilities and exposure, alerts and incidents, automated investigations, response actions — read through the Defender interface in its own right, not inferred from directory data.
Purview and Exchange Unified audit log, retention posture, and mail-flow authentication measured from public DNS — SPF, DKIM, DMARC and MTA-STS as the rest of the internet sees them.
Licensing Subscribed products against actual assignment and use, so you can see which controls you are already paying for and have not switched on. This line often funds the engagement.

Read-only throughout

Every permission granted is a read permission. Nothing in your tenant can be created, changed or removed by the assessment, and it cannot widen its own reach.

Nothing sensitive changes hands

Your administrator approves the access; we generate our own sign-in material and register only the public half of it. There is nothing to email, and nothing to leak.

One dedicated registration

Purpose-built for your assessment rather than shared with other work, so approving it grants reach to nobody else.

Scoped to what a finding needs

Where a permission would put personal information within reach without improving a finding, we hand it back — and our tooling records the omission.

Auditable from your side

The registration belongs in your own monthly access review. You can withdraw it in one action, and every request it made appears in your logs.

Your data stays classified

Evidence lands in a per-client store where every table carries a data classification and a POPIA category, with per-load lineage and a stated retention period.

Method

A signal catalogue, not a scanner report

The findings do not come from a product’s default rule set. They come from a standing Iris catalogue built and corrected across real tenant engagements, where every signal carries a permanent identifier, the plane it is read from, what “bad” looks like, and what to do about it. Identifiers are never renumbered, and a claim we later disprove is struck through with a date rather than quietly deleted.

95signals, each with a permanent ID
13domains of tenant posture
9cross-plane correlation questions
12documented false positives
46carried-forward lessons

The twelve documented false positives matter as much as the ninety-five signals. A finding that evaporates under scrutiny costs you credibility with your own auditor, so we test the innocent explanation before anything reaches your report. In one engagement a delegated administration structure looked like the highest-value finding on the page; measured properly, it was an unused shell. It went into the report as a governance question, not an exposure.

Findings alone are half a deliverable. Every item we raise ships with how to fix it and what evidence closes it — because what you are actually buying is the ability to answer your auditor. Iris AI assessment standard

Where we fit

We don’t replace your security tools. We measure whether they cover what you think they cover.

Most of a security budget goes on runtime tools — software that watches for things happening on the devices it is installed on. That is a genuinely different job from establishing what your estate actually consists of, who holds standing access to it, and which control paths reach which devices. Both matter. Only one of them answers an auditor.

The denominator problem. Every tool reports coverage against its own install base. In the assessment above, the organisation’s register listed 71 machines while Defender knew about 8,532 — so every coverage percentage anyone had quoted was measured against the wrong total. A tool cannot tell you what it is missing. That is the question we exist to answer, and it is why we read six planes and compare them against each other rather than trusting any single one.

Where an assurance assessment sits alongside the usual stack
Tool class The question it answers well What it is not built to tell you
Endpoint detection and response SentinelOne, CrowdStrike Falcon, Microsoft Defender for Endpoint, Sophos Is something malicious happening on this device right now, and can I contain it? Coverage is anchored to its own deployment. Add-on network discovery may spot an unmanaged device, but not its join type, its encryption state, who signs into it, or whether it exists in your directory at all.
Cloud posture scoring Microsoft Secure Score, CSPM dashboards How does my tenant compare to the vendor’s own recommended baseline? A vendor-weighted score is not audit evidence. It does not map to the control areas your auditor rates, and it will not tell you which item matters most in your context.
Vulnerability scanning Tenable, Qualys, Rapid7 Which reachable hosts carry known vulnerabilities, and how severe are they? Almost nothing about identity: who owns an application registration, what consent is standing, whether an account can do MFA, or which devices any policy actually reaches.
Directory posture tools PingCastle, Purple Knight, Entra ID Governance Is my directory configured against a known catalogue of weaknesses? Genuinely useful, and the closest neighbour to this work. Strong on one plane. They do not correlate the directory against device management, Defender inventory, mail authentication and licensing — which is exactly where the contradictions surface.
Remote monitoring and management N-able, ConnectWise, Intune alone Are the endpoints I manage patched, healthy and reachable? Built to operate the estate rather than to evidence it, and its inventory is again its own agent’s view of the world.
Point-in-time audit consultancy Did we comply this year, in the opinion of a qualified reviewer? Leaves a report rather than machinery. Next cycle the evidence is rebuilt from scratch, usually by the same overstretched team.

We read across planes, not down one

The findings that change decisions come from disagreement between sources — the register against Defender, the join type against the deployment method, the licence against what is switched on. No single tool holds both sides.

Every finding carries its remedy

A severity score is not an answer. Each item states the fix, the owner, and the artefact that closes it, so the report is a work plan rather than a reading exercise.

It becomes standing evidence

Collection moves onto a schedule with a stated retention period, so next year’s audit is answered from evidence already captured rather than reconstructed under pressure.

So keep what you have. If you already run an endpoint platform, we are not asking you to displace it — our assessments frequently end by telling clients precisely where it was never installed. The two are complementary: yours watches what is happening, ours establishes what is there.

Why now

The control areas your auditor already rates

For South African public-sector institutions this is not a discretionary exercise. The Auditor-General assesses information-technology general controls annually and publishes the ratings. In the PFMA 2024-25 cycle, 191 auditees were scoped, and the Auditor-General recorded an overall decline in the strength of the IT control environment.

AGSA PFMA 2024-25 — IT general controls, 191 auditees scoped
Control area Good Concerning Poor Not good
User access management 60 · 31% 114 · 60% 17 · 9% 69%
Security management 69 · 36% 103 · 54% 19 · 10% 64%
IT service continuity 97 · 51% 82 · 43% 12 · 6% 49%
Overall IT control environment 37 · 20% 137 · 72% 17 · 8% 80%

Source: Auditor-General of South Africa, PFMA 2024-25 consolidated general report, IT general controls chapter (printed p.105). Separately, 70 auditees were assessed for cyber posture: 45 (64%) showed shortcomings and 8 (11%) had significant exploitable weaknesses. The Auditor-General’s most frequent findings were untested backups, no vulnerability-management tooling, weak access controls, unpatched systems, and insufficient logging and monitoring of administrator activity.

Three things follow from that table

User access is the worst-rated area, and it is the one an identity assessment answers directly. Sixty-nine percent of scoped auditees are rated Concerning or Poor on user access management. Every signal we read — ownerless applications, standing consent, MFA registration, privileged role assignment, dormant accounts — is evidence in that exact area.

The obligation is already written down. For national and provincial departments, the Corporate Governance of ICT Policy Framework requires the head of ICT to report on information-security management including user access, ICT availability, service continuity, third-party management, configuration management, and improvement plans arising from information-systems audits — internal and Auditor-General alike. An assessment that maps to those headings is not a new deliverable; it is the one already owed.

The findings repeat because the machinery is missing, not the intent. The Auditor-General names the same root causes every cycle: vacancies, skills shortages, over-reliance on vendors, ageing systems. None of those are solved by another annual report written by hand. They are solved by measurement that runs on a schedule.

How an engagement runs

From access request to standing evidence

The sequence is fixed, because each step depends on the one before it. The first measured readout typically lands in the same week access is approved.

  1. 01

    Day 1

    Access request, in writing

    A single document naming what is being asked for, every read permission requested, the reason for each, and how we handle it. Your administrator approves it as it stands or strikes lines out.

  2. 02

    Day 1–2

    Approval and verification

    Once approved, we run a verification pass proving every permission actually resolves and every interface answers. You get the before-and-after record, including anything that did not work and why.

  3. 03

    Same day

    First collection

    The full catalogue runs read-only across every plane. Raw responses are retained losslessly alongside the parsed rows, so any figure in your report traces back to the exact record it came from.

  4. 04

    Week 1

    Correlation and challenge

    Cross-plane questions run, then every candidate finding is tested against its innocent explanation. What survives goes in the report. What does not is recorded as tested and cleared — which is itself evidence.

  5. 05

    Week 2

    Findings, remediation and evidence

    A versioned, dated report: each finding with its severity, the control area it lands in, the prescribed fix, the owner, and the artefact that will close it. Written to be handed to an auditor without translation.

  6. 06

    Ongoing

    Standing measurement

    Collection moves onto a schedule — perishable data daily, population snapshots weekly, deep walks monthly — with a stated retention period. Next year’s audit is answered from evidence already captured, not reconstructed from memory.

The wider platform

Where the assessment leads

An assessment tells you where you stand. These are the Iris platforms that change it, built on the same principle: measure the estate as it is, on infrastructure you control.

Alchemy

Finds what nobody wrote a rule for

Our machine-intelligence engine for high-volume operational data. Descriptor-driven, interpretable by construction, and able to run fully air-gapped — no cloud, no GPU, no internet. On a benchmark of injected anomalies it recovered 81% at perfect precision: zero false positives.

Gremlin

Runs quietly on every endpoint and server

A signed, lightweight agent reporting device health, patch and encryption posture, administrator membership, listening services and behavioural baselines — per device, per hour of day. Built for estates with poor connectivity, and for the servers a cloud console cannot see.

Kingfisher

Integrated physical security management

Our next-generation platform unifying access control, video, intrusion, fire and communications, with signed tamper-evident evidence export, cause-and-effect automation, and multi-organisation federation built in rather than bolted on.

Common questions

What clients ask before they approve access

What is an identity and cloud assessment?

A read-only measurement of your Microsoft identity estate. We read Microsoft Entra ID, on-premises Active Directory, Microsoft Intune, Microsoft Defender, Microsoft Purview and Exchange Online, compare what we find against a catalogue of 95 signals, and return every gap with a prescribed fix and the evidence that closes it.

How is this different from SentinelOne, CrowdStrike or our existing endpoint tool?

They answer different questions. An endpoint platform detects and contains threats on the devices where its agent is installed. An identity and cloud assessment establishes what your estate actually consists of, who holds standing access to it, and which control paths reach which devices — including the devices no agent ever reached. It is complementary to your endpoint platform, not a replacement for it.

Can the assessment change anything in our tenant?

No. Every permission granted is a read permission, so nothing can be created, modified or deleted, and the assessment cannot widen its own reach. You can withdraw the access in one action, and every request it makes appears in your own audit logs.

Do we need to install an agent?

No. The assessment reads Microsoft’s own interfaces, so there is nothing to deploy to endpoints, no configuration change, and no maintenance window. Our Gremlin agent is a separate product you can adopt afterwards if you want continuous endpoint telemetry.

How long does it take?

The access request goes out on day one and the first collection runs the same day access is approved. Correlation and challenge testing take the first week, and the findings report with remediation and closing evidence lands in week two.

What do we actually receive?

A versioned, dated report listing each finding with its severity, the control area it falls under, the prescribed fix, the owner, and the artefact that will close it. It is written to be handed to an auditor without translation.

How does this help with an Auditor-General audit?

The Auditor-General rates security management, user access management and IT service continuity every year. User access is the worst-rated area nationally, and it is the one an identity assessment answers directly — ownerless applications, standing consent, MFA registration, privileged roles and dormant accounts are all evidence in that control area.

Does it address POPIA?

Yes, in two ways. It surfaces the conditions that create exposure under POPIA — unencrypted devices holding personal information, unmanaged endpoints, accounts without strong authentication — and the evidence itself is stored per client with a data classification and POPIA category on every table, under a stated retention period.

Does it work if our estate is not domain-joined?

Yes, and that is often the finding. Many estates assume Group Policy still reaches their devices when almost none are domain-joined any more. We measure join type and management channel directly, so you learn which control path actually reaches which devices.

What does an identity and cloud assessment cost?

Pricing is scoped to the size of the estate and the planes in scope. We quote after a short scoping call, and the access request document is issued before anything is approved so you can see the full extent of what is being asked for first.

Next step

Start with the readout

The fastest way to test any of this is to let us measure one tenant. You approve a written, read-only access request; we return a findings report with a prescribed fix and a closing artefact against every item. If it tells you nothing you did not already know, you have spent a week and approved nothing you cannot withdraw in one action.

Request an identity and cloud assessment

We send the access request document first, so you can see exactly what is being asked for before anything is approved.