Identity and cloud assurance
Iris AI is a South African AI and big-data company with eight years of turning high-volume operational telemetry into decisions. We read your Entra ID, Active Directory, Intune and Defender estate as it actually is — then hand you the findings, the fix for each one, and the evidence that closes it.
Every organisation can describe its identity estate. Very few can measure it. The gap between the two is where audit findings, breaches and regulatory exposure live — and it is measurable in days, read-only, without touching a single production system.
Identity and cloud assurance is a read-only assessment of an organisation’s Microsoft identity estate — Microsoft Entra ID, on-premises Active Directory, Microsoft Intune, Microsoft Defender, Microsoft Purview and Exchange Online — that measures the estate as it is actually configured rather than as it is documented, and reports every gap with a prescribed fix and the evidence needed to close it. Iris AI delivers it from Johannesburg, South Africa, mapped to the Auditor-General of South Africa’s IT general control areas and to POPIA obligations.
The scale we work at
What one assessment surfaces
These came out of one enterprise tenant, on the first pass, with no agent installed and no ability to change anything. Every figure is drawn from the tenant’s own records.
Coverage
Six planes, read together. Most assessments look at one and infer the rest — which is exactly how a 71-machine register survives next to an 8,532-machine reality.
Every permission granted is a read permission. Nothing in your tenant can be created, changed or removed by the assessment, and it cannot widen its own reach.
Your administrator approves the access; we generate our own sign-in material and register only the public half of it. There is nothing to email, and nothing to leak.
Purpose-built for your assessment rather than shared with other work, so approving it grants reach to nobody else.
Where a permission would put personal information within reach without improving a finding, we hand it back — and our tooling records the omission.
The registration belongs in your own monthly access review. You can withdraw it in one action, and every request it made appears in your logs.
Evidence lands in a per-client store where every table carries a data classification and a POPIA category, with per-load lineage and a stated retention period.
Method
The findings do not come from a product’s default rule set. They come from a standing Iris catalogue built and corrected across real tenant engagements, where every signal carries a permanent identifier, the plane it is read from, what “bad” looks like, and what to do about it. Identifiers are never renumbered, and a claim we later disprove is struck through with a date rather than quietly deleted.
The twelve documented false positives matter as much as the ninety-five signals. A finding that evaporates under scrutiny costs you credibility with your own auditor, so we test the innocent explanation before anything reaches your report. In one engagement a delegated administration structure looked like the highest-value finding on the page; measured properly, it was an unused shell. It went into the report as a governance question, not an exposure.
Findings alone are half a deliverable. Every item we raise ships with how to fix it and what evidence closes it — because what you are actually buying is the ability to answer your auditor. Iris AI assessment standard
Where we fit
Most of a security budget goes on runtime tools — software that watches for things happening on the devices it is installed on. That is a genuinely different job from establishing what your estate actually consists of, who holds standing access to it, and which control paths reach which devices. Both matter. Only one of them answers an auditor.
The denominator problem. Every tool reports coverage against its own install base. In the assessment above, the organisation’s register listed 71 machines while Defender knew about 8,532 — so every coverage percentage anyone had quoted was measured against the wrong total. A tool cannot tell you what it is missing. That is the question we exist to answer, and it is why we read six planes and compare them against each other rather than trusting any single one.
| Tool class | The question it answers well | What it is not built to tell you |
|---|---|---|
| Endpoint detection and response SentinelOne, CrowdStrike Falcon, Microsoft Defender for Endpoint, Sophos | Is something malicious happening on this device right now, and can I contain it? | Coverage is anchored to its own deployment. Add-on network discovery may spot an unmanaged device, but not its join type, its encryption state, who signs into it, or whether it exists in your directory at all. |
| Cloud posture scoring Microsoft Secure Score, CSPM dashboards | How does my tenant compare to the vendor’s own recommended baseline? | A vendor-weighted score is not audit evidence. It does not map to the control areas your auditor rates, and it will not tell you which item matters most in your context. |
| Vulnerability scanning Tenable, Qualys, Rapid7 | Which reachable hosts carry known vulnerabilities, and how severe are they? | Almost nothing about identity: who owns an application registration, what consent is standing, whether an account can do MFA, or which devices any policy actually reaches. |
| Directory posture tools PingCastle, Purple Knight, Entra ID Governance | Is my directory configured against a known catalogue of weaknesses? Genuinely useful, and the closest neighbour to this work. | Strong on one plane. They do not correlate the directory against device management, Defender inventory, mail authentication and licensing — which is exactly where the contradictions surface. |
| Remote monitoring and management N-able, ConnectWise, Intune alone | Are the endpoints I manage patched, healthy and reachable? | Built to operate the estate rather than to evidence it, and its inventory is again its own agent’s view of the world. |
| Point-in-time audit consultancy | Did we comply this year, in the opinion of a qualified reviewer? | Leaves a report rather than machinery. Next cycle the evidence is rebuilt from scratch, usually by the same overstretched team. |
The findings that change decisions come from disagreement between sources — the register against Defender, the join type against the deployment method, the licence against what is switched on. No single tool holds both sides.
A severity score is not an answer. Each item states the fix, the owner, and the artefact that closes it, so the report is a work plan rather than a reading exercise.
Collection moves onto a schedule with a stated retention period, so next year’s audit is answered from evidence already captured rather than reconstructed under pressure.
So keep what you have. If you already run an endpoint platform, we are not asking you to displace it — our assessments frequently end by telling clients precisely where it was never installed. The two are complementary: yours watches what is happening, ours establishes what is there.
Why now
For South African public-sector institutions this is not a discretionary exercise. The Auditor-General assesses information-technology general controls annually and publishes the ratings. In the PFMA 2024-25 cycle, 191 auditees were scoped, and the Auditor-General recorded an overall decline in the strength of the IT control environment.
| Control area | Good | Concerning | Poor | Not good |
|---|---|---|---|---|
| User access management | 60 · 31% | 114 · 60% | 17 · 9% | 69% |
| Security management | 69 · 36% | 103 · 54% | 19 · 10% | 64% |
| IT service continuity | 97 · 51% | 82 · 43% | 12 · 6% | 49% |
| Overall IT control environment | 37 · 20% | 137 · 72% | 17 · 8% | 80% |
Source: Auditor-General of South Africa, PFMA 2024-25 consolidated general report, IT general controls chapter (printed p.105). Separately, 70 auditees were assessed for cyber posture: 45 (64%) showed shortcomings and 8 (11%) had significant exploitable weaknesses. The Auditor-General’s most frequent findings were untested backups, no vulnerability-management tooling, weak access controls, unpatched systems, and insufficient logging and monitoring of administrator activity.
User access is the worst-rated area, and it is the one an identity assessment answers directly. Sixty-nine percent of scoped auditees are rated Concerning or Poor on user access management. Every signal we read — ownerless applications, standing consent, MFA registration, privileged role assignment, dormant accounts — is evidence in that exact area.
The obligation is already written down. For national and provincial departments, the Corporate Governance of ICT Policy Framework requires the head of ICT to report on information-security management including user access, ICT availability, service continuity, third-party management, configuration management, and improvement plans arising from information-systems audits — internal and Auditor-General alike. An assessment that maps to those headings is not a new deliverable; it is the one already owed.
The findings repeat because the machinery is missing, not the intent. The Auditor-General names the same root causes every cycle: vacancies, skills shortages, over-reliance on vendors, ageing systems. None of those are solved by another annual report written by hand. They are solved by measurement that runs on a schedule.
How an engagement runs
The sequence is fixed, because each step depends on the one before it. The first measured readout typically lands in the same week access is approved.
Day 1
A single document naming what is being asked for, every read permission requested, the reason for each, and how we handle it. Your administrator approves it as it stands or strikes lines out.
Day 1–2
Once approved, we run a verification pass proving every permission actually resolves and every interface answers. You get the before-and-after record, including anything that did not work and why.
Same day
The full catalogue runs read-only across every plane. Raw responses are retained losslessly alongside the parsed rows, so any figure in your report traces back to the exact record it came from.
Week 1
Cross-plane questions run, then every candidate finding is tested against its innocent explanation. What survives goes in the report. What does not is recorded as tested and cleared — which is itself evidence.
Week 2
A versioned, dated report: each finding with its severity, the control area it lands in, the prescribed fix, the owner, and the artefact that will close it. Written to be handed to an auditor without translation.
Ongoing
Collection moves onto a schedule — perishable data daily, population snapshots weekly, deep walks monthly — with a stated retention period. Next year’s audit is answered from evidence already captured, not reconstructed from memory.
The wider platform
An assessment tells you where you stand. These are the Iris platforms that change it, built on the same principle: measure the estate as it is, on infrastructure you control.
Our machine-intelligence engine for high-volume operational data. Descriptor-driven, interpretable by construction, and able to run fully air-gapped — no cloud, no GPU, no internet. On a benchmark of injected anomalies it recovered 81% at perfect precision: zero false positives.
A signed, lightweight agent reporting device health, patch and encryption posture, administrator membership, listening services and behavioural baselines — per device, per hour of day. Built for estates with poor connectivity, and for the servers a cloud console cannot see.
Our next-generation platform unifying access control, video, intrusion, fire and communications, with signed tamper-evident evidence export, cause-and-effect automation, and multi-organisation federation built in rather than bolted on.
Common questions
A read-only measurement of your Microsoft identity estate. We read Microsoft Entra ID, on-premises Active Directory, Microsoft Intune, Microsoft Defender, Microsoft Purview and Exchange Online, compare what we find against a catalogue of 95 signals, and return every gap with a prescribed fix and the evidence that closes it.
They answer different questions. An endpoint platform detects and contains threats on the devices where its agent is installed. An identity and cloud assessment establishes what your estate actually consists of, who holds standing access to it, and which control paths reach which devices — including the devices no agent ever reached. It is complementary to your endpoint platform, not a replacement for it.
No. Every permission granted is a read permission, so nothing can be created, modified or deleted, and the assessment cannot widen its own reach. You can withdraw the access in one action, and every request it makes appears in your own audit logs.
No. The assessment reads Microsoft’s own interfaces, so there is nothing to deploy to endpoints, no configuration change, and no maintenance window. Our Gremlin agent is a separate product you can adopt afterwards if you want continuous endpoint telemetry.
The access request goes out on day one and the first collection runs the same day access is approved. Correlation and challenge testing take the first week, and the findings report with remediation and closing evidence lands in week two.
A versioned, dated report listing each finding with its severity, the control area it falls under, the prescribed fix, the owner, and the artefact that will close it. It is written to be handed to an auditor without translation.
The Auditor-General rates security management, user access management and IT service continuity every year. User access is the worst-rated area nationally, and it is the one an identity assessment answers directly — ownerless applications, standing consent, MFA registration, privileged roles and dormant accounts are all evidence in that control area.
Yes, in two ways. It surfaces the conditions that create exposure under POPIA — unencrypted devices holding personal information, unmanaged endpoints, accounts without strong authentication — and the evidence itself is stored per client with a data classification and POPIA category on every table, under a stated retention period.
Yes, and that is often the finding. Many estates assume Group Policy still reaches their devices when almost none are domain-joined any more. We measure join type and management channel directly, so you learn which control path actually reaches which devices.
Pricing is scoped to the size of the estate and the planes in scope. We quote after a short scoping call, and the access request document is issued before anything is approved so you can see the full extent of what is being asked for first.
Next step
The fastest way to test any of this is to let us measure one tenant. You approve a written, read-only access request; we return a findings report with a prescribed fix and a closing artefact against every item. If it tells you nothing you did not already know, you have spent a week and approved nothing you cannot withdraw in one action.
We send the access request document first, so you can see exactly what is being asked for before anything is approved.