Tenant Monitor.
What you pay for, and what you never approved.
The free scan shows the estate today. Tenant Monitor keeps checking it every month and tells you what moved.
Licences nobody uses, priced against the wholesale rate card. The AI tools and third-party apps your staff connected with one OAuth click. The renewals that auto-charge while nobody is looking. Security posture travels with all of it, because the same read produces it, but the money and the unapproved apps are the reason to run this. Read-only, with evidence artifacts every month.
What you can check
- 35AI vendors in the detection catalogue
Tenant Monitor looks for 35 named AI vendors when it reads your estate, alongside every third-party OAuth app it finds.
Counted from AI_VENDOR_PROFILES, the shipped detection catalogue, and stated exactly rather than rounded. It is the size of what the product looks FOR, not a count of what your tenant runs. The free scan returns that.
Run the free scan on your own estate
Tenant Monitor reads your tenant and writes nothing to it.
Read-only access, with the scope set published in full, so the absence of a write permission is something you can check rather than something we assert. There is no agent to install.
See the exact read-only scopes we requestCharged from day one, with a 30-day money-back guarantee on your first payment.
Ask within 30 days of the first payment and it is refunded in full, no reason required, with the subscription cancelled from the date of the request. After that, cancellation from the billing portal takes effect at the end of the current billing period and past months are not pro-rated. The guarantee is written into the Refund Policy, so it is a term rather than a promise on a marketing page.
Refund Policy, section 05Renewal notices go out 90, 30 and 7 days before each auto-renewal date the scan finds. That is how the product is configured, not a term anything holds us to.
Your report is emailed on the 1st of each month, and again as soon as your first scan finishes rather than at the next month boundary. That is how the product is configured, not a term anything holds us to, and no report has been dispatched in production yet.
Ranked by how you can check it. Only a measured figure is set as one.
What a quarter of no monitoring costs.
Between departures, the estate keeps moving. Spend, access and posture drift on their own, and without a watch the first sign is usually the bill or the breach.
Auto-renewals that charge before anyone reviews them
A yearly contract renews on its own date. The first anyone hears of it is the invoice, and by then the cancel window has closed.
AI vendors reading company data nobody approved
Staff connect AI tools to mail, files and calendars with a single OAuth click. No policy signed off on it, and nobody is watching what they can read.
Licences billing for people who left last quarter
Dead and duplicate seats keep drawing from the invoice. Nobody reclaimed them, because nobody was reading the licence report.
What the watch does every month.
Tenant Monitor re-scans on your cadence and only speaks up when it matters. Flat rate, unlimited estate.
Drift alerts, only on real regressions
Email when posture actually slips, for example an admin drops MFA or Secure Score falls. Routine changes stay quiet.
Renewal radar with a 90 / 30 / 7-day heads-up
Upcoming auto-renewals ranked by at-risk spend, so nothing renews unseen and unquestioned.
Recoverable licence and spend, priced for real
Dead, inactive and duplicate licences priced against the synced Pax8 wholesale rate card. The rate is real; what you recover depends on your own seat data.
Evidence artifacts you can export
The EU AI Act inventory register (CSV), a remediation runbook (PS1 + MD) and a white-label PDF, generated from your scan.
A monthly SaaS Command report
A CFO-ready report emailed on the 1st, and again the moment your first scan finishes, with the headline figure, the risks and what changed.
See exactly what the Auditor delivers
One free scan puts all of this in front of you. Tenant Monitor keeps it live in your dashboard and inbox. Every shot below is a real, shipped surface.
From one free scan
The estate, laid bare
Connect Microsoft 365 or Google read-only, or drop a CSV. In minutes you see the shadow AI your team connected, your live security posture, and exactly what your licensing should cost.
Every OAuth grant your staff approved, scored by permission risk. Export the revoke list for IT.
68%
MFA-capable
2
Admins no MFA
143
Users assessed
€18,400
Now
€2,140/mo
Optimized
€1,690/mo
Your estate priced against real Pax8 wholesale, not an estimate. The number nobody else gives you free.
What Tenant Monitor adds
A living service, not a one-off
Tenant Monitor re-scans on your cadence and only speaks up when posture drifts or a renewal approaches. The report becomes a card in your dashboard, an alert in your inbox, and a monthly PDF for finance.
Your estate is being watched
Cadence
Monthly
Last scan
1 Jun 2026
Next scan
1 Jul 2026
Secure Score
48%
2 admins without MFA at last scan.
ITSailor monitoring: 1 more admin without MFA
Posture change detected
2 changes since your last scan
Estate Intelligence
SaaS Command Report
Recoverable, annualised
€18,400/yr
47 apps · 3 lenses · 6 risks
Prepared for your CFO
ITSailorThe artifacts you export
The dashboard is the living view. These are the documents you hand to a CFO, an auditor, or - if you run an MSP - your own client. Each one is generated from your real scan.
AI governance
EU AI Act inventory register
Every AI tool in the estate, classified and owned - the register an assessor asks for first.
- Governance priority per tool: act-now, review or monitor
- Data posture, owner, DPA status and the gaps to close
- Evidence for the EU AI Act, NIST AI RMF and ISO 42001
- High-risk tier depends on your use - confirmed per tool, never claimed
Executable
Remediation runbook
The findings become a script you run in your own tenant - not a to-do list you retype.
- Idempotent PowerShell, preview by default
- Add -Apply to execute the bulk steps
- Right-size licenses and revoke risky OAuth grants
- A readable .md runbook ships alongside for review
For MSPs
White-label client report
The monthly posture report an operator mails a client - under their own brand, without building a deck.
- Posture, recoverable spend and what changed this month
- Your logo and brand colour, not ours
- One report per tenant across the Fleet
- Recommended actions the client can act on
Deep on the tenant, not the whole stack.
Microsoft 365 is the continuous, read-only core. Everything else is honestly a lighter touch.
Continuous, read-only. Licences, spend, Shadow IT and AI, and live posture, re-scanned on your cadence.
A one-off snapshot scan over read-only Google OAuth. The continuous watch stays on Microsoft 365.
CSV exports from tools like Slack, Zoom and Atlassian run entirely in your browser and fold into the same estate view, deduped. No agent to install.
Evidence for the frameworks your auditor opens.
Every scan maps live Microsoft 365 signals to the control objectives behind DORA, NIS2 and ISO 27001, and exports the register an assessor asks for. It also answers the MFA coverage questions a cyber-insurance renewal form actually asks, surface by surface. Evidence for those objectives, never a certification ITSailor holds.
ICT risk and third-party monitoring signals (Articles 6 and 28), read from live Microsoft 365 posture.
Risk-management and access-control measures (Article 21), evidenced by continuous posture and licence monitoring.
Annex A access-control and supplier objectives, addressed with a monthly control-objective gap map.
Monitoring, sold as a product.
The free scan is a snapshot. Tenant Monitor keeps the estate monitored: recurring scans, drift alerts, a renewal radar and a monthly report, flat rate, unlimited estate. Microsoft 365 posture and spend, re-checked every month.
Scheduled re-scan
We re-scan your Microsoft 365 tenant weekly or monthly, hands-off, and keep every result.
Drift alerts
Email only when posture actually regresses, for example an admin loses MFA, not on routine changes.
Renewal radar
A 90 / 30 / 7-day heads-up before each auto-renewal, so nothing renews unseen.
Monthly report
A fresh CFO-ready SaaS Command report each month, plus the exportable artifacts.
Tenant Monitor
30-day money-back guarantee.
€119/mo billed annually
EUR 1428/yr
Prices excl. VAT. VAT is calculated at checkout.
Keeps the whole Microsoft 365 estate watched: licence waste, Shadow IT and AI, and posture drift, month after month.
Shows what a single departure left open and evidences what closed, in one pack per leaver. Same tenant connection pattern, same read-only posture, separate scans and separate evidence.
Two products, one read-only posture. See Offboarding EvidenceRun both, one invoice.
One subscription that provisions Tenant Monitor and Offboarding Evidence together: evidence-grade offboarding and continuous Microsoft 365 monitoring, on one dashboard.
Same price as both annual plans, billed as one invoice for one onboarding.
€318/mo billed annually
EUR 3816/yr
30-day money-back guarantee. Prices excl. VAT, calculated at checkout.
Start both modulesToday it watches and reports in full. Actions are next.
Tenant Monitor already does its whole job: continuous read-only monitoring, drift and renewal alerts, and a monthly report, live today. The Act tier is next, adding human-approved licence and posture actions gated behind a named person, so a finding can become a fix without leaving the tool. It changes nothing in your tenant on its own until you turn it on.
What IT and finance leads ask first.
What does Tenant Monitor actually monitor?
Your Microsoft 365 estate, continuously: licence and spend waste, Shadow IT and Shadow AI (third-party OAuth apps and 35 named AI vendors), live security posture (MFA coverage, Conditional Access, admins without MFA, Secure Score), and renewals. It re-scans on your cadence, alerts you by email when posture drifts, and emails a CFO-ready report each month, starting the moment your first scan finishes rather than at the next month boundary.
What access does it need, and can it change anything?
Read-only. Connect via read-only Microsoft Graph or Google OAuth, or drop a CSV that runs entirely in your browser. First scan takes minutes, with no agent to install. Tenant Monitor reads and reports; it never writes to your tenant. Every scope we request is listed at /trust/scopes.
Where is the scan data stored, and can I delete it?
Scan data is stored encrypted in the EU (Hetzner, Falkenstein). Tenant Monitor holds read-only access to your tenant, revocable in one step, and nothing on our side is load-bearing. Your history is destroyed on request. See the Trust Center for data handling and sub-processors.
Does Tenant Monitor replace Vanta or Drata?
No, and it does not try to be. Vanta and Drata are compliance-automation platforms that carry you through a SOC 2 or ISO 27001 audit across your whole stack. Tenant Monitor does one focused job: continuous Microsoft 365 posture and licence monitoring, with one-off Google Workspace snapshot scans and a control-objective gap map. Different jobs, different price brackets. See the honest scope comparison.
Is this evidence for DORA, NIS2 and ISO 27001?
It maps live Microsoft 365 signals to DORA, NIS2 and ISO 27001 control families, and exports the register an assessor asks for. It also answers the MFA coverage questions a cyber-insurance renewal form actually asks. That is evidence for those objectives, not a certification. ITSailor states control coverage conservatively and never claims a certification it does not hold.
What non-Microsoft systems can it read?
Microsoft 365 is the continuous, read-only core. Google Workspace runs as a one-off snapshot scan. Beyond that, CSV exports from tools like Slack, Zoom and Atlassian run entirely in your browser and fold into the same estate view, deduped. Microsoft 365 gets the full continuous depth; the rest is a lighter-touch view by design.
What does it cost, is there a trial, and how does VAT work?
€149/month, or €119/month billed annually, flat rate for the whole estate. There is no trial: you are charged from day one and covered by a 30-day money-back guarantee, and you can cancel anytime. Prices are excl. VAT; VAT is calculated at checkout, and eligible EU B2B buyers outside Malta reverse-charge.
Can I see the output before I buy?
Yes. Run the free SaaS Auditor scan on the tool page and you get the full report, the AI Command Brief and the CFO-ready PDF, with no signup and no card. See all sample artifacts.
Know what connected to the tenant this month.
New OAuth grants, new AI tools and dormant licences appear between audits. The watch reads them monthly and writes the register you would otherwise assemble by hand.
The CSV the watch exports, produced by the same code path from fixed sample data. It downloads on click.