Skip to content
Product · SaaS and Microsoft 365 monitoring· Both modules

Tenant Monitor.
What you pay for, and what you never approved.

The free scan shows the estate today. Tenant Monitor keeps checking it every month and tells you what moved.

Licences nobody uses, priced against the wholesale rate card. The AI tools and third-party apps your staff connected with one OAuth click. The renewals that auto-charge while nobody is looking. Security posture travels with all of it, because the same read produces it, but the money and the unapproved apps are the reason to run this. Read-only, with evidence artifacts every month.

Read-only, no agent to install Evidence artifacts every month 30-day money-back guarantee

What you can check

35AI vendors in the detection catalogue

Tenant Monitor looks for 35 named AI vendors when it reads your estate, alongside every third-party OAuth app it finds.

Counted from AI_VENDOR_PROFILES, the shipped detection catalogue, and stated exactly rather than rounded. It is the size of what the product looks FOR, not a count of what your tenant runs. The free scan returns that.

Run the free scan on your own estate
  • Tenant Monitor reads your tenant and writes nothing to it.

    Read-only access, with the scope set published in full, so the absence of a write permission is something you can check rather than something we assert. There is no agent to install.

    See the exact read-only scopes we request
  • Charged from day one, with a 30-day money-back guarantee on your first payment.

    Ask within 30 days of the first payment and it is refunded in full, no reason required, with the subscription cancelled from the date of the request. After that, cancellation from the billing portal takes effect at the end of the current billing period and past months are not pro-rated. The guarantee is written into the Refund Policy, so it is a term rather than a promise on a marketing page.

    Refund Policy, section 05
  • Renewal notices go out 90, 30 and 7 days before each auto-renewal date the scan finds. That is how the product is configured, not a term anything holds us to.

  • Your report is emailed on the 1st of each month, and again as soon as your first scan finishes rather than at the next month boundary. That is how the product is configured, not a term anything holds us to, and no report has been dispatched in production yet.

Ranked by how you can check it. Only a measured figure is set as one.

The drift

What a quarter of no monitoring costs.

Between departures, the estate keeps moving. Spend, access and posture drift on their own, and without a watch the first sign is usually the bill or the breach.

Auto-renewals that charge before anyone reviews them

A yearly contract renews on its own date. The first anyone hears of it is the invoice, and by then the cancel window has closed.

AI vendors reading company data nobody approved

Staff connect AI tools to mail, files and calendars with a single OAuth click. No policy signed off on it, and nobody is watching what they can read.

Licences billing for people who left last quarter

Dead and duplicate seats keep drawing from the invoice. Nobody reclaimed them, because nobody was reading the licence report.

What monitoring does monthly

What the watch does every month.

Tenant Monitor re-scans on your cadence and only speaks up when it matters. Flat rate, unlimited estate.

  • Drift alerts, only on real regressions

    Email when posture actually slips, for example an admin drops MFA or Secure Score falls. Routine changes stay quiet.

  • Renewal radar with a 90 / 30 / 7-day heads-up

    Upcoming auto-renewals ranked by at-risk spend, so nothing renews unseen and unquestioned.

  • Recoverable licence and spend, priced for real

    Dead, inactive and duplicate licences priced against the synced Pax8 wholesale rate card. The rate is real; what you recover depends on your own seat data.

  • Evidence artifacts you can export

    The EU AI Act inventory register (CSV), a remediation runbook (PS1 + MD) and a white-label PDF, generated from your scan.

  • A monthly SaaS Command report

    A CFO-ready report emailed on the 1st, and again the moment your first scan finishes, with the headline figure, the risks and what changed.

What you get

See exactly what the Auditor delivers

One free scan puts all of this in front of you. Tenant Monitor keeps it live in your dashboard and inbox. Every shot below is a real, shipped surface.

From one free scan

The estate, laid bare

Connect Microsoft 365 or Google read-only, or drop a CSV. In minutes you see the shadow AI your team connected, your live security posture, and exactly what your licensing should cost.

Shadow IT + Shadow AI
14 third-party apps6 AI
ChatGPTAIhighrevoke
GrammarlyAImedium
Zoomlow

Every OAuth grant your staff approved, scored by permission risk. Export the revoke list for IT.

Shadow AI, surfaced
Security posture · live Microsoft 365
48%
Secure Score

68%

MFA-capable

2

Admins no MFA

143

Users assessed

critical2 admin accounts can sign in without MFA.
Live security posture
Exact CSP pricing · Pax8
Recoverable / yr live wholesale

€18,400

Now

€2,140/mo

Optimized

€1,690/mo

Your estate priced against real Pax8 wholesale, not an estimate. The number nobody else gives you free.

Exact CSP pricing

What Tenant Monitor adds

A living service, not a one-off

Tenant Monitor re-scans on your cadence and only speaks up when posture drifts or a renewal approaches. The report becomes a card in your dashboard, an alert in your inbox, and a monthly PDF for finance.

Your dashboard
Tenant Monitor Active

Your estate is being watched

Cadence

Monthly

Last scan

1 Jun 2026

Next scan

1 Jul 2026

Secure Score

48%

2 admins without MFA at last scan.

A live posture card
ITSailor · Tenant Monitornow

ITSailor monitoring: 1 more admin without MFA

ITSailorMonitoring

Posture change detected

2 changes since your last scan

critical1 more admin without MFA
mediumSecure Score dropped 48% to 41%
2
Admins no MFA
41%
Secure Score
€420
Monthly waste
Alerts only on drift
PDF

Estate Intelligence

SaaS Command Report

72

Recoverable, annualised

€18,400/yr

47 apps · 3 lenses · 6 risks

Prepared for your CFO

ITSailor
Monthly CFO report
Also includedRenewal heads-ups at 90 / 30 / 7 daysSlack or Microsoft Teams drift alertsSaved contract registerDORA / NIS2 / ISO 27001 gap mapAI Command Brief (Claude)Copilot readiness check
Beyond the dashboard

The artifacts you export

The dashboard is the living view. These are the documents you hand to a CFO, an auditor, or - if you run an MSP - your own client. Each one is generated from your real scan.

AI governance

EU AI Act inventory register

Every AI tool in the estate, classified and owned - the register an assessor asks for first.

CSV
  • Governance priority per tool: act-now, review or monitor
  • Data posture, owner, DPA status and the gaps to close
  • Evidence for the EU AI Act, NIST AI RMF and ISO 42001
  • High-risk tier depends on your use - confirmed per tool, never claimed
Download a real sample

Executable

Remediation runbook

The findings become a script you run in your own tenant - not a to-do list you retype.

PS1 + MD
  • Idempotent PowerShell, preview by default
  • Add -Apply to execute the bulk steps
  • Right-size licenses and revoke risky OAuth grants
  • A readable .md runbook ships alongside for review

For MSPs

White-label client report

The monthly posture report an operator mails a client - under their own brand, without building a deck.

PDF
  • Posture, recoverable spend and what changed this month
  • Your logo and brand colour, not ours
  • One report per tenant across the Fleet
  • Recommended actions the client can act on
What it reads

Deep on the tenant, not the whole stack.

Microsoft 365 is the continuous, read-only core. Everything else is honestly a lighter touch.

Microsoft 365 Continuous

Continuous, read-only. Licences, spend, Shadow IT and AI, and live posture, re-scanned on your cadence.

Google WorkspaceOne-off snapshot

A one-off snapshot scan over read-only Google OAuth. The continuous watch stays on Microsoft 365.

CSV importsIn your browser

CSV exports from tools like Slack, Zoom and Atlassian run entirely in your browser and fold into the same estate view, deduped. No agent to install.

EU regulatory alignment

Evidence for the frameworks your auditor opens.

Every scan maps live Microsoft 365 signals to the control objectives behind DORA, NIS2 and ISO 27001, and exports the register an assessor asks for. It also answers the MFA coverage questions a cyber-insurance renewal form actually asks, surface by surface. Evidence for those objectives, never a certification ITSailor holds.

DORA

ICT risk and third-party monitoring signals (Articles 6 and 28), read from live Microsoft 365 posture.

NIS2

Risk-management and access-control measures (Article 21), evidenced by continuous posture and licence monitoring.

ISO 27001

Annex A access-control and supplier objectives, addressed with a monthly control-objective gap map.

Tenant Monitor

Monitoring, sold as a product.

The free scan is a snapshot. Tenant Monitor keeps the estate monitored: recurring scans, drift alerts, a renewal radar and a monthly report, flat rate, unlimited estate. Microsoft 365 posture and spend, re-checked every month.

Scheduled re-scan

We re-scan your Microsoft 365 tenant weekly or monthly, hands-off, and keep every result.

Drift alerts

Email only when posture actually regresses, for example an admin loses MFA, not on routine changes.

Renewal radar

A 90 / 30 / 7-day heads-up before each auto-renewal, so nothing renews unseen.

Monthly report

A fresh CFO-ready SaaS Command report each month, plus the exportable artifacts.

Tenant Monitor

30-day money-back guarantee.

€119/mo billed annually

EUR 1428/yr

Prices excl. VAT. VAT is calculated at checkout.

Start Tenant MonitorPrefer a scoped assessment call?
Both modules
Combined subscription

Run both, one invoice.

One subscription that provisions Tenant Monitor and Offboarding Evidence together: evidence-grade offboarding and continuous Microsoft 365 monitoring, on one dashboard.

Same price as both annual plans, billed as one invoice for one onboarding.

€318/mo billed annually

EUR 3816/yr

30-day money-back guarantee. Prices excl. VAT, calculated at checkout.

Start both modules
In buildRoadmap · Act tier

Today it watches and reports in full. Actions are next.

Tenant Monitor already does its whole job: continuous read-only monitoring, drift and renewal alerts, and a monthly report, live today. The Act tier is next, adding human-approved licence and posture actions gated behind a named person, so a finding can become a fix without leaving the tool. It changes nothing in your tenant on its own until you turn it on.

Buyer questions

What IT and finance leads ask first.

What does Tenant Monitor actually monitor?

Your Microsoft 365 estate, continuously: licence and spend waste, Shadow IT and Shadow AI (third-party OAuth apps and 35 named AI vendors), live security posture (MFA coverage, Conditional Access, admins without MFA, Secure Score), and renewals. It re-scans on your cadence, alerts you by email when posture drifts, and emails a CFO-ready report each month, starting the moment your first scan finishes rather than at the next month boundary.

What access does it need, and can it change anything?

Read-only. Connect via read-only Microsoft Graph or Google OAuth, or drop a CSV that runs entirely in your browser. First scan takes minutes, with no agent to install. Tenant Monitor reads and reports; it never writes to your tenant. Every scope we request is listed at /trust/scopes.

Where is the scan data stored, and can I delete it?

Scan data is stored encrypted in the EU (Hetzner, Falkenstein). Tenant Monitor holds read-only access to your tenant, revocable in one step, and nothing on our side is load-bearing. Your history is destroyed on request. See the Trust Center for data handling and sub-processors.

Does Tenant Monitor replace Vanta or Drata?

No, and it does not try to be. Vanta and Drata are compliance-automation platforms that carry you through a SOC 2 or ISO 27001 audit across your whole stack. Tenant Monitor does one focused job: continuous Microsoft 365 posture and licence monitoring, with one-off Google Workspace snapshot scans and a control-objective gap map. Different jobs, different price brackets. See the honest scope comparison.

Is this evidence for DORA, NIS2 and ISO 27001?

It maps live Microsoft 365 signals to DORA, NIS2 and ISO 27001 control families, and exports the register an assessor asks for. It also answers the MFA coverage questions a cyber-insurance renewal form actually asks. That is evidence for those objectives, not a certification. ITSailor states control coverage conservatively and never claims a certification it does not hold.

What non-Microsoft systems can it read?

Microsoft 365 is the continuous, read-only core. Google Workspace runs as a one-off snapshot scan. Beyond that, CSV exports from tools like Slack, Zoom and Atlassian run entirely in your browser and fold into the same estate view, deduped. Microsoft 365 gets the full continuous depth; the rest is a lighter-touch view by design.

What does it cost, is there a trial, and how does VAT work?

€149/month, or €119/month billed annually, flat rate for the whole estate. There is no trial: you are charged from day one and covered by a 30-day money-back guarantee, and you can cancel anytime. Prices are excl. VAT; VAT is calculated at checkout, and eligible EU B2B buyers outside Malta reverse-charge.

Can I see the output before I buy?

Yes. Run the free SaaS Auditor scan on the tool page and you get the full report, the AI Command Brief and the CFO-ready PDF, with no signup and no card. See all sample artifacts.

Tenant Monitor

Know what connected to the tenant this month.

New OAuth grants, new AI tools and dormant licences appear between audits. The watch reads them monthly and writes the register you would otherwise assemble by hand.

Download a real sample register

The CSV the watch exports, produced by the same code path from fixed sample data. It downloads on click.