Tenant ops, license rationalization, governance baselines.
Services that leave evidence behind.
Fixed-scope engineering for Microsoft 365, Azure, security, automation and AI operations. You leave with policies, runbooks, evidence packs and an Exit Kit your next vendor can use.
Catalog state
Every service has a handover trail.
Published tracks plus gated services with a visible status.
Outcomes, capability layers or delivery phases in the data model.
Every entry routes to a scope page with artefacts, exclusions and handover notes.
Gated services state their build status instead of pretending to be ready.
Services with outcomes, capability layers or delivery phases in the catalog.
Founder proof inventory mapped into the service model.
Service operating table
Pick by artefact, not by brochure category.
The index exposes what each service produces before you open a detail page. Use the table when you know the operational problem. Use the workshop when the scope spans more than one track.
Workspace Operations
Microsoft 365, Google Workspace, CSP billing, device baselines and tenant operations.
ITS-M365, access reviews, owner ledger
Workspace administration, CAA, Vault retention, license audit.
Microsoft CSP, Google reseller, AWS Marketplace, SaaS resale.
Device procurement, Autopilot, Intune/Jamf, automated lifecycle.
Tenant moves, mailbox cutovers, workload migrations.
Host pools, FSLogix profiles, autoscaling done right.
Security & Infrastructure
Azure landing zones, Defender, Sentinel, backup design and resilience evidence.
DORA, NIS2, source-linked controls, recovery drills
Azure CAF landing zones, IaC, governance baselines.
GCP landing zones, Terraform, VPC SC, org policies.
XDR rollout, detection tuning, compliance evidence.
Sentinel SIEM with controlled cost and MITRE-mapped detections.
Tested DR with documented RPO and RTO targets.
Audit, remediate and govern cloud + SaaS spend.
CIS M365 baseline, Conditional Access, admin hardening and handover.
AI Operating Layer
n8n, Power Automate, HOIST, DECKLOG and production AI integration work.
Prompt repos, trace logs, workflow runbooks
Bespoke LLM features inside your existing apps.
Custom workflow building in n8n, Power Automate, Make and Zapier.
| Service | Best fit | Artefacts | Delivery signal | Action |
|---|---|---|---|---|
Own the tenant stateIdentity, licences, endpoints Workspace OperationsMicrosoft 365, Google Workspace, CSP billing, device baselines and tenant operations. 5 workspace tracks 5/6 open now Evidence ITS-M365, access reviews, owner ledger | ||||
Tenant ops, license rationalization, governance baselines. | Posture report with prioritized remediation backlog. Hardened tenant configuration aligned to CIS Level 1 + Level 2 controls. Scope bounded | Framework: CIS M365 v7.0.0 <5 days Time from kick-off to hardened tenant baseline | View scope | |
Workspace administration, CAA, Vault retention, license audit. | Posture report with CIS-aligned remediation backlog. CAA policies deployed for admin consoles + high-risk apps. Scope bounded | Framework: CIS Google Workspace v1.x <5 days Time from kick-off to hardened Workspace baseline | View scope | |
Microsoft CSP, Google reseller, AWS Marketplace, SaaS resale. | Consolidated licensing under our partner agreements. Monthly cost report attributed to business owners. Scope bounded | Time to Value: Next billing cycle €0 Setup fee - margin is built into vendor list price | View scope | |
Device procurement, Autopilot, Intune/Jamf, automated lifecycle. | Zero-touch enrollment working end-to-end (procurement → user-ready in under 24 hours). MDM baseline aligned to CIS endpoint benchmark for your OS mix. Scope bounded | Time to User: Under 24 hours from order <24h Order to user-ready device, fully managed | View status | |
Tenant moves, mailbox cutovers, workload migrations. | Migration plan with waves, timelines, rollback criteria. Successful pilot + full production cutover. Scope bounded | Typical Duration: 2-24 weeks by tier 0 Big-bang cutovers - every migration runs in waves | View scope | |
Host pools, FSLogix profiles, autoscaling done right. | Working AVD host pools with documented image lifecycle. Autoscaling policy with measured cost-vs-concurrency report. Scope bounded | <5 sec FSLogix profile load time at session start <5 sec FSLogix profile load time at session start | View scope | |
Prove the controlsCloud, SIEM, continuity Security & InfrastructureAzure landing zones, Defender, Sentinel, backup design and resilience evidence. 7 resilience tracks 7/7 open now Evidence DORA, NIS2, source-linked controls, recovery drills | ||||
Azure CAF landing zones, IaC, governance baselines. | Landing zone deployed and documented (typically 3-7 management groups + 5-15 subscriptions). IaC repository with examples, contribution guide and CI/CD pipeline. Scope bounded | Framework: Azure CAF + CIS Azure Foundations 4-8 weeks Time from kick-off to a documented starter landing zone | View scope | |
GCP landing zones, Terraform, VPC SC, org policies. | GCP organization deployed and documented (folders + projects + billing). Terraform repository with CFT-aligned modules and CI/CD pipeline. Scope bounded | Framework: GCP Security Foundations + CFT 4-8 weeks Time from kick-off to a documented starter organization | View scope | |
XDR rollout, detection tuning, compliance evidence. | Defender deployment baseline with tracked exceptions. Tuned analytics ruleset with documented signal-to-noise targets per detection. Scope bounded | Compliance: DORA / NIS2 / ISO 27001 mapping <5 / day Target false-positive volume after baseline tuning (from 100+ / day) | View scope | |
Sentinel SIEM with controlled cost and MITRE-mapped detections. | Sentinel workspace tuned to budget and threat model. Documented connector portfolio with cost per connector. Scope bounded | Framework: MITRE ATT&CK + custom detections 50+ Analytics rules deployed with MITRE ATT&CK mapping | View scope | |
Tested DR with documented RPO and RTO targets. | BIA + tiered RPO/RTO targets per workload. Backup architecture deployed and verified. Scope bounded | BIA Framework: ISO 22301 + DORA Article 11 3 workloads Mission-critical restorations proven end-to-end | View scope | |
Audit, remediate and govern cloud + SaaS spend. | Spend audit with prioritized backlog and realised-saving estimates sized against your own spend baseline. Tagging + cost-attribution model in operation. Scope bounded | Time to Value: 4 weeks for baseline + backlog ~30% Independent estimate of cloud spend wasted industry-wide (Flexera 2026) | View scope | |
CIS M365 baseline, Conditional Access, admin hardening and handover. | Tenant posture report with prioritized remediation backlog. Applied CIS-aligned baseline with change log and rollback notes. Scope bounded | Framework: CIS Microsoft 365 Foundations v7.0.0 5 days Typical time to baseline report | View scope | |
Ship with evalsAgents, workflows, private RAG AI Operating Layern8n, Power Automate, HOIST, DECKLOG and production AI integration work. 5 AI and workflow tracks 2/2 open now Evidence Prompt repos, trace logs, workflow runbooks | ||||
Bespoke LLM features inside your existing apps. | Working AI feature inside your application. Prompt + eval library committed to your repo with version control. Scope bounded | Eval Framework: Promptfoo / Inspect / custom Config-change Provider switch - never a rewrite, portability by default | View scope | |
Custom workflow building in n8n, Power Automate, Make and Zapier. | Working automations covering the prioritised scenarios. Versioned flow definitions in your source control. Scope bounded | 100% Flows versioned in source control with named owners 100% Flows versioned in source control with named owners | View scope | |
Founder delivery proof
Real operator numbers, kept in the page where buyers need them.
These are anonymised outcomes from work inside regulated, audit-heavy Maltese operations before ITSailor. They are used as evidence for the service model, not as client logos.
device compliance
Intune plus Conditional Access baseline landed inside a 30-day window.
hardware onboarding
Windows Autopilot replaced manual click-and-install work.
dead licences reclaimed
HR status changes killed sessions, converted mailboxes and reclaimed E3/E5 waste.
L1 ticket volume removed
Jira Service Management and n8n handled standard access requests after approval.
malicious payload block rate
Defender for Office 365 tuning with Safe Links, Safe Attachments and isolation playbooks.
developer onboarding cut
Documentation-as-code moved infrastructure knowledge into Git review.
What delivery looks like
Screens buyers can understand before they book a call.
The visual panels mirror the artefacts produced by the services: policy repos, audit evidence, workflow queues and handbook material.
Evidence route
M365 hardening path
- DiscoveryShort call. We choose the right service or route you to the workshop.
- BaselineRead-only scan, scope lock and rollback notes before touching production.
- BuildPolicies, scripts, flows and docs land as reviewable artefacts.
- EvidenceControls map to ITS-M365, NIST CSF 2.0, GDPR, DORA, NIS2 or your internal standard.
- Exit KitRunbooks, ownership map and handover notes stay in your tenant.
Policy repo
Evidence pack
Automation queue


Evidence by default
Controls are mapped before the handover call.
Defensible wording only: mapped, ready and aligned. No fake certification seals.
Need a wider architecture call before picking a service?
The €499 workshop covers Cloud, Microsoft 365, security and AI automation in one live session. The service table becomes the implementation path after scope is clear.