Use case
Informed by Microsoft CAF AI strategy
What the workflow is for, who keeps the decision, and how value would be recognised.
A stated decision boundary is not evidence that the boundary is enforced anywhere.
Answer 18 controls across 6 dimensions. The result is a self-assessment, not an audit or a certificate.
Deployment control room
Choose the answer you can evidence today. A missing owner, policy, test, or incident path should appear in the plan, not disappear behind a generous score.
Diagnostic · model 2026-07-02
Each control is a real deployment question: who owns the workflow, where the data lives, what the AI may do, what gets logged, what happens when it fails. Every answer is taken at face value. Nothing here opens your tenant, your code or your data, so the result is worth exactly what the answers are, and Unknown is a valid answer.
One of four bands, from "unsafe to deploy" to "production-ready for a bounded use case".
Every risk signal your answers raise, ranked critical, high or medium, with the reason.
A fixed 30/60/90 sequence with your first evidence gap and your first safe use case written into it.
The verdict, both registers and the plan, in six sections you can forward internally.
6 dimensions, 3 controls each
Use case
Workflow clarity, decision rights, value hypothesis
Data
Sources, permissions, sensitivity, retention
Governance
Owner, policy, oversight, assessment trigger
Security
Prompt, tool, supplier, and model risk controls
Architecture
Identity, integration, logging, environments
Operations
Evaluation, incidents, training, rollout ownership
The controls were written against public framework material: NIST AI Risk Management Framework, NIST AI 600-1 Generative AI Profile, ISO/IEC 42001:2023, EU AI Act overview, OWASP Top 10 for LLM Applications, Microsoft Cloud Adoption Framework for AI. No control cites a clause, so read that as the shelf the questions came from, not a mapping.
Control surface
The scan is organised around operating decisions: what the workflow may do, which data it can reach, who owns it, how it is tested, and what happens when it fails. Each dimension states what you tell it and what that telling does not prove.
Informed by Microsoft CAF AI strategy
What the workflow is for, who keeps the decision, and how value would be recognised.
A stated decision boundary is not evidence that the boundary is enforced anywhere.
Informed by NIST Map and ISO 42001
Which sources the workflow reaches, how permissions carry, and what sensitivity applies.
Nothing here opens a tenant or a data store. The inventory is the one you describe.
Informed by EU AI Act and ISO 42001
Whether an owner, a written policy, an oversight step and an assessment trigger exist.
Saying a policy exists is not the policy. Neither the document nor its adoption is read.
Informed by OWASP LLM Top 10
Which prompt, tool, supplier and model controls you believe are in place today.
No control is exercised. This is not a penetration test or a supplier assessment.
Informed by Microsoft CAF and NIST Measure
How identity, integration, logging and environment separation are arranged.
No log or endpoint is read. A described architecture can differ from the deployed one.
Informed by NIST Manage and ISO 42001
Whether evaluation sets, incident paths, user training and rollout ownership exist.
An incident path nobody has ever run scores exactly like one that has been rehearsed.
Evidence model
A team can understand its gaps without being ready to deploy. It can also have a technically strong prototype with unacceptable use-case risk. The markers beside each step are the same key the other diagnostics use, so read what is missing from this one: no step is marked observed, because the scan reads your answers and never your systems.
This self-assessment is informed by public framework material and scores what you declare. It verifies nothing, and it is not a legal opinion, compliance audit, conformity assessment, certification, or substitute for testing the target environment.
Each answer contributes to its dimension, to risk signals, to certainty, and to any hard blockers, which can hold the verdict at unsafe even when other controls score well. Every control is answered before a result renders.
Unknown is an option on all 18 controls, and it is an answer rather than a hole in the model. It scores zero, it counts as zero certainty, it carries that control's worst risk, and it lands in the evidence register instead of quietly taking a favourable default.
The result lists why each material risk was raised and which documents, tests, owners, or technical evidence you said were missing. The list is capped, and the result says so when it truncates.
The recommended starting shape reduces decision authority, data exposure, and integration scope. It remains a planning recommendation until something verifies it.
FAQ
18 controls across 6 dimensions, 3 in each. Every control offers Unknown, which scores zero and becomes an evidence gap instead of a favourable default.
No. Every input is an answer you select. Nothing connects to your tenant, repository, code, logs, or data, and no answer is verified. That is why the output is a self-assessment and why the result is worth exactly what your answers are worth.
A readiness verdict, readiness and risk scores, self-reported certainty, a six-axis view, a risk register, an evidence-gap list, a first safe use case, a 30/60/90-day plan, and a PDF brief in six sections.
No. It is a structured self-assessment informed by public frameworks. It does not establish legal compliance, certify an AI management system, or replace a technical and legal review.
Scoring runs in your browser. A result is submitted only when you intentionally provide a work email for follow-up or report delivery.
ITSailor field library
Use the free packs for agent guardrails, governance decisions, operational evidence, and workflow engineering. Every available free resource remains browsable below.
25 free resources in the verified catalog. Reviewed 2026-07-18.
Twelve model-neutral system prompts for IT operations and security workflows.
12 model-neutral system prompts · configuration guide
Downloadable packTurn Claude Code into a working member of your IT operations team: 7 specialist agents, 5 guided skills, a project-memory template and the safety rails for regulated EU environments.
7 agents · 5 guided skills · safety contract
Downloadable packStructured decision matrices for mapping regulatory gaps.
Gap analysis · compliance mapping · incident taxonomy
Discovery, architecture, security baseline, policy and operating-review templates for Azure platform planning.
6 planning templates · policy intent · operating review
Downloadable packAssess AVD requirements, architecture, FSLogix recovery, security, cost and regional outage readiness.
6 planning templates · recovery · cost and outage review
Downloadable packPlan, run and evidence recovery drills without inventing the process during an incident.
6 working templates · drill evidence · recovery validation
Downloadable packThe six-tab Excel model ITSailor uses to surface cloud + SaaS waste and rank the savings backlog. Real formulas, not a static sheet.
6-tab Excel model · formulas · prioritised savings backlog
Downloadable packTrack renewals, audit licence use, assess new vendors and prepare evidence before commitment windows close.
6 working templates · renewal calendar · audit and reclaim procedures
Downloadable packStructure discovery, pilot waves, cutover, rollback and hypercare for cloud and Microsoft 365 migrations.
7 working templates · cutover gates · rollback procedure
Downloadable packDiscovery, architecture, organisation policy and operating-review templates for a governed Google Cloud foundation.
6 planning templates · policy set · operating review
Downloadable packRead-only PowerShell and KQL examples for Secure Score, inactive licensed users and failed sign-in bursts.
2 read-only Graph scripts · 1 KQL query · permissions guide
Downloadable packVersioned workpapers for reviewing Microsoft 365 controls, evidence, permissions and remediation priorities.
38 source-linked checks · permission audit · gap analysis
Downloadable packOperational templates for triage, device isolation, email purge, identity compromise and detection review.
7 working templates · 4 response procedures · review records
Downloadable packThree KQL detections plus the catalogue, tuning, hunting and review records needed to operate them.
3 KQL samples · 2 runbooks · monthly operating review
Downloadable packAWS Terraform scaffolding, a BCDR SOP and an infrastructure decision matrix.
AWS Terraform baseline · BCDR SOP · decision matrix
Downloadable packRecord ownership, architecture, handover evidence and supplier-exit questions before a dependency becomes lock-in.
4 neutral templates · ownership map · handover and supplier-exit checks
Downloadable packTwo sanitised n8n workflow exports, a broken-flow triage runbook and the operating notes needed to adapt them safely.
2 sanitised n8n exports · triage runbook · operating notes
Get an AI deployment verdict, risk register, and 90-day plan from what you declare.
18 declared controls · risk register · unknowns stay unknown
Interactive toolModel one workflow from your own operating numbers and see the range it produces.
Your own baseline · three scenarios · 7 scored questions of 10
Interactive toolInspect one GitHub repository across five evidence families.
5 evidence families · unreadable controls stay unknown · token not stored
Interactive toolEnsure your emails hit the inbox, not the spam folder.
Live DNS checks · 29 DKIM selectors
Interactive toolReview your Microsoft 365 security posture across 38 risk-weighted controls.
38 checks · 6 categories · source-linked assessment
Interactive toolIdentify access leaks and data risks for departing users.
Risk profile · gap matrix · remediation timeline
Interactive toolFind every SaaS you run - and pay for - across users, spend, and SSO.
Three scan paths · browser-local CSV processing