Skip to content

Services

MIR · Managed Identity Resilience MCR · Managed Cloud Resilience MER · Managed Email Resilience MBR · Managed Brand Resilience MAR · Managed AI Resilience

Company

Resources Company Contact Get my Exposure Score →
MAREarly access DISCOVER → GOVERN → CONSTRAIN → TEST

AI exposure is an identity problem wearing a new name.

MAR discovers the AI tools and agent identities already running in your estate, and governs the standing access nobody has reviewed.

90 secondsNo signup to startRead-only, no agents

EarlyACCESS PROGRAMME
Read-onlyDISCOVERY
DesignPARTNER LED

The problem

Your AI risk register probably lists policy. Your exposure is access.

The question is not whether staff use AI. It is which credentials the AI is holding, and what those credentials can reach.

// no leaver process

Non-human identities that outnumber your people

An agent credential has standing permissions, no MFA, no manager and no offboarding. It is the closest thing most environments have to a permanent, unmonitored admin account — and it rarely appears in an access review.

// a decade of over-sharing, now searchable

AI assistants inherit permissions nobody had audited

Copilot-class tools create no new access. They make existing over-permission trivially queryable in natural language. The exposure was always there; the interface changed.

// untrusted input, trusted action

Agents that read attacker-controlled text

Any agent reading email, documents or web content is reading text an attacker can influence. Give it write access with no approval gate and a single poisoned input becomes a chain of authorised actions.

The programme

What MAR covers

Scope for the early-access programme. Capabilities are being built with design partners — we will tell you plainly what is live and what is roadmap.

01 · Discover

Find the AI touching your data

Shadow AI discovery across browser extensions, personal accounts, embedded SaaS features and OAuth-connected agents.

  • AI tool and agent inventory
  • OAuth grant and connector discovery
  • Embedded vendor-AI feature detection
  • Data-egress path mapping
02 · Govern

Treat non-human identity like identity

The same discipline MIR applies to service accounts, applied to agents and service principals.

  • Non-human identity inventory with named owners
  • Permission scoping and right-sizing
  • Credential lifecycle and rotation
  • Inclusion in access reviews
03 · Constrain

Fix reachability before rollout

What an AI assistant can reach is a permissions question, answered before the licence is switched on.

  • Over-sharing remediation ahead of assistant deployment
  • Sensitivity labelling and data-boundary enforcement
  • Approval gates for agent write actions
  • Audit logging of agent activity
04 · Test

Verify the instruction boundary

Prompt-injection and agent-abuse testing, repeated as the system changes.

  • Prompt-injection testing of customer-facing and internal agents
  • Agent-abuse and tool-misuse scenarios
  • Vendor AI default review per SaaS platform
  • Retesting on change, not once at launch

Honest status: MAR is in early access. Discovery and non-human identity governance draw on capability we already run at scale; prompt-layer testing and continuous agent monitoring are being built with design partners. We will tell you which is which on the first call rather than after you sign.

At a glance

What’s included

The commercial and technical shape of the programme, before you talk to anyone.

StatusEarly access. Design-partner programme — limited places
DeploymentRead-only discovery via existing Microsoft 365 / identity provider integration
BaselineAI Exposure Assessment — shadow AI and non-human identity discovery
What you getDirect influence on scope and roadmap, and early-partner commercial terms
What we askAccess for discovery, and honest feedback on what is actually useful
OverlapsRuns naturally alongside MIR (non-human identity) and MBR (AI brand abuse)

Who MAR fits

This is a good fit if…

  • Microsoft 365 Copilot deployed, in pilot, or on the roadmap this year
  • Teams building agents or MCP connectors against production systems
  • A board or regulator asking what your AI risk position is
  • Shadow AI you suspect but cannot quantify

If none of these describe you, MAR probably is not your priority — and we would rather tell you that than sell it. Run the free assessment on a different surface and see where your score is actually worst.

Objections

The fair questions

Discovery and governance are the mature parts: shadow AI inventory, non-human identity discovery, OAuth grant review, and data-reachability assessment ahead of an assistant rollout — these draw directly on the identity work we already do at scale. Prompt-layer testing and continuous agent monitoring are being built with design partners. We would rather tell you that than imply a finished platform.

Copilot readiness is one deliverable inside it, and for many organisations the most urgent. The larger problem is non-human identity: agents and connectors holding standing permissions with no owner, no review and no offboarding. That will outlast any single vendor’s assistant.

A ban you cannot enforce technically produces shadow AI rather than less of it, and moves corporate data into consumer accounts you have no visibility into or claim over. Discovery first tells you what the policy is actually competing with.

Start with MAR

Find out where you stand on ai — in 90 seconds.

Eight questions, a score, and your top three exposure factors. If you want the real number, the full assessment reads your actual environment: read-only, no agents, 48 hours to a report.

90 secondsNo signup to startNo agents, read-onlyNo obligation

Get my Exposure Score — free →