The list

Everything the platform does, in one long list.

31 features, grouped by what you are trying to get done, each with a description that tells you what it actually is. The ones marked in the free plan need read-only access and nothing else.

Illustration of an IT administrator holding a very long checklist that unrolls to the floor

See your directory

Everything in this group runs on read-only access. Nothing is changed, and you can remove the app in four clicks.

  • Free health check

    In the free plan

    A scored report on your tenant, about ten minutes after consent.

    Sign in with Microsoft, approve read access, and the platform counts what is actually in the directory: users, groups, devices, licenses and sign-in activity. The result is a score out of 100 with the findings behind it, not a PDF someone wrote about you. You can rerun it whenever you want.

  • Ghost account detection

    In the free plan

    Accounts still enabled after the person left.

    Leaving dates get recorded in HR and never reach the directory. The report lists every account that is still enabled with no recent sign-in, together with the last sign-in date, the groups it still belongs to and the licenses still assigned to it.

  • Unused license cost

    In the free plan

    What you pay each month for licenses nobody signs in with.

    Assigned licenses are matched against actual sign-in activity and priced per month. The number is the one you can take to a budget meeting: this many seats, this much money, these people. Removing them is a one-click order once you upgrade — the reading of them is free.

  • Data quality findings

    In the free plan

    Missing managers, empty departments, inconsistent naming.

    Every rule you might want to automate later depends on attributes being present and consistent. The platform grades the attributes that matter — manager, department, company, employee ID, usage location — and shows you which records break them before you build anything on top.

  • Device and duplicate review

    In the free plan

    Three device registries, no synchronization between them.

    Entra ID, Intune and Autopilot each keep their own list, and after five years of Microsoft 365 they disagree. The review lines them up, flags stale and duplicated records, and proposes the ones safe to clean up.

  • Findings with the evidence attached

    In the free plan

    Every finding opens on the objects behind it.

    A finding you cannot verify is an opinion. Each one opens on the exact accounts, groups or devices that triggered it, with the Graph properties used to decide, so your own admin can check the claim in the portal in a minute.

Orders and approvals

The order is the change. A manager describes what they need, an approver sees the exact effect and the cost, and the platform executes it.

  • New employee orders

    Paid plan

    One form: role, company, start date, access package.

    The line manager fills in what they already know, and the platform derives the rest — account, groups, licenses, device policy, mailbox. There is no retyping into a second system, because the request and the execution are the same record.

  • Offboarding that finishes

    Paid plan

    Disable, revoke sessions, strip licenses, handle devices, close the record.

    Disabling an account blocks new sign-ins and nothing else. The offboarding order runs the full sequence Microsoft documents as separate steps — session revocation, group removals, license removals, device deactivation, mailbox handling — and does not close until each one has reported back.

  • Approval with the effect shown

    Paid plan

    The approver sees the change, the reason and the monthly cost.

    Approvers are asked to approve an outcome, not a ticket title. The screen shows the concrete change, who asked, the sentence of justification they wrote, and what it adds to the monthly bill. Approvals are logged with all of it attached.

  • Self-service catalogue

    Paid plan

    What employees may ask for, and who decides.

    Access packages, applications, licenses and equipment are published as a catalogue with an owner and an approval route each. If nobody owns it, it is not in the catalogue — which turns out to be the fastest way to find the access nobody has been responsible for.

  • Order queue

    Paid plan

    Every open order, across every tenant, in one list.

    Type, requester, tenant, status, age and assignee in a single view. Ageing orders surface on their own instead of waiting for someone to ask about them in a status meeting.

  • Employee app

    Paid plan

    Requests, approvals, equipment and licenses on the phone.

    Approvers approve from the phone, employees see what they have and what they have asked for, and relevant organisational contact lists can be synchronised to the phone's own address book for anyone who opts in.

Rights and delegation

Zero standing rights for people. The platform holds the permissions, and it can only do what an approved order asks for.

  • No standing admin rights

    Paid plan

    Nobody keeps a permanent Global Administrator role.

    The right moves from twelve people who can do anything at any time to one service that can only execute approved orders. Break-glass accounts stay where they belong, documented and monitored, rather than being the everyday way of working.

  • Access rules matrix

    Paid plan

    Who may request, who approves, what is written down.

    Rules are expressed per company, department and order type, and the matrix shows the whole thing on one screen. When someone asks why a request went to a particular approver, you can point at the row.

  • Delegation without portal access

    Paid plan

    Service desk and local IT get scope, not roles.

    Instead of handing out administrative units and custom roles in the Entra portal, delegation is expressed in the order model: this group may run these order types for these companies. They never sign into the portal, so there is nothing to misconfigure there.

  • Permission transparency

    In the free plan

    Every Graph permission listed, graded and explained.

    You can see exactly which Microsoft Graph permissions the app holds, why each is needed and what it is used for. Read consent and write consent are separate steps, and you can live on read-only for as long as you like.

  • Access review with a decision attached

    Paid plan

    Reviewers keep or remove, and the removals become one order.

    A review lists every member of a group with when they were added and when they last used the access, and flags the ones that should not be there at all — an account still active after its leaving date, for instance. Decisions create one access change order when the review completes, so nothing is removed before it has been approved.

  • The audit trail you thought you had

    Paid plan

    Request, reason, approval and result in one record.

    Entra ID logs that a change happened and who was signed in. It cannot log why, because nobody told it. Each order keeps the decision and the execution together, so an auditor's question is answered by opening one record rather than correlating three systems.

Groups and multi-tenant

Built for organisations with more than one tenant — after an acquisition, or as a service provider with a hundred clients.

  • One console, many tenants

    Paid plan

    Switch tenant without switching browser profile.

    Every connected tenant with its identity count in one list, one sign-in. No guest accounts in client directories, no separate admin identity per customer, no browser profile per client.

  • Standards across tenants

    Paid plan

    The same order types and rules everywhere.

    Order types, approval routes and naming conventions are defined once and applied to every tenant that should have them, with per-tenant exceptions where reality requires them. New acquisitions get the standard on day one instead of in the consolidation project that never finishes.

  • IT chargeback

    Paid plan

    Cost allocated per company, per period.

    Licenses and services are attributed to the company that consumes them, so the internal invoice is produced from the directory rather than from a spreadsheet someone maintains. Group hygiene stops being only an access problem and becomes budget control.

  • Connected business applications

    Paid plan

    What is attached to the tenant, and who owns it.

    Enterprise applications, their consented permissions and their owners in one overview per tenant. Applications with high-privilege consent and no owner are the ones you want to know about before someone else finds them.

Licenses and AI spend

Seat licenses are a fixed cost you can see. AI credits are a metered cost you mostly can't. This group is about attributing both to the company that actually consumes them.

  • License metering and billing

    Paid plan

    Seat products metered, entitled and billed per company.

    Copilot, Visio and other seat-based add-ons are attributed to the company using them — entitlement, usage and billing in the same ledger that already runs the identities behind the cost. The internal invoice comes from the directory, not from a spreadsheet someone maintains in April.

  • AI credits across vendors

    Paid plan

    AI usage credits allocated per company — also outside Microsoft.

    Microsoft meters Copilot credits inside its own billing. Other AI vendors meter theirs inside their own. Entra Logic allocates AI usage credits to companies and cost centers in one ledger, across vendors, alongside licenses and chargeback — one AI cost line per company instead of one per vendor.

  • Copilot credit allocation

    Planned

    Planned: Copilot credit budgets per company.

    Microsoft's spending policies assign Copilot credit budgets through security groups only — so the budget control is exactly as good as the group hygiene underneath it. We plan to allocate Copilot credits per company and per tenant on top of that model, in the same ledger as the rest of this group. This is planned, not shipped. This line changes when it ships.

Automation

Rules replace the scripts that one person wrote and nobody else understands.

  • Automation rules

    Paid plan

    A trigger, a condition, an action, a log line.

    Rules are built in the interface, versioned, and run under the platform's identity rather than a service account with a password in a text file. Every run is logged with what it changed and what it skipped.

  • Replacing script debt

    Paid plan

    Retire the PowerShell that runs on somebody's laptop.

    Scheduled scripts, service accounts with standing rights and key-person knowledge are the usual state after a few years of Microsoft 365. Rules cover the recurring parts of that work with an owner, an audit trail and a way to turn them off.

  • HR and joiner-mover-leaver triggers

    Paid plan

    Changes in role, company or manager start the right order.

    A move is not a new hire and not a leaver, and it is the case most organisations handle worst. Movers generate an order that both grants and removes, with the removals made explicit so the approver has to look at them.

Running it

The unglamorous parts that decide whether a platform survives its first year.

  • Self-service onboarding

    In the free plan

    Consent, read, report. No form and no call.

    The whole start is a Microsoft sign-in and a consent screen you can read. If it does not convince you, you close the tab and nobody phones you about it.

  • Plan and billing in the product

    Paid plan

    Identity count, current plan, cancel yourself.

    Pricing is per managed identity with volume steps, shown against your real number rather than a range. Upgrading and cancelling are both buttons in the product.

  • Removal in four clicks

    In the free plan

    Entra portal → Enterprise applications → Entra Logic → Delete.

    Access ends immediately. Data we have read is deleted within 30 days, or right away if you ask. This is written on the pages you read before you start, not in a support article you find afterwards.

  • EU data handling

    In the free plan

    European hosting, a data processing agreement, named sub-processors.

    The agreement and the sub-processor list are downloadable without a sales conversation, because the people who have to review them are not the people who buy.

The fastest way to check the list is against your own tenant.

Read-only access, about ten minutes, no form and no call. Everything marked as free above is running before you have spoken to anyone here.