Trust and security posture
Outsight is designed as a practical, read-only Microsoft 365 hygiene snapshot. This page states current intent and operating boundaries; it is not a compliance attestation or security certification.
Read-only by design
Outsight requests read-only Microsoft Graph permissions and uses them to inspect tenant hygiene signals. It does not write to Microsoft 365, change policies, disable accounts, remove guests, rotate credentials, alter SharePoint sharing, or perform remediation actions.
Permission transparency
The requested scopes are visible during Microsoft admin consent and are listed on the privacy page. Administrators should verify the permissions are appropriate before consenting and can revoke the Enterprise Application in Microsoft Entra ID when access is no longer needed.
Data minimization
Outsight aims to store only the tenant identifiers, scan metadata, findings, and report data needed to provide the dashboard/PDF experience. It does not intentionally collect mailbox bodies, Teams messages, document contents, or passwords.
Important caveats
- Stored OAuth tokens are sensitive and require strong operational controls.
- Scan output depends on Microsoft Graph data availability and permissions.
- Findings are hygiene indicators, not proof of compromise or compliance.
- Outsight is not a security audit, managed detection platform, or incident response service.
Questions or deletion requests
Contact support@example.com for trust questions, access concerns, or deletion requests. Replace this placeholder before public launch.