AI is exposing the security gaps that were always there.
TrueRock finds the AI risk across every client, governs every AI they use, and proves it with evidence — all on the Microsoft 365 they already own.
TrueRock.AI is a multi-tenant Microsoft 365 security and AI-governance platform for Managed Service Providers (MSPs), built by TrueRock AI LLC in Redmond, Washington.
Two products, one engine. TrueRock OutCrop is what your team uses to find and prove the risk across every client. TrueRock Managed AI is what your clients' people use — governed AI you switch on per client, and meter.
In geology, an outcrop is where the bedrock breaks the surface — the one place you can see what the ground is really made of. TrueRock OutCrop does that for every client you manage. It brings what's hidden inside each Microsoft 365 tenant to the surface — overshared files, shadow AI, over-privileged agents, missing Conditional Access, configuration drift — ranked across your whole book, with the evidence behind every finding and the runbook to fix it.
// every client's risk, brought to the surface
// grounded, cited, redacted
// governed AI calls, metered per client
What it means for you — and for the clients you protect.
AI is the newest workload on the estate you already run. TrueRock governs it under your existing practice and turns it into a recurring service — metered to real usage, priced for the governance you provide — across your whole book, on the tier clients own, with evidence they sign off on.
The AI your team already reaches for — Copilot, Claude, agents — stays governed, not blocked. Your sensitive data stays yours: protected on the plan you already have, never fed to a model that shouldn't see it. And you get proof — a cited record you can hand your own board or auditor. Your trusted partner delivers it, not a black box.
Pick a product; watch the film — every demo cited to what it shows.
A one-time readiness check is a snapshot — stale the day it ships. TrueRock is built to reason deeper, prove every finding, and keep measuring across your whole book.
Reasons over a client's real environment — the connections and exposures a flat checklist never sees.
Every finding traces to its evidence. "The model said so" doesn't survive a client review. Provenance does.
The same intelligence never stops — the first assessment through every day you manage the tenant.
The AI reasoning is native to every surface and every client — not a chatbot bolted onto a legacy dashboard. Multi-tenant from day one, so it spans your whole book with clean, GDAP-secured isolation.
Help every client get the most out of the Microsoft 365 they own. On Business Basic through E3, TrueRock adds data classification, AI prompt protection, shadow-AI discovery and compliance evidence across your whole book. Where a client has E5, Copilot or Agent 365, TrueRock amplifies those richer signals into governance you can act on across every client.
Every capability answers twice — Without TrueRock, With TrueRock, on any SKU.
Your Microsoft 365 plan = what the client’s plan provides today, including what E5 adds on a single tenant · Plus TrueRock = what TrueRock adds on every plan, across every client.
| Capability | Your Microsoft 365 planthe Microsoft SKU, natively | Plus TrueRockon any SKU · cross-tenant |
|---|---|---|
| Shadow AI + agent governance Find and risk-score every AI app, browser extension and autonomous agent touching the tenant — including the Copilot Studio and Power Automate agents clients build themselves. | Basic–E3: not part of Microsoft 365 today. E5 adds Defender for Cloud Apps discovery — but single-tenant, and it doesn’t see the agents built inside Power Platform. | Basic → E5Enumerates and risk-scores every AI app and agent across your whole book, on any SKU. Where a client has E5, it folds Defender’s discovery in — and rolls it all into one cross-tenant AI Watch report. |
| AI Watch — Governed AI Safety Report One per-client report of every AI touching the tenant — the governed lane in full, Microsoft Copilot via the audit log, and shadow-AI traffic on every managed device — with the right label applied so the AIs you can’t watch still can’t read what they shouldn’t. | Not part of Microsoft 365 today below E5. E5 gives a Copilot / Purview audit trail — one tenant, one product, not a safety report. | Basic → E5Unifies the governed lane, Copilot and shadow AI into one Safety Report per client. Where E5’s Copilot/Purview audit exists, it folds that signal into the same cross-tenant report — honest about what’s off-device. |
| Find sensitive data (classification) Automatically read the content of files and mail and classify what’s sensitive — PHI, PII, financials, contracts — without anyone labeling it first. | Basic–E3: no automatic classification at all (manual labels only). E5 adds auto-label policies + trainable classifiers — deeper, but single-tenant. | Basic → E5Reads the content itself and classifies it on any SKU, cross-tenant — the “gold” nobody labeled, surfaced on Business Premium. Where E5’s labels exist, it reads them into the portfolio and the AI-readiness score. |
| Data exposure + blast radius Map who — and what — can reach classified data: the people, apps and agents that can read, write or exfiltrate it, and the reach an attacker inherits. | Basic–E3: not part of Microsoft 365 today. E5 / SharePoint-Advanced adds access-governance reports — single-tenant, and blind to third-party app scopes. | Basic → E5Shows who and what can reach classified data across every tenant, then reasons across scope, owner and sensitivity to name the single highest-risk key to revoke first. Unifies E5’s access-governance signals cross-tenant. |
| Remediate exposure Close the leak: revoke risky external shares, apply the exact protecting label, and stand up DLP on the data types actually found. | Manual share-revoke on any tier. E5 adds auto-labeling policies + inline DLP — single-tenant, and only once someone configures it. | Basic → E5Detect and one-click revoke on any SKU; name the exact Purview label the item needs and ship it as a runbook you approve, from Business Premium up. Drives E5’s DLP + auto-label across every tenant from one console. |
| Conditional Access enforcement Verify the sign-in policies that keep accounts safe — MFA, device trust, blocking legacy auth — actually cover every user. | Only from Business Premium up (Entra P1); Basic/Standard can’t enforce it at all. E5 adds risk-based CA (Entra P2). | Business Premium → E5Coverage-gap analysis per tenant, license-aware — names the failing baselines and the users a lesser SKU leaves excluded, and honestly flags the gap on the tiers that can’t enforce it. Reads P2 risk signals into cross-tenant coverage. |
| Device compliance (Intune / Defender) Confirm every managed device is encrypted, patched and antivirus-healthy — with a ranked queue of what to fix first. | Only from Business Premium up (Intune); not part of Microsoft 365 today on Basic/Standard. E5 adds Defender for Endpoint EDR — deeper, single-tenant. | Business Premium → E5Cross-tenant compliance across Defender + Intune, plus a remediation queue ranked by how many endpoints each fix clears. Reads Defender EDR signals into that view. |
| Compliance mapping + client-ready reports Map a client’s real configuration to the controls that matter across CIS for Microsoft 365, HIPAA, NIST CSF, ISO 27001 and Essential Eight, and produce the branded, cited evidence pack. Compliance splits into what a machine can prove and what people must attest — this is the first part, delivered whole: every control counted against the framework’s total and traceable to the signal behind it. | Basic/Std: not part of Microsoft 365 today. Business Premium+: a Compliance Manager score for one tenant. E5: fuller controls — still single-tenant. | Basic → E5Turns real config into framework mappings and MSP-branded, cited DOCX + PDF per client — every claim traceable to a control, and every control still needing human attestation named as scoped work rather than quietly scored. Pulls E5’s compliance signals into that report across the book. |
| Assess — AI readiness + threat intel Score whether each tenant can safely turn AI on — six dimensions from labeling to oversharing to DLP-for-AI — and surface the CVEs that actually threaten each client, ranked by real exploitability. | Basic–E3: not part of Microsoft 365 today. E5 adds Defender vulnerability management on the threat side — deeper, single-tenant, and it doesn’t score AI-readiness. | Basic → E5An AI-readiness score per tenant plus per-client CVE ranking — KEV and vendor-surface, not raw CVSS — across the whole book. Reads Defender’s vuln signals into that ranking and the readiness score. |
| AI-governance maturity + next best step Place each client on the journey from ad-hoc AI use to a governed AI estate — Land, Ground, Automate, Connect — and name the one thing to fix next to move up a level. | Basic/Std: not part of Microsoft 365 today. Business Premium+: a Compliance Manager score for controls on one tenant — not a staged AI-governance journey, and no next best step. E5: fuller controls, same single tenant. | Basic → E5A gated four-stage maturity level per tenant, computed from that tenant’s own posture — a later stage never counts until the foundation clears — plus the next best areas to improve, each with the real number and the concrete fix, as a client-ready report. |
| Licensing advisor + daily change tracking Read every tenant’s licensing to reclaim waste, close security gaps, right-size seats and drive adoption — and track what changed each day — as advice, not an upsell. | A raw license list on every tier, and nothing more — no advice, no daily diff. No Microsoft SKU ships this, E5 included. | Basic → E5Reclaim / secure / right-size / drive-usage per tenant, costed against compliance, plus daily change tracking across the whole book — the license as a lever to protect the client, not a blanket upsell.TrueRock is the ceiling — no SKU ships this |
| Automate — Skills Author a cited report once and run it the same way on every client — the MSP writes the generator, every technician runs it identically. | Nothing — no MSP-authored, RBAC-aware report automation exists in any Microsoft SKU. | Basic → E5Author once, run everywhere: cited, RBAC-aware report generators that any technician can run, fork and edit as templates — the same report, the same way, on every client.TrueRock is the ceiling — no SKU ships this |
| Onboard the whole book in one consent One GDAP-native admin consent registers every client you manage, you pick a pilot tenant, and a plan quota caps spend before the first scan runs. | GDAP is Microsoft’s own and you already have it — we add nothing to the mechanism. What no SKU gives is one consent that turns your delegated access into a working cross-client console, with a spend cap on it. | Basic → E5One admin consent covers the whole book, not one tenant at a time. Pick a pilot client, run it, and a plan quota bounds the cost before it starts — honest about what is scanned and what is not. |
| First-Look assessment for a prospect Run a read-only assessment of a prospect’s Microsoft 365 under the access they grant, and hand them a result that says what was examined, what was not, and why — with no overall score invented from partial evidence. | No Microsoft 365 SKU produces a prospect-facing assessment: the admin center scores a tenant you already administer, for its own owner. There is nothing to hand someone who is not yet a client. | Basic → E5A read-only first look that names every surface it read AND every surface it could not, with the reason — a license it lacks, an API that does not expose it, or a permission not granted. Findings carry the object and the endpoint they came from, and where the evidence runs out it says so instead of scoring anyway.TrueRock is the ceiling — no SKU ships this |
| Findings into your PSA, as tickets Turn findings into tickets in the PSA your service desk already lives in — ConnectWise, Autotask or HaloPSA — routed to the right board by severity and control, without anyone re-typing them. | Nothing. No Microsoft 365 SKU writes a ticket into an MSP’s PSA — the admin center is where a finding stops. | Basic → E5Routing rules you author (severity plus control) pick the board and queue, and the same finding is never dispatched twice. A failure is recorded and retried rather than dropped. The dispatch path is proven end to end on our side against a test adapter; pointing it at your live ConnectWise, Autotask or HaloPSA takes your own PSA credentials.TrueRock is the ceiling — no SKU ships this |
| Portfolio cockpit — every client, ranked The whole book on one screen: every tenant ranked worst-first by risk, and every metric opening onto the client most affecting it and the root cause they share. | Every tier gives an admin centre and a score for one tenant at a time. No Microsoft 365 SKU ranks your clients against each other, and none explains why a number moved. | Basic → E5Every tenant ranked by risk in one view, filterable by risk band and security domain, each metric drilling to the finding and the tenant behind it — and a synthesis of the correlation and the shared root cause, not just the number. |
| Capability | Your Microsoft 365 planthe Microsoft SKU, natively | Plus TrueRockon any SKU · cross-tenant |
|---|---|---|
| Governed Managed AI A sanctioned workspace over Copilot, Claude and OpenAI: every prompt scrubbed of secrets, quota-checked and metered, each question routed to the right-cost model, with a content gate that redacts sensitive data before it ever reaches a model. | A governed multi-AI lane is not part of Microsoft 365 today, on any SKU. Copilot governs Copilot only. | Basic → E5TrueRock’s governed lane over Copilot, Claude and OpenAI — sanctioned, metered and cost-controlled per client, and delivered as a governed managed service you’re paid to run, on any Microsoft 365 tier a client already runs. A persistent protective label on the source file, so the protection travels with it, needs Business Premium.TrueRock is the ceiling — no SKU ships this |
| Content gate on every prompt Classify what a prompt and its grounding documents carry on the way in, and block or redact unlabeled PHI, PII and card data before it ever reaches a model — then name the label that would protect the source file. | On Basic–E3, prompt inspection is not part of Microsoft 365 today. E5’s Purview controls reach Microsoft Copilot on that one tenant — and only Copilot; the other assistants a team actually uses sit outside them. | Basic → E5Inspects every prompt and grounding document before any model sees it — Copilot, Claude, OpenAI or an agent your client built — and blocks or redacts on your policy: one MSP baseline, per-tenant overrides, across the book. A protective label on the source file itself needs Business Premium. |
| Their own AI client, your policy Let a technician work in the assistant they already use — proven today with Claude, and open to any client that can authenticate to the connector — reaching one client’s data through a connector you sanction, with your policy applied on the way in and on the way out, and every call in an audit trail. | Copilot’s controls cover Copilot on each tenant; the other assistants a team uses need their own governance, and an MSP needs one policy across clients. | Basic → E5One connector you sanction, governed by a policy you author: an MSP baseline with per-tenant overrides, a floor the tenant cannot weaken, and a refusal that names the rule it applied. Every decision recorded — including the ones it could not make.TrueRock is the ceiling — no SKU ships this |
| Per-person answers, not a shared index Two people ask the governed assistant the same question about the same client and get different answers, because each person’s retrieval runs on their own delegated access — auditable one user at a time. | Microsoft 365 Copilot already honors each user’s permissions on the tenant it runs in — that is its design, and we do not claim otherwise. What no SKU gives is the same guarantee on the OTHER assistants a team uses, or one place to prove it across your whole book. | Basic → E5Retrieval built with each person’s own delegated token, so a document they cannot open is never read, never summarized and never indexed for them — not filtered out after the fact. On the Microsoft 365 the client already pays for. |
| Capability | Your Microsoft 365 planthe Microsoft SKU, natively | Plus TrueRockon any SKU · cross-tenant |
|---|---|---|
| AI cost control — right model per question Send simple questions to a lighter model and hard reasoning to the powerful one — control AI cost per client without giving up quality, and show the credits saved. | No Microsoft 365 SKU routes by complexity or shows AI savings — Copilot is a flat per-seat license, one price whatever you ask. | Basic → E5Picks the right-cost model per tenant, re-runs a low-confidence answer on the powerful one, and shows the credits saved per client — cost control a flat license can’t give, on any Microsoft 365 tier a client already runs.TrueRock is the ceiling — no SKU ships this |
| Ask TrueRock — grounded, cited answers A security-analyst chat across every client’s real Microsoft 365 that reasons across clients — every claim cited to the record it came from. | Not part of Microsoft 365 today, on any SKU — Copilot is per-tenant and per-seat, not a multi-tenant analyst. | Basic → E5Cited answers across every client’s real Microsoft 365 at once — it connects records across two or more clients to surface the systemic pattern, not just answer for one tenant.TrueRock is the ceiling — no SKU ships this |
| AI spend limits + client chargeback Cap what each client can spend on AI before they spend it, meter every token back to the tenant that caused it, and account for it per client, priced to the usage you actually meter. | No Microsoft 365 SKU meters AI per client for an MSP — Copilot is a flat per-seat license billed to the tenant, with no limit to set and no margin line. | Basic → E5Per-tenant token limits with soft-warn and hard-block thresholds and a reset cadence you choose, plus a monthly statement per client — raw cost, your margin, the line the client sees — so AI is a managed service you can price, not an open tab.TrueRock is the ceiling — no SKU ships this |
It starts with a single tenant. Connect one client and TrueRock returns a board-ready, fully cited map of their AI risk — the shadow AI, the exposed data, the readiness gaps — every finding traced to where it lives, and honest about what it hasn't yet seen. That first read is the conversation that becomes a priced engagement.
Rather ask a question first? .