TrueRock OutCrop
TrueRock OutCrop is the MSP's workspace in TrueRock.AI: one view across every client's Microsoft 365 tenant, ranked worst-first. Every finding carries its evidence and its fix.
See your own Microsoft 365 exposure
What it does
- Shadow AI + agent governance
- Find and risk-score every AI app, browser extension and autonomous agent touching the tenant — including the Copilot Studio and Power Automate agents clients build themselves.
- AI Watch — Governed AI Safety Report
- One per-client report of every AI touching the tenant — the governed lane in full, Microsoft Copilot via the audit log, and shadow-AI traffic on every managed device — with the right label applied so the AIs you can’t watch still can’t read what they shouldn’t.
- Find sensitive data (classification)
- Automatically read the content of files and mail and classify what’s sensitive — PHI, PII, financials, contracts — without anyone labeling it first.
- Data exposure + blast radius
- Map who — and what — can reach classified data: the people, apps and agents that can read, write or exfiltrate it, and the reach an attacker inherits.
- Remediate exposure
- Close the leak: revoke risky external shares, apply the exact protecting label, and stand up DLP on the data types actually found.
- Conditional Access enforcement
- Verify the sign-in policies that keep accounts safe — MFA, device trust, blocking legacy auth — actually cover every user.
- Device compliance (Intune / Defender)
- Confirm every managed device is encrypted, patched and antivirus-healthy — with a ranked queue of what to fix first.
- Compliance mapping + client-ready reports
- Map a client’s real configuration to the controls that matter across CIS for Microsoft 365, HIPAA, NIST CSF, ISO 27001 and Essential Eight, and produce the branded, cited evidence pack. Compliance splits into what a machine can prove and what people must attest — this is the first part, delivered whole: every control counted against the framework’s total and traceable to the signal behind it.
- Assess — AI readiness + threat intel
- Score whether each tenant can safely turn AI on — six dimensions from labeling to oversharing to DLP-for-AI — and surface the CVEs that actually threaten each client, ranked by real exploitability.
- AI-governance maturity + next best step
- Place each client on the journey from ad-hoc AI use to a governed AI estate — Land, Ground, Automate, Connect — and name the one thing to fix next to move up a level.
- Licensing advisor + daily change tracking
- Read every tenant’s licensing to reclaim waste, close security gaps, right-size seats and drive adoption — and track what changed each day — as advice, not an upsell.
- Automate — Skills
- Author a cited report once and run it the same way on every client — the MSP writes the generator, every technician runs it identically.
- Onboard the whole book in one consent
- One GDAP-native admin consent registers every client you manage, you pick a pilot tenant, and a plan quota caps spend before the first scan runs.
- First-Look assessment for a prospect
- Run a read-only assessment of a prospect’s Microsoft 365 under the access they grant, and hand them a result that says what was examined, what was not, and why — with no overall score invented from partial evidence.
- Findings into your PSA, as tickets
- Turn findings into tickets in the PSA your service desk already lives in — ConnectWise, Autotask or HaloPSA — routed to the right board by severity and control, without anyone re-typing them.
- Portfolio cockpit — every client, ranked
- The whole book on one screen: every tenant ranked worst-first by risk, and every metric opening onto the client most affecting it and the root cause they share.