Two excerpts from real deliverable formats, anonymised and reconstructed with representative figures. You should be able to judge the quality of the thinking — and whether it would survive your board, your auditor, or your customer's security team — before you speak to anyone.
One page from the executive pack. The full deliverable carries two to three of these, each traced to a specific system and priced into the remediation roadmap.
A vendor-hosted assistant embedded in the support desk. It reads inbound ticket text, retrieves from an internal knowledge base, and holds a tool integration permitting lookup of customer account records. Deployed by the support function in Q1; no security review was performed prior to launch.
Vendor-side content filtering (marketing-documented, not contractually specified). Agent review before send — the reply is not auto-dispatched, which is the sole meaningful barrier and depends entirely on the agent noticing anomalous content under queue pressure.
Immediate (0–30 days). Bind the account-lookup tool to the ticket's verified customer identity — this single change eliminates the disclosure path independent of model behaviour. Enable tool-invocation logging with retrieved record identifiers.
90 days. Introduce an AI vendor review gate covering data handling, retention, and breach notification, and apply it retroactively to the three assistants already in production.
An extract from the inventory delivered with every access audit. The full matrix lists every authorisation in the tenant; this shows the classification logic and the revoke-first ordering.
| Application | Publisher | Access granted | Users | Last active | Risk | Rationale & action |
|---|---|---|---|---|---|---|
| ██████ Sync | Unverified | Full Drive · read/write | 1 | 418 days | Critical | Authorised by a user who left in 2025. Token remains valid with full file access. Revoke immediately. |
| ████ Analytics | Unverified | Domain-wide delegation | All | 62 days | Critical | Delegation granted for a 2024 migration that concluded. Impersonates any user. Revoke; confirm project closed. |
| ███████ Notetaker | Unverified | Calendar · Drive · Meet recording | 14 | 2 days | Critical | Adopted organically; records client calls and retains transcripts on vendor infrastructure. No DPA in place. Suspend pending vendor review. |
| █████ CRM Connector | Verified | Gmail · read-only | 38 | Today | Medium | Business-critical and verified, but mailbox scope exceeds requirement. Reduce to metadata scope. |
| ██████ Scheduler | Verified | Calendar · read/write | 52 | Today | Low | Scope proportionate to function; publisher verified. No action. |
Risk is scored as data sensitivity × access level × publisher posture, applied identically to every authorisation and stated in the report so the rating is auditable rather than asserted. Findings map to SOC 2 CC6.1–6.3 (logical access) and, where regulated data is in scope, to HIPAA minimum-necessary provisions.
The complete 94-row inventory, the ordered revoke list formatted for an administrator to execute directly, the control-mapping page for the audit file, and a 60-minute findings session with the team.
Client names, application names, and identifying details are redacted or replaced. Figures are representative of engagements of this size rather than any single client's actual data. No client is identifiable from these extracts, and none is published without written permission — which is the same standard applied to your engagement.
A fifteen-minute session walking through a complete anonymised report — what was found, how it was rated, and what the client did about it. No obligation, and often it answers the question by itself.