How it works
A measured picture of what your AI estate can reach.
Polaris reads your Microsoft 365 and Azure estate, builds a warehouse of agents, permissions, labels, and effective reach, and turns it into two things: an honest risk picture, and a reversible way to close the exposure. Here is how each part works.
Cross-plane inventory
Every agent, on every plane it hides on.
“How many AI agents run in our tenant?” has no single screen that answers it, because agents live on at least three separate control planes. Polaris enumerates all of them and reconciles them into one census — with owner, configuration, connections, and the grounding data each one is wired to.
Depth, not a phone book: per agent we record ownership, configuration drift, tool and connection risk, and grounding-data sensitivity — the things an auditor actually asks.
Coverage is reported per plane. Where a scope is denied or a subscription is unlicensed, Polaris says so — it never reports a blind spot as a zero.
Oversharing detection & remediation
Find the reach that’s too wide — then close it, reversibly.
Oversharing is the blocker for turning AI on: Copilot surfaces whatever a user can already reach, so overshared content becomes AI-exposed content on day one. Polaris finds it and gives you the controls to fix it without a big-bang risk.
- Broad-group detection. Not just the SharePoint “Everyone” claim — any Entra/AD group whose membership is effectively tenant-wide, and every site, app, and flow it can reach.
- Admin-set reach thresholds. What counts as “overshared” differs by org — you set the number (e.g. a site reachable by ≥10,000 users), and Polaris scores against it.
- Sensitivity-label intersection. The highest-risk finding is a sensitive label on an over-reachable site — surfaced first.
- Remediation campaigns with teeth. Notify the responsible owners, give them 30 days, and on expiry enforce — remove the over-broad access and/or correct the site’s label.
Enforcement, live-validated in our own tenant
Enforcement writes to your tenant, so it carries blast radius — which is exactly why it is off by default, previewed, audited, and undoable.
Deployment model
Your data stays in your tenant.
A real architectural difference, not a policy promise.
In your subscription
Polaris deploys into your own Azure subscription and Microsoft 365 tenant. The warehouse of permissions, agents, and labels is built where your data already lives.
No data exfiltration
We don’t pull your tenant’s content into a vendor cloud to analyse it. There is no multi-tenant lake of your sharing graph sitting on our side.
Least-privilege, separated scopes
Read scopes and the write scopes that enforcement needs are separated and optional. Enforcement permissions are only added when you choose to arm remediation.
Design-partner program
Build it with us.
Polaris is pre-general-availability. We’re working with a small group of design partners — Microsoft-centric MSPs and in-house governance leads — who have the agent-sprawl problem today and want to shape what we build. Honest terms: there is no paying tier yet.
What partners get:
- Early access to the inventory and oversharing product, deployed in your own tenant.
- Direct influence on the roadmap — thresholds, campaign design, the reports you need.
- A working relationship with the people building it, not a support queue.
What we ask: a real Microsoft 365 estate to learn from, and candid feedback.
One human reads every message. No automated sequence, no data collected beyond your email and what you choose to tell us.