Solution

Security findings prioritized for MSP action

A finding is a single security issue on one customer, ranked and explained. The point of a findings queue is that everything from a Microsoft 365 assessment to a certificate check to a CVE match arrives in the same list, in the same severity language, so a technician works one queue instead of five tools.

Where findings come from

Every check the platform runs produces findings into the same queue. The source is recorded, but the triage experience does not change with it.

Microsoft 365 assessments

Posture gaps from Secure Score, Conditional Access, Defender, identity signals, sharing, and admin configuration.

Domain and email security

DNS, DNSSEC, MX, CAA, and deep email authentication: SPF, graded DMARC, DKIM keys, BIMI, MTA-STS, DANE.

External attack surface

Subdomain and asset discovery, subdomain-takeover detection, exposed services and open ports, and web-app exposure.

Certificate monitoring

Certificate Transparency observations for new or unexpected certificates, plus an expiry rollup with tiered warnings.

Website security scans

HTTPS, TLS configuration, HSTS, CSP, security headers, cookies, and technology fingerprints.

CVE correlation

NVD, CISA KEV, and EPSS matched against technology detected on customer assets.

What makes a finding actionable

A list of issues is not the same as a queue you can work. Four things make the difference.

Severity you can trust

Findings are classified by severity so a team can clear critical and high issues before lower-priority items. Severity accounts for match confidence: a low-confidence technology fingerprint cannot on its own produce a high-severity confirmed finding.

The context that produced it

Each finding carries the customer workspace, the specific asset or Microsoft 365 setting involved, and when it was first seen. A technician does not have to go and reconstruct why the finding exists.

Remediation guidance

Findings include guidance written for the person who has to fix it and for the message that goes to the customer, so the queue drives both the change and the communication.

Stable identity across scans

A finding that persists between assessments stays the same finding rather than reappearing as new each run, so "open for six weeks" is visible and age can be tracked.

Triage across a portfolio

One ranked list, many customers

The organization view merges open findings across every customer workspace and orders them by severity, so the first hour of the day is spent on the genuinely urgent items regardless of which client they belong to.

Per-customer drill-down

From the portfolio list, a single customer’s findings open with their full Microsoft 365 and asset context for focused remediation work or a customer call.

Findings in the wider workflow

Assessment
Scheduled Microsoft 365 and asset assessments generate the findings.
Triage
Organization and customer views support portfolio-wide prioritisation.
Alerts
New or changed high-severity findings route to the owner through notification policies.
Reporting
Open findings and their status appear in customer reports for QBRs and audits.
Needs attention

Related pages

Frequently asked questions

Next steps

See how findings are prioritized across customers