Microsoft 365 governance · built by M365 engineers
Still paying for a
Microsoft 365 audit
that's stale in two weeks?
Stale guest accounts. Licenses nobody's using. A Secure Score nobody can explain. Conditional Access exclusions from three admins ago. lisa runs every day — read-only, pseudonymised in-memory — and replaces the once-a-year snapshot with posture you watch continuously. Enable it once and forget it: no agents, no stored PII, no Microsoft expertise required.
No setup · no agents · no upfront payment
Built for security-conscious teams
Built for security teams who need to know their Microsoft 365 posture — before an audit, a board meeting, or an incident forces the question.
One platform, five engines
Not a scanner. A continuous governance platform.
Security posture is the flagship — but lisa runs every day across five engines that keep your tenant secure, compliant, and tidy without anyone babysitting it.
Security Posture
A daily scan engine that re-evaluates 138 signals across eight domains and synthesises findings with severity and concrete remediation. It replaces the point-in-time security audit with a living dashboard — your posture over time, never a report that's stale in two days.
Open the live posture demoConfiguration Baselines
Captures your tenant's live configuration as a versioned desired state and re-checks it every day. When a control drifts, you see exactly what changed — then enforce the desired state to bring it back, or accept the drift and keep it audited and traceable on the timeline.
See drift detectionGuest Lifecycle
Every tenant accumulates forgotten external accounts. lisa inventories each one, flags the stale and unsponsored, and drives renewals and removals through proper approval flows — so guest access never quietly piles up.
See guest governanceTeams & Groups Lifecycle
Enforces ownership and archive policy across Teams and SharePoint. lisa auto-archives dormant teams and moves their data to cold-tier storage — automatically, respecting your policy. Cleaner tenant, lower storage bill.
See lifecycle automationLicence Optimization
Maps your Microsoft 365 spend seat by seat and finds what leaks — idle licences, E5s that never open Defender, E3/E5 overlaps, licences left on disabled users. Every finding is quantified in CHF and ranked, so the biggest saving is the first thing you fix.
See licence savingsVerified against CIS v7.0.0
59 of 143 automatable CIS Microsoft 365 v7.0.0 controls — and growing every release.
Benchmark released 2026-05-19. lisa checks these the moment a scan runs — no waiting for the next quarterly audit — and we expand coverage with every release. 17 of 160 total controls are manual by nature and can't be automated by any tool.
41.3%
of all automatable CIS v7.0.0 controls, checked continuously
17
controls are manual by nature — no tool automates these
Coverage by admin center
From M365 engineers, for M365 engineers
Built by people who run Microsoft 365 — not people selling a dashboard.
We couldn't find a tool that actually helps M365 admins understand and harden their tenant without becoming Microsoft experts first. So we built one, on three principles we refuse to compromise.
Enable and forget
A scan runs, findings are prioritised, and you know exactly what to do. lisa manages the complexity so your tenant doesn't become another dashboard that creates more work than it saves.
Self-describing
No feature needs a manual or a support call. Every finding tells you why it matters, what to fix, and the impact — in language an M365 engineer reads once and acts on.
Runs without you
lisa scans every day in the background — no maintenance, no babysitting, no learning curve. Your team gets the findings, not the upkeep.
Sound familiar?
Most M365 tenants carry costs and risks
nobody's watching.
Security gaps and wasted spend build up quietly — through onboarding, license changes, and default settings nobody ever hardened. lisa surfaces both continuously and re-checks them every day, so a fix that silently regresses doesn't go unnoticed until the next audit.
Still paying CHF 10k+ a year for a one-time M365 audit?
A snapshot report is out of date the day config changes. lisa runs continuously for less than one annual audit costs.
Running PowerShell modules nobody on your team fully understands?
Inherited scripts nobody dares to touch aren't a security process — they're a single point of failure.
How many stale guest accounts are sitting in your tenant right now?
Most tenants don't know. lisa inventories every external account and flags the ones nobody's using anymore.
Not sure if you're using your Microsoft licenses efficiently?
Unused and over-provisioned licenses quietly cost real money every month — and nobody's watching them.
Paying for E5 on users who never open Defender or Power BI?
Premium licences sit unused where E3 would do — you overpay every month, and nobody's checking who actually needs them.
Disabled and ex-employee accounts still holding paid licences?
Every offboarded user with a live licence is money walking out the door — and they pile up quietly after each leaver.
Staring at a Microsoft Secure Score you can't explain to anyone?
A number with no story behind it doesn't help you prioritise. lisa turns it into findings you can act on.
Conditional Access exclusions nobody remembers adding — or why?
Every exception is a gap. Policies that grew organically for years usually protect less than anyone assumes.
Next compliance audit landing in a week — and you're not ready?
lisa gives you an executive-ready posture report in minutes, not the weeks a manual review takes.
These are real — and fixable. lisa tells you exactly which ones apply to your tenant.
Get started
Know exactly what's
misconfigured — and how to fix it.
Authorize read-only access and let lisa do the rest: it scans every day, pseudonymises in memory, and gives your team a live dashboard with concrete remediation — plus continuous guest, Teams, and configuration governance running quietly in the background.
No upfront payment · Read-only OAuth · Swiss-founded · No endpoint agents