Seviact
For MSPs and managed IT/security providers
Evidence-first Microsoft 365 security oversight.
Seviact gives MSPs one place to oversee Microsoft 365 security across every managed customer: evidence-backed issues tied to the specific device or account involved, guided remediation with a clear approval trail, independent re-verification before anything is marked resolved, and customer-ready proof of the work done.
Security signals are easy to generate. Acting on them well is harder.
Microsoft 365 produces a constant stream of security signals. The hard part for an MSP isn’t seeing that something happened — it’s knowing which signals are worth attention, what’s actually going on behind them, what to do next, and how to prove the work was done once it’s finished.
Seviact sits alongside Microsoft’s own security tools — Defender, Sentinel, and the rest of the Microsoft 365 security stack — as a governance, evidence and proof layer for supported Microsoft 365 security scenarios. It isn’t a replacement for them, and it doesn’t attempt to monitor everything in Microsoft 365 — it works with supported controls and connected environments.
How Seviact works
Six stages, from connecting an environment through to demonstrating the work that was done.
Connect
Connect supported Microsoft 365 environments and establish the evidence needed for supported security checks.
Identify
Surface evidence-backed findings and see what actually needs attention.
Investigate
Review the evidence behind a finding — what was observed, why it matters, and what it affects.
Resolve
Get clear remediation guidance, with governed workflows where they're supported and guided steps where they're not.
Verify
Re-check the evidence after remediation, rather than treating an issue as resolved because someone marked it done.
Prove
Turn findings, actions and verification into evidence you can show your customer.
Security issues backed by evidence.
Every issue in Seviact traces back to something Microsoft 365 actually showed — the evidence comes first, and interpretation follows it, not the other way around.
Rather than leaving checks scattered across separate Microsoft consoles, they’re brought into one workspace. Supported categories today include Admin MFA coverage, Secure Score posture, security-setting drift, legacy authentication exposure, Conditional Access coverage, device compliance, and dormant privileged accounts.
This is a supported, growing set of checks — not visibility into everything happening in Microsoft 365.
Current issues
Priority issues
Connection health
Last checked
- highAdmin MFA coverage
- mediumDevice compliance below target
- mediumConditional Access coverage
- mediumDormant privileged accounts
- What we found
- Device compliance is below Seviact's supported 80% coverage target.
- Why it matters
- Unmanaged or non-compliant devices can increase exposure.
- Affected
- The specific non-compliant devices, drawn from available Intune evidence.
- Evidence
- Device name, primary user, operating system, compliance state, last check-in.
- How to resolve
- Review the listed devices and remediate the underlying compliance conditions.
- Who should resolve it
- MSP technician / Microsoft 365 administrator.
- Verification required
- Seviact re-checks the evidence before the issue is marked resolved.
Evidence has limits, and Seviact shows those limits rather than filling the gap with assumptions — for device compliance, that means compliance state is shown, but not always the specific policy reason Microsoft assigned it. Illustrative example above — not a screenshot of the live product, and not real customer data.
An Action Guide helps MSP operators decide what to review next.
It’s deterministic and explainable — not AI, and not an autonomous decision-maker — prioritising connection-health problems first, then the highest-severity open issue, then the supported guidance available for that capability. Available to MSP operators today, across the customers assigned to them.
Restore Microsoft connection for the affected customer
Why this needs attention: when the Microsoft 365 connection is unhealthy, Seviact guides the operator to restore it before relying on new evidence — so this is reviewed ahead of other open issues.
What to do
- 1. Confirm the Microsoft 365 connection status for this customer.
- 2. Reauthorise the connection if it has expired.
- 3. Re-check evidence once the connection is restored.
Remediation & governance
Not every issue can or should be fixed the same way.
Guidance
- Seviact
- Explains what needs attention and how to review it.
- Administrator
- Reviews the guidance and decides how to proceed.
- Approval
- Not required
Manual remediation
- Seviact
- Provides the exact steps and records the outcome.
- Administrator
- Makes the Microsoft 365 change directly, then confirms completion.
- Approval
- Depends on the workflow
Approval-governed workflow
- Seviact
- Holds the next step until a named approver signs off.
- Administrator
- Approves, then completes the change themselves.
- Approval
- Required
No product UI surface used in the controlled pilot performs a live Microsoft 365 tenant change automatically. Every path — guidance, manual remediation, or approval-governed — ends with a person completing the change themselves, and Seviact recording and re-checking the result.
Completion is not proof.
A technician records
“I’ve done the work.”
Seviact confirms
“Fresh evidence shows the issue is resolved.”
Seviact re-checks Microsoft evidence before treating supported issues as resolved. A technician’s note alone is never enough.
This isn’t instant or continuous — it depends on Seviact’s next supported evidence check, not a live watch on your tenant.
Turn completed security work into customer-ready proof.
Seviact generates an MSP-branded, print-ready security report straight from a customer’s actual posture data — suitable for a regular customer security review. It’s a record of the work done and the evidence behind it, not a certification, an insurer approval, or a regulator attestation.
Customer Security Review
Issues reviewed
Resolved work
Verified outcomes
Outstanding attention
- Current security position
- Findings
- Remediation activity
- Verification
- Remaining attention
Know which customers need attention.
Each customer tenant is explicitly mapped to your MSP and access-controlled — nothing is auto-discovered. One console shows connection health, open issues, and high-priority counts for every mapped customer, with a direct drill-through into any one of them. This is oversight, not fleet-wide automation.
- Managed customer
- Connection health
- Open issues
- Priority issues
- Last checked
Illustrative structure — not real customer data.
Alongside this, Seviact compares supported security settings across assessments to surface meaningful changes.
What this means for your MSP
- Know what needs attention
- Move from a stream of security signals to a shortlist of evidence-backed issues.
- Give technicians clear next steps
- Provide the context and guidance to act with confidence, not just an alert.
- Verify work rather than simply close tickets
- Re-check the evidence after remediation instead of trusting a status field.
- Show customers what was done
- Turn findings, actions and verification into material you can put in front of a client.
Who it’s for
Primarily MSPs, managed IT providers and Microsoft 365 security service providers managing security across client environments. Internal IT/security teams handling Microsoft 365 responsibilities alongside everything else can use it too, though the workflow is built primarily around the MSP model.
Evaluate Seviact through a controlled pilot.
If you'd like to see how Seviact would work in your own environment, we can discuss a pilot suited to your MSP.