What you just read
The result above is not an illustration. It is produced by the engine from packaged evidence, re-rendered every time this page is built, and it carries four lines that most reports do not have together: what was observed, on what basis, how complete the evidence was, and what the conclusion does not establish.
That last line is why the first three are worth acting on.
Why this is different
It shows why. Every conclusion names its basis: a requirement the product enforces, a documented limit with a number, Microsoft's own guidance, a convention, or an opinion stated as ours. Four of those lead to four different conversations, and a report that renders them identically has removed the one thing the reader needed. The five kinds of claim →
Unknown stays unknown. When evidence was not collected, was refused, or cannot answer the question, the result does not become a pass. It says so, in words, and the report distinguishes what was observed from what was assumed. Why unknown is never a pass →
The evidence is yours. Collection, assessment and reporting run on your machine. The documents that come out can be inspected, re-run and verified by somebody else without us. Checking a document somebody handed you →
How it works
Four steps, and you can stop after any of them and still have something usable.
| 1 · Microsoft 365 | A read only collector reads the surfaces you point it at, with credentials you configure |
| 2 · Evidence | What came back, normalised to JSON, with its provenance and the gaps named |
| 3 · Rules | Public rule files, in plain text, that you can read, argue with and change |
| 4 · Assessment | A document for a person in Markdown and for a pipeline in JSON |
What it can assess
Thirteen collection areas. Nine feed rules; four deliberately do not, because a conclusion needs a sentence somebody can defend and Microsoft publishes nothing to defend one with.
| SharePoint sites and storage | Ownership, quota, classification, sharing and permission scale |
| Custom script and customisation | Whether the classic scripting model is still open, and what that permits |
| Conditional Access | Whether a policy that appears in the portal is enforcing anything |
| Copilot agents | What exists, published as an inventory rather than as a verdict |
| Microsoft 365 licensing | Assignment, usage and dependency kept separate, so an unused licence is not read as a saving before the consequence is established |
Every capability, and how far each has been proved →
Try it
It ships with example data, so the whole thing runs before it is pointed at anything real.
Trust and security
Runs locally. Read only. No account with pH7x Systems. It has no write path to your tenant, no destination of ours to upload to, and no service we operate in its path. What it talks to is Microsoft. If the sign in is interactive, the report says so on its first page: that run saw what one person can see.
Open source
MIT. The rules, the collector, the schemas and the tests are public, and the result is verifiable without us.
If you would rather not do it alone
We can run the reading with you and tell you which findings matter in your context. It answers a different question from the SharePoint Compass, which helps you choose a direction rather than measure a condition.