AI exposure is an identity problem wearing a new name.
MAR discovers the AI tools and agent identities already running in your estate, and governs the standing access nobody has reviewed.
90 secondsNo signup to startRead-only, no agents
The problem
Your AI risk register probably lists policy. Your exposure is access.
The question is not whether staff use AI. It is which credentials the AI is holding, and what those credentials can reach.
// no leaver process
Non-human identities that outnumber your people
An agent credential has standing permissions, no MFA, no manager and no offboarding. It is the closest thing most environments have to a permanent, unmonitored admin account — and it rarely appears in an access review.
// a decade of over-sharing, now searchable
AI assistants inherit permissions nobody had audited
Copilot-class tools create no new access. They make existing over-permission trivially queryable in natural language. The exposure was always there; the interface changed.
// untrusted input, trusted action
Agents that read attacker-controlled text
Any agent reading email, documents or web content is reading text an attacker can influence. Give it write access with no approval gate and a single poisoned input becomes a chain of authorised actions.
The programme
What MAR covers
Scope for the early-access programme. Capabilities are being built with design partners — we will tell you plainly what is live and what is roadmap.
Find the AI touching your data
Shadow AI discovery across browser extensions, personal accounts, embedded SaaS features and OAuth-connected agents.
- AI tool and agent inventory
- OAuth grant and connector discovery
- Embedded vendor-AI feature detection
- Data-egress path mapping
Treat non-human identity like identity
The same discipline MIR applies to service accounts, applied to agents and service principals.
- Non-human identity inventory with named owners
- Permission scoping and right-sizing
- Credential lifecycle and rotation
- Inclusion in access reviews
Fix reachability before rollout
What an AI assistant can reach is a permissions question, answered before the licence is switched on.
- Over-sharing remediation ahead of assistant deployment
- Sensitivity labelling and data-boundary enforcement
- Approval gates for agent write actions
- Audit logging of agent activity
Verify the instruction boundary
Prompt-injection and agent-abuse testing, repeated as the system changes.
- Prompt-injection testing of customer-facing and internal agents
- Agent-abuse and tool-misuse scenarios
- Vendor AI default review per SaaS platform
- Retesting on change, not once at launch
Honest status: MAR is in early access. Discovery and non-human identity governance draw on capability we already run at scale; prompt-layer testing and continuous agent monitoring are being built with design partners. We will tell you which is which on the first call rather than after you sign.
At a glance
What’s included
The commercial and technical shape of the programme, before you talk to anyone.
| Status | Early access. Design-partner programme — limited places |
| Deployment | Read-only discovery via existing Microsoft 365 / identity provider integration |
| Baseline | AI Exposure Assessment — shadow AI and non-human identity discovery |
| What you get | Direct influence on scope and roadmap, and early-partner commercial terms |
| What we ask | Access for discovery, and honest feedback on what is actually useful |
| Overlaps | Runs naturally alongside MIR (non-human identity) and MBR (AI brand abuse) |
This is a good fit if…
- Microsoft 365 Copilot deployed, in pilot, or on the roadmap this year
- Teams building agents or MCP connectors against production systems
- A board or regulator asking what your AI risk position is
- Shadow AI you suspect but cannot quantify
If none of these describe you, MAR probably is not your priority — and we would rather tell you that than sell it. Run the free assessment on a different surface and see where your score is actually worst.
The fair questions
Discovery and governance are the mature parts: shadow AI inventory, non-human identity discovery, OAuth grant review, and data-reachability assessment ahead of an assistant rollout — these draw directly on the identity work we already do at scale. Prompt-layer testing and continuous agent monitoring are being built with design partners. We would rather tell you that than imply a finished platform.
Copilot readiness is one deliverable inside it, and for many organisations the most urgent. The larger problem is non-human identity: agents and connectors holding standing permissions with no owner, no review and no offboarding. That will outlast any single vendor’s assistant.
A ban you cannot enforce technically produces shadow AI rather than less of it, and moves corporate data into consumer accounts you have no visibility into or claim over. Discovery first tells you what the policy is actually competing with.
Find out where you stand on ai — in 90 seconds.
Eight questions, a score, and your top three exposure factors. If you want the real number, the full assessment reads your actual environment: read-only, no agents, 48 hours to a report.
90 secondsNo signup to startNo agents, read-onlyNo obligation