AI Readiness Assessment Scan - By Sabiki Security
Sabiki Security · Cybersecurity & IT
Certification per Microsoft Marketplace.
Evidence tier Source Confirmed · 1 capture on record
What the publisher says
As described on Microsoft Marketplace.
Sabiki Security are excited to announce the release of our AI Readiness Assessment Scan as a FREE TOOL!
Know what AI can reach in your tenant — before you turn it on
Show the rest of the publisher’s description (51 more lines)
Sabiki Security are excited to announce the release of our AI Readiness Assessment Scan as a FREE TOOL!
Copilot and AI agents inherit the tenant you already have. They read what your
people can read, follow the sharing you already allow, and act through identities
that hold standing permissions around the clock. A file that is overshared today
becomes a file an assistant can surface on request tomorrow. Deployment does not
create these conditions. It makes them reachable at machine speed.
The Sabiki AI Readiness Scan answers one question before you commit:
is this tenant in a fit state to run AI?
What it does
The scan runs 112 checks across four pillars and returns a readiness score out
of 100, a prioritised worklist, and a plain-English explanation of every finding
with the exact steps to fix it.
- Settings — sharing, consent, Conditional Access, and the tenant
controls that decide who can approve an application into your environment.
- Data Protection — sensitivity labelling, DLP policy coverage and
retention, measured against the content AI would be able to read.
- Data Exposure — anonymous links, guest access and stale sites: the
surface an assistant inherits on day one.
- Identities — the AI agents, service principals and other non-human
identities already operating in your tenant, and what each one can reach.
Scored against recognised frameworks
Every check maps to established benchmarks, so the result is a measured pass
rate rather than a vendor opinion:
CIS Microsoft 365 Foundations Benchmark
- NIST AI Risk Management Framework
- EU AI Act
- ISO/IEC 42001
Honest about what it can and cannot see
The scan reports its own coverage. Controls it measured, controls evidenced only
by self-attestation, and controls no tenant scan can reach are counted and shown
separately. Anything that could not be assessed is marked as such rather than
guessed, and your score reflects only what was actually checked.
Built for the questions AI raises
Readiness is more than a configuration checklist. The scan reads non-human
identity depth and maps each signal to why it matters once AI is live:
- Blast radius — what an agent inherits on compromise, including
high-severity scopes reaching mail, files and Teams at once.
- Credential hygiene — secrets that never rotate, and keys orphaned by
staff who have already left.
- Dormancy — identities that wake after months of silence.
Fast, and nothing to install
Onboarding and the scan together take under fifteen minutes. The scan is
agentless and requires no deployment. Nothing is installed in your tenant and no
configuration is changed. Results are available immediately in the console and as
an exportable, print-ready PDF report with a prioritised Now / Next / Later
roadmap you can hand to a board or a client.
Free
The AI Readiness Scan is free, with no trial period and no sales requirement.
If the result comes back strong, that is a useful thing to know at no cost. If it
does not, you leave with a specific, ordered list of fixes rather than a vague
concern.
Preview
5 imagesAgent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Sources
Publisher resources
2 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.





