Echo
Microsoft 365 security operations. One view.
A security operations dashboard that brings alerts, identity risk, device compliance, email threats and incidents into a single console — instead of the half a dozen admin portals they live in today.

This is the actual dashboard
Not a video, not a click-through, not a picture. This is Echo itself, running in the page. Move through all eight views, drill into an incident, run a collection, sort and filter a table, export it, switch the theme. Everything works because it is the real build — reading fictional data rather than a live tenant.
The real build, reading fictional data. Nothing here is connected to a live tenant.
The answer is in there somewhere
Microsoft 365 does not lack security information. It scatters it. Answering “is anything wrong this morning?” means opening these, one at a time, and holding the answer in your head as you go.
Echo puts all of it on one screen.
Eight views, one morning check
Each view answers one question properly rather than showing a tile of everything. Every table drills down, sorts, filters and exports.

The morning check, on one screen
Secure score against a 30-day trend, open alerts by severity, a live incident feed and sign-ins over the last 24 hours. The header states when the last collection ran and when the next one is due, so nothing on screen is of unknown age.
- Critical, high, risky users, MFA gaps and non-compliant devices at a glance
- Secure score trended, not just stated
- Live incident feed with the source against each entry
- Signals by source — Entra ID, Defender XDR, Intune, Exchange, service health

Who can get in, and how hard it would be
MFA registration, risky sign-ins over 14 days and the users behind them. Identity is where most incidents start, so it gets its own view rather than a tile on someone else's dashboard.
- MFA coverage across the tenant
- Risky sign-ins trended over 14 days
- Risky users listed with what triggered them
- Conditional access coverage and privileged accounts

What they get in on, and what is arriving
Device compliance broken down by platform with the machines that have quietly stopped checking in, alongside quarantine, phishing and impersonation detections from Defender for Office 365.
- Compliance state by platform
- Stale and non-compliant devices surfaced, not buried
- Threat detections over 30 days by source
- Recent detections listed with what was done about them

Ranked by what it puts at risk
Open incidents by severity and the new ones over 12 days, with an alert centre and the policies generating them — so a noisy rule gets fixed rather than ignored.
- Correlated incidents, ranked by risk not arrival time
- New incidents trended so a spike is visible
- Alert centre with configurable policies
- Drill into any record, then act on it

What you would fail on today
Control coverage mapped to CIS, ISO 27001, NIST CSF and SOC 2, with the top control gaps ranked — next to live Microsoft 365 status and advisories, because half of what looks like a fault is Microsoft having a bad morning.
- Framework coverage across CIS, ISO 27001, NIST CSF and SOC 2
- Coverage by domain, with the gaps ranked
- Live Microsoft 365 service status and advisories
- Everything exportable to CSV
The same picture, out of hours
Every view reflows to a phone rather than shrinking. Severity counts stack, tables become cards, and the incident feed stays readable one-handed — because the call that matters rarely arrives while you are at your desk.
- Every view, not a cut-down mobile subset
- Severity counts and incidents readable at a glance
- Tables reflow to cards rather than scrolling sideways
- Light and dark, following the device


Nothing it doesn’t need
One view, not another portal
The problem is not that Microsoft lacks data — it is that the data is spread across half a dozen consoles. Echo puts what needs attention on one screen.
Read-only, by design
Echo reads through the Microsoft Graph with least-privilege, read-only consent. It reports on your tenant and cannot reconfigure it — there is no setting in Echo that changes anything in Microsoft 365.
Collection, then evaluation
Echo runs a collection against the tenant, then evaluates every signal against its policy engine. The header always says how old the picture is.
Built by people who run tenants
Shaped by what our own engineers check every morning across the estates we manage, rather than by a feature list assembled from a competitor's website.
Built, not mocked up
The demo above is the software itself — every view, every drill-down, every export. What it reads today is fictional data rather than a live tenant, which is the step still ahead of it.
It’s built. You’ve just used it.
Echo is working software, not a concept — every view above is the real thing. What it reads today is fictional data rather than a live tenant, and we’re talking to a small number of organisations about what it should connect to first. If the problem it solves is one you recognise, we want to hear which part of it matters most to you.