Engagement Security
carlos.annes@takeittocloud.com
How an assessment engagement accesses your environment, what evidence is collected, where it is stored, and how it is removed. This page describes the standing engagement model; anything specific to your organisation is confirmed in writing before collection starts.
1. Access model
Assessments are read-only. Access is granted through a dedicated Microsoft Entra app registration created for the engagement, authenticating with a certificate rather than a client secret.
Microsoft Graph scopes are requested per module on a least-privilege basis — a module receives only the permissions its checks require. No write permissions are requested or granted at any point.
Before collection starts, a permission preflight runs and lists every scope the engagement will use, so the set of granted permissions can be reviewed and approved in full.
2. What is collected
The assessment collects configuration and posture evidence: tenant and workload settings, policy definitions, assignments, and counts.
It does not collect end-user file contents and it does not collect mailbox contents.
3. Storage and retention
Collected evidence is stored encrypted on the consultant’s systems for the duration of the engagement, and is deleted on client request after delivery.
The deliverables produced from that evidence — reports, crosswalks, trackers and exports — remain the property of the client.
4. Data processing agreement
A data processing agreement is available on request. The GDPR applies to the processing carried out during the engagement.
5. Removal at engagement end
At the end of the engagement the app registration is removed. Where the engagement continues as a retainer with a recurring assessment cadence, the registration is instead documented and retained for that reuse, with the same read-only scope.