What gets checked
- Enterprise identity architecture, SSO migrations, or complex conditional-access programs
- Holding your passwords or recovery keys
- Changes your IT provider should own - we write the requirement and coordinate the handoff
For most offices this is the fastest path from vague worry to a concrete security improvement. If the changes are larger, the Tune-Up becomes the work order.
Questions owners actually ask
Do you need our passwords?
No. Your team signs in and drives. We review settings beside you, write the plan, and only make changes when authorized in writing.
Is this the same as zero-trust?
No. For a small or mid-sized office, the useful work is much plainer: MFA where it matters, fewer admins, no orphaned accounts, and a real offboarding habit.
Can our IT provider implement the fixes?
Yes. That is often the best answer. We give them the clear requirements and help the owner understand what was done.
More on the full FAQ page - including “why should we trust you with our office?”, answered honestly.