Observed control coverage
One square per observed check · unavailable data is never scored as safe
The Microsoft consent window is one of those screens people stop reading because it looks like paperwork. I want the opposite reaction. Put it on the conference-room display, slow down, and read every permission out loud. If a vendor cannot explain a line, that line should not be there.
In the book I hand business owners a single interview question for vetting providers:
"When you're evaluating IT providers, ask: 'What's the hardest decision you've ever made on behalf of a client—or an employee?' The answer tells you everything about their values. If they can't think of one, they haven't been tested yet."
Consent works the same way in reverse. Every time an MSP asks permission before reaching deeper, states what it can and cannot see, and stops at the boundary, it is answering that question in real time. The prospect is watching you be tested. A read-only scope you honored is worth more in that room than any certification on the wall, because it is values demonstrated instead of claimed.
From The 3AM Test by Steve Copeland.
Somewhere along the way, the software industry decided that permissions are a thing to get past. Bury the scary parts in gray text, bundle the access requests so nobody can untangle them, get the click, move on. Consent became a speed bump between the vendor and the data.
We built SCOUTz on the opposite bet: that in this market, for this buyer, consent done honestly is not a speed bump. It's a selling point, and one of the strongest we have.
The honest version begins before a scan touches anything. The client sees exactly what will be accessed, in specific terms, through Microsoft's own consent flow. Not "improve your experience" language. The actual scopes. And, critically, the list is short and it matches. Every permission requested maps to a collector that uses it. Nothing provisioned "for later." Nothing broad where narrow works. We audit our own app registration against actual usage, because over-provisioned registrations, asking for wide access on day one to make future features easier, are the industry norm, and the norm is wrong. An unused permission isn't convenient. It's standing risk with no offsetting benefit, sitting in the client's tenant, waiting to matter.
Now watch what this does in a sales conversation, because this is the part MSPs underestimate. Every serious prospect has a moment of hesitation before granting access. Something in them, or their IT counsel, or their attorney, says wait, what exactly are we letting in? Most vendors dread that moment. It should be your favorite moment in the whole meeting. Hand over the permission list. Invite the counsel to read it. Explain what each scope does and which finding it feeds. Point out what's absent: no content reads, no file access, no mail bodies.
The prospect's toughest skeptic just became your best closer. Because the skeptic has seen the other consent screens, the sprawling ones, the vague ones, and here is a vendor who narrowed the request on purpose and can defend every line. Scrutiny is only a threat to companies with something in the fine print. When the fine print is clean, scrutiny is free marketing.
This is what I mean when I say consent is a feature. Not a compliance checkbox, not legal cover. A designed experience that demonstrates, before any finding is ever delivered, how the vendor behaves when nobody's forcing them. Clients extrapolate from it, and they should. A company that respects the boundary at the consent screen is telling you how it treats everything behind it.
Ask for less. Show your work. Let them read the list. In a market drowning in vague permission grabs, transparency isn't just ethical. It's a competitive weapon.