PROSPECT INTELLIGENCEILLUSTRATIVE
SCOUTz product evidence supporting The Questions Your Client’s Tenant Can Answer Before They Do.
Is a discovery questionnaire the same as an assessment?

No. A questionnaire captures what people believe or can recall; an assessment adds source-based evidence, and the strongest discovery process uses both.

Hand a business owner a security questionnaire and watch what happens. Do all users have multi-factor authentication enabled? Sure, I think so. Are legacy authentication protocols disabled? What's legacy authentication? How many third-party applications have access to your data? A few? Maybe five?

None of those answers are lies. They're guesses dressed up as answers, because the honest response to almost every question on the form is "I don't know," and nobody writes that on an insurance application.

This is the quiet fiction underneath most SMB security: nearly everything we know about a small company's posture is self-reported by someone who has no way of knowing. The owner guesses, the insurance carrier prices the guess, the compliance framework certifies the guess, and everyone proceeds as if data changed hands.

Meanwhile the tenant knows. Every question on that form has a factual answer sitting in Microsoft 365 configuration right now. Not an impression, not a recollection of something the IT guy said in 2023. A setting, readable in seconds, with a timestamp.

The current SCOUTz Microsoft 365 security workflow schedules 69 authenticated collector engines against a tenant, and I think of each one as a question the owner couldn't have answered honestly. Who actually has admin rights, including the accounts everyone forgot. Which applications hold standing permissions to read mail. Whether the MFA policy everyone assumes is universal has exceptions carved into it. What the tenant is spending against what it's using.

The gap between what owners believe and what the config shows is the most reliable thing I've seen in this business. Every scan surfaces at least one "that can't be right" moment, and it's always right, because config doesn't misremember. I've watched an owner insist his company had six third-party apps connected, then read a list of forty-one. He wasn't dishonest. He was answering from the only place he could, which was his own head.

For MSPs, this gap is the entire opportunity. You're not selling protection against hypothetical hackers. You're selling something more basic: replacing guesses with answers. Every business owner is currently attesting to things they cannot verify, on documents with legal and financial consequences. Show up as the person who can turn "I think so" into "here it is, in writing," and you've made yourself hard to replace.

The questionnaire isn't going away. The guessing can.