MONOKEL
Security Exposure Intelligence

Understand what
you’re exposed to.

Monokel brings security observations from identities, applications, devices, sharing, cloud and external exposure into one explainable view — so you can understand what matters, and why.

Read-only accessRunning in minutesNo agents to deploy
Environment
Aldervik AB · Last observation today 09:12
9 open findings1 domain not yet verified
IdentityRisk
3 open findings
ApplicationsRisk
4 open findings
SharingRisk
2 open findings
DevicesOK
No open findings
CloudUnknown
Not enough evidence yet
External ExposureOK
No open findings
High
Applications hold privileged access that is not being used
Applications · 27 affected applications
Details →

Signals make more sense together.

Security data lives across identities, applications, devices, sharing, cloud and the public internet. Each admin portal shows its piece. Exposure only becomes understandable in context.

IdentityApplicationsSharingDevicesCloudExternal Exposure
Monokel
ExposureContextChange

Monokel brings those observations together into one security understanding — a decision layer above your security data, not another console to operate.

Start with your environment.

The Environment is Monokel’s primary view. It answers the questions that actually matter.

What does the environment look like?
Inventory and security state across every connected domain, in one place — not scattered across admin portals.
What is creating exposure?
The observations that matter, explained in context — not a raw stream of alerts.
What has changed?
Differences between observations over time, so drift is visible instead of silent.
What can be verified?
And what can’t. Where evidence is missing or incomplete, Monokel shows UNKNOWN — never a green checkmark.

Security domains, not product silos.

Each domain holds inventory, observations, findings and changes — with the evidence behind them.

🔐
Identity
Accounts, privileged roles, access policies and authentication posture.
🔑
Applications
OAuth grants, app permissions, credentials and how access is actually used.
📁
Sharing
External sharing, public links, guests and collaboration exposure.
💻
Devices
Device compliance, endpoint protection status and management coverage.
☁️
CloudExpanding
Cloud subscriptions and resources, and the exposure they create.
🌐
External Exposure
Domains, certificates, email authentication — what’s visible from the outside.

Providers and domains are different things: Microsoft Entra feeds Identity and Applications, SharePoint feeds Sharing, Intune feeds Devices, Azure feeds Cloud, DNS and TLS feed External Exposure. The domain picture grows as coverage grows.

Findings you can reason about.

Monokel groups related observations into findings — prioritised by severity and explained with evidence — instead of overwhelming you with individual alerts.

HighSharing · 4 affected sites
Externally shared sites owned only by inactive accounts
What was observed
Four sites with active external sharing links are owned solely by accounts that show no recent sign-in activity.
Context
Site ownership and account activity are separate observations. Together they show external access that no active owner is accountable for.
Why it matters
The sharing stays live while no one is left to notice it, question it or remove it.
Where to address it
SharePoint admin center.
One pattern, one finding
A risky pattern affecting 27 applications is one finding with 27 affected applications — not 27 independent alerts.
Severity and priority
Every finding carries a severity — Critical, High, Medium or Low — and is prioritised so you know where to start.
From finding to control
Each finding points to where the underlying control lives — Entra, Intune, Defender, your DNS provider — so action happens in the system that owns it.

Exposure is not static.

Monokel compares observations over time, so you can see what changed — and what the picture looked like when a decision was made.

Since previous observation
Sign-in policy exclusion added for an admin accountIdentity
New organisation-wide sharing link on a finance siteSharing
Application granted broader API permissionsApplications

Monokel is observation-based, not a real-time stream. Every claim is anchored to what was observed, and when — which also means the history stays explainable.

Knowing what you don’t know matters.

Monokel distinguishes observed safety from insufficient evidence. Three states, told honestly.

OK
Supported by evidence. Monokel observed the control and can show what it saw.
Risk
Something observed creates exposure. Explained with evidence and context, so you can judge it.
Unknown
Not enough evidence to make a claim — and Monokel says so. Missing data never becomes a green checkmark.

Most tools quietly treat what they can’t see as fine. Monokel treats it as a fact worth knowing.

Running in minutes.

No agents. No infrastructure changes. Read-only.

01
Connect your environment
Grant read-only consent. Nothing to install, nothing to change.
02
Monokel observes and structures
Security observations are collected across identities, applications, devices, sharing and external exposure — and structured into one model, with a record of what was seen and when.
03
Understand what matters
Exposure, context and change — with findings you can explain and evidence you can point to.
For MSPs & IT Partners

Every customer environment, understood the same way.

A consistent security understanding across customers — exposure, findings, changes and environment health — without reconstructing the picture from admin portals, tenant by tenant.

One consistent picture
Every customer environment described the same way: exposure, findings, changes and what remains unverified.
Grounded customer conversations
Findings with severity, affected entities and evidence — not screenshots from six portals.
Change since last time
See what changed in each environment between observations. Useful for recurring reporting.
Nothing to deploy
Read-only access per customer environment. No agents, no infrastructure.

Where the observations come from.

Microsoft 365 is Monokel’s deepest integration today. Provider support is expanding — deliberately.

Available today
Microsoft Entra ID
Identities, applications and access policies
SharePoint & OneDrive
Sharing and collaboration exposure
Microsoft Intune
Device posture and compliance
Microsoft Defender
Endpoint protection signals
DNS · TLS · Email auth
External exposure of your domains
Being expanded
Microsoft Azure
Cloud subscriptions and resources
Google Workspace
Identity and collaboration

Providers are data sources. Domains are how Monokel structures what it learns. Monokel is not conceptually tied to one vendor.

FAQs

What access does Monokel need?+
Read-only. Monokel reads configuration and security signals from the environments you connect, and never modifies anything.
Does Monokel fix issues for me?+
No — deliberately. Remediation happens in the systems that own the controls: Microsoft Entra, Intune, Defender, Azure, Google Workspace, your DNS provider. Monokel tells you what you’re exposed to, why it matters, and where the control lives.
Is Monokel only for Microsoft 365?+
Microsoft 365 is the deepest integration today — Entra, SharePoint, OneDrive, Intune, Defender — alongside external exposure of your domains. Azure and Google Workspace support is being expanded. The model isn’t tied to one vendor.
How is this different from Microsoft Secure Score?+
Secure Score tracks configuration posture within Microsoft’s products. Monokel builds an explainable picture of exposure: what was observed, why it matters, what changed, and what can’t currently be verified — including what’s visible from outside your organisation.
What happens when Monokel can’t verify something?+
It says so. Where evidence is missing or incomplete, Monokel shows UNKNOWN rather than assuming safety. Missing data is never presented as a green checkmark.
Do I need a security background to use this?+
No. Every finding explains what is happening, why it matters and what is affected in plain language. Built for IT leads and decision makers, not SOC analysts.
Does this work for multi-tenant / MSP setups?+
Yes. Monokel supports multiple customer environments with per-environment views and a consistent way to understand exposure across all of them.

Know what you’re exposed to —
and why.

Connect read-only and see what the evidence shows.

Open the product
Read-only accessFree to tryRunning in minutes