Product

TrueRock OutCrop

TrueRock OutCrop is the MSP's workspace in TrueRock.AI: one view across every client's Microsoft 365 tenant, ranked worst-first. Every finding carries its evidence and its fix.

See your own Microsoft 365 exposure

What it does

Shadow AI + agent governance
Find and risk-score every AI app, browser extension and autonomous agent touching the tenant — including the Copilot Studio and Power Automate agents clients build themselves.
AI Watch — Governed AI Safety Report
One per-client report of every AI touching the tenant — the governed lane in full, Microsoft Copilot via the audit log, and shadow-AI traffic on every managed device — with the right label applied so the AIs you can’t watch still can’t read what they shouldn’t.
Find sensitive data (classification)
Automatically read the content of files and mail and classify what’s sensitive — PHI, PII, financials, contracts — without anyone labeling it first.
Data exposure + blast radius
Map who — and what — can reach classified data: the people, apps and agents that can read, write or exfiltrate it, and the reach an attacker inherits.
Remediate exposure
Close the leak: revoke risky external shares, apply the exact protecting label, and stand up DLP on the data types actually found.
Conditional Access enforcement
Verify the sign-in policies that keep accounts safe — MFA, device trust, blocking legacy auth — actually cover every user.
Device compliance (Intune / Defender)
Confirm every managed device is encrypted, patched and antivirus-healthy — with a ranked queue of what to fix first.
Compliance mapping + client-ready reports
Map a client’s real configuration to the controls that matter across CIS for Microsoft 365, HIPAA, NIST CSF, ISO 27001 and Essential Eight, and produce the branded, cited evidence pack. Compliance splits into what a machine can prove and what people must attest — this is the first part, delivered whole: every control counted against the framework’s total and traceable to the signal behind it.
Assess — AI readiness + threat intel
Score whether each tenant can safely turn AI on — six dimensions from labeling to oversharing to DLP-for-AI — and surface the CVEs that actually threaten each client, ranked by real exploitability.
AI-governance maturity + next best step
Place each client on the journey from ad-hoc AI use to a governed AI estate — Land, Ground, Automate, Connect — and name the one thing to fix next to move up a level.
Licensing advisor + daily change tracking
Read every tenant’s licensing to reclaim waste, close security gaps, right-size seats and drive adoption — and track what changed each day — as advice, not an upsell.
Automate — Skills
Author a cited report once and run it the same way on every client — the MSP writes the generator, every technician runs it identically.
Onboard the whole book in one consent
One GDAP-native admin consent registers every client you manage, you pick a pilot tenant, and a plan quota caps spend before the first scan runs.
First-Look assessment for a prospect
Run a read-only assessment of a prospect’s Microsoft 365 under the access they grant, and hand them a result that says what was examined, what was not, and why — with no overall score invented from partial evidence.
Findings into your PSA, as tickets
Turn findings into tickets in the PSA your service desk already lives in — ConnectWise, Autotask or HaloPSA — routed to the right board by severity and control, without anyone re-typing them.
Portfolio cockpit — every client, ranked
The whole book on one screen: every tenant ranked worst-first by risk, and every metric opening onto the client most affecting it and the root cause they share.

Watch it work

See your own Microsoft 365 exposure