Drift governance

Know when your tenant stops matching what you approved

Dredd holds an estate against a configuration you approved — one you declared, or one you captured from a tenant you already trust. Every change that was not approved becomes a finding with exactly two answers: revert it, or ratify it into the baseline. It is configuration governance rather than posture scoring — the question is not whether a setting is wise, but whether it is what you decided.

Under development Still being written

Real work is still happening on this one. It is not available, it carries no list price, and there is no date — a date invented to fill this space would be the first thing on this site you could catch us out on. Ask, and you will get an honest read on where it is.

Why it matters

Most of what looks wrong in a mature tenant is not wrong. It is unexplained. A setting was changed for a reason that made sense during an incident, by an administrator who has since moved on, and no record survives of whether anyone agreed to it. A posture score cannot settle that. It can say whether a value matches a general standard, and a great deal of deliberate, correct, business-specific configuration does not.

The question asked at an audit, at an incident review, and in an administrator's first week is narrower: is this what we decided? SOC 2 and ISO 27001 both expect change control over the systems in scope, and a tenant where any sufficiently privileged account can change anything with nothing recording whether the change was approved is precisely the gap those questions are aimed at. Microsoft's audit log will tell you a value changed. It will not tell you the change was allowed.

What it does

  • A baseline, declared or captured — write the approved configuration down, or take a tenant you already trust and capture its live state as the first version. Either way the result is a versioned artefact with an author and a date, rather than a shared understanding that leaves when the person holding it does.
  • Drift, field by field — the live estate is compared against that baseline, and a finding names the setting, the approved value, the current value and when the two parted company. "Something changed" is not a finding; it is a reason to go looking, and going looking is the work this exists to remove.
  • Exactly two answers — revert it, or ratify it into the baseline. There is no third state where a difference sits acknowledged on a dashboard for a year. Closing a finding either restores the approved configuration or changes what "approved" means, and both are decisions somebody makes on the record.
  • Ratification moves the baseline forward — as a new version, with an author and a reason. "Was this approved?" is then answered by a record rather than a recollection, which is the part a change-control question actually turns on.
  • Reverting writes to your tenant — approval-gated, and a separate opt-in on top of the product's own admin consent. Dredd is one of the products that changes your estate rather than only reporting on it, which belongs on the page you read before buying and not in onboarding.
  • One baseline, many tenants — hold a whole client book against the same approved configuration, and ratify a client's legitimate exception against that client instead of relaxing the baseline for everyone else.
  • Findings that leave the product — control-tagged into the shared findings store, so drift from an approved configuration can be read as change-control evidence in CompliancePortal and rolled up in PosturePortal rather than collected a second time by hand. Neither of those has shipped either.

What it will not do

It will not tell you your baseline is a bad one. Ratify a weak configuration and Dredd holds the estate to it without complaint — that is the whole bargain, and it is the difference from SecurityPortal, which scores the same estate against a published standard and has opinions for a living. Running one without the other leaves a real gap in either direction: a tenant that faithfully matches an unwise baseline, or a tenant that scores well and is nothing like what anyone signed off.

Coverage is narrower than "your tenant", and naming it is more use than implying the rest. Microsoft Entra ID is the control plane it is being built against. Microsoft 365 tenant configuration and Intune are designed and not written, and until they are, drift in them is drift Dredd cannot see.

A baseline only covers the scope you put in it. An empty finding list means nothing changed in what you asked to be watched — never that nothing changed. What sits outside the monitored scope is not quietly passing; it is not being looked at, and the product will say which of the two it is.

Capability and what you get from it

CapabilityWhat you get from it
A baseline you declare or captureThe approved configuration exists as an artefact with a version and an author, not as an assumption
Comparison of the live estate against itDrift arrives as a finding, rather than at the next review or after the incident
Field-level findingsWhat it was, what it is, and when it changed — enough to act on without opening an investigation first
Two answers, no thirdA difference ends as a revert or as a decision; nothing accumulates as "acknowledged"
Ratification as a versioned change"Was this approved?" is answered by a record with a name and a date on it
Approval-gated revertThe approved configuration is put back in-product, after somebody approves it, rather than automatically
One baseline across many tenantsA client's legitimate exception is ratified for that client instead of loosening the baseline for the whole book
Control-tagged findingsChange control becomes evidence downstream instead of a second collection exercise

Tell us what you would want held to a baseline

Dredd will be quoted rather than listed. Its unit is monitored configuration scope, which is the metric this pricing model understands least, and it is being sized against real estates rather than guessed at from a spreadsheet. Describe the scope you would want watched and you will get an honest read on where the product actually is — which is worth more than a date we would have to invent.