Know which vendor changes affect your customers. Track the fix. Verify the outcome.

Impactfold helps service providers connect vendor changes to evidence in customer environments, prioritise action, and track remediation through verification.

Current coverage Starting with Microsoft 365. Built around a vendor-agnostic model, with additional connectors and checks added as they are validated.

  1. Vendor changeAn announcement that can affect customers
  2. Approved ruleWhat evidence means exposure
  3. Customer evidenceRead from each connected environment
  4. FindingA classification per customer, with its evidence
  5. Remediation taskAssigned, tracked, done by your engineer
  6. Verified closureOnly after a later complete scan

Microsoft 365 Current coverage

Further vendors Added only once validated. None available yet.

The recurring problem

Vendors announce changes. Providers still have to work out which customers they affect.

The announcement is the same for everyone. The work is not: an engineer has to check each customer environment, find the objects involved, fix them and show the customer it is done. Then the next change arrives.

APIs

Interfaces retired or changed, such as a legacy mail API an integration still calls.

Authentication

Sign-in methods and protocols withdrawn or tightened.

Permissions

Consent models and permission scopes that change what applications may do.

Configuration

Defaults and settings a vendor changes on its own schedule.

Product behaviour

Features that start working differently for existing customers.

These are the kinds of change Impactfold is designed for, not a list of checks available today. A change becomes checkable only when a rule for it has been validated. Today there is one: EWS application consent in Microsoft 365.

One workflow, reused for every change

From the vendor's announcement to a closure you can show the customer.

  1. Connect

    Each customer's administrator grants the connector read-only access. Nothing is written to their environment.

  2. Collect

    An approved rule defines which evidence to read. Every request's outcome is recorded, including the ones that fail.

  3. Interpret

    The same rule classifies each customer: Affected, Likely affected, Needs manual review, Safe for this change, or Unknown. The evidence stays attached to the result.

  4. Assign

    Findings become remediation tasks with an owner and a due date. Your engineers make the change under their own access.

  5. Verify

    A later complete scan that no longer finds the exposure closes the finding and the task. Nothing else can.

How each step works today

Current coverage

Microsoft 365 first. Other vendors when they are validated.

Available in the pilot

  • A Microsoft 365 connector: application-only, read-only Microsoft Graph permissions, granted by each customer's administrator.
  • One detection rule: applications consented to Exchange Web Services (EWS) permissions in Microsoft Entra.
  • Portfolio overview, per-customer results, findings, remediation tasks and an append-only audit trail.
  • Scans started by an operator, with every result kept in the customer's history.

Not available today

  • Connectors for any vendor other than Microsoft.
  • Microsoft checks other than EWS application consent.
  • Scheduled or continuous scanning.
  • Changes made to customer environments. Impactfold does not remediate.

Proof: one controlled validation

Finding, human fix, re-scan, verified closure: run in Advina Labs' own Microsoft test tenant.

16 September 2026, EWS consent rule v2. The permission was granted and revoked on purpose, so the product had a real exposure to find and a real fix to verify.

  1. Test setup: an operator grants an EWS application permission to a test applicationtenant change · operator
  2. Product scan reads the tenant and opens a finding: Affected, with the grant as evidencereal Microsoft read · scan engine
  3. Remediation task created and marked ready for verification. Nothing closes.operator
  4. The grant is revoked in Microsoft Entra: the human fixtenant change · operator
  5. A later complete scan finds no EWS grant and closes the finding and the taskreal Microsoft read · scan engine

Every Microsoft read was real. The provider's own sign-in to Impactfold was simulated for this run. Two independent Azure CLI reads agreed with the product: grant present, then grant removed. It is one run in a test tenant, not a customer result. Read the validation note: what was configured, observed and verified, and its limits.

Where to go next

Start from the question you have.

Questions

Asked first, answered plainly.

Is Impactfold an EWS checker?

No. Impactfold is built around a vendor-agnostic model: vendor change, detection rule, customer evidence, finding, remediation and verified closure. Microsoft 365 is the first connector, and EWS application consent is the first check validated against a real tenant. Other checks and vendors are added only when they have been validated, and none is available yet.

What does the Microsoft 365 connector need?

Three read-only Microsoft Graph application permissions: Organization.Read.All to verify the connection, and Application.Read.All and Directory.Read.All for the EWS consent check. Each customer's own administrator grants them to the connector application registered for your pilot. Full detail.

Does a finding prove an application is using EWS?

No. The EWS check reports consent recorded in Microsoft Entra. Microsoft Graph does not expose EWS traffic, so actual usage is established separately, for example from Microsoft's EWS usage report, and every result says so.

What happens when a scan cannot read everything?

The result is Unknown, with the reason shown: permission denied, stale data or collection failed. A run that is interrupted records no result at all. Neither can report Safe, and neither can close a finding.

Can someone close a finding by hand?

No. An engineer marks the task ready for verification. Only a later complete scan that no longer finds the exposure closes the finding and its task, and the closure is attributed to that scan.

Does Impactfold scan automatically?

Not today. Scans are started by an operator. Every scan, finding and verified closure is kept in the customer's history, so each re-check adds to the record.

What does a pilot cost?

Scope, duration and total cost are agreed in writing before any customer tenant is connected. How pilot terms are set.

A supervised pilot on customers you manage, with scope and cost agreed before any tenant is connected.