Changelog

What changed, when, and what it means for a scan.

Rule versions, validation runs and website changes, newest first. A new rule version never reaches a customer tenant until an operator approves that exact version. Entries dated 15 September 2026 were in place before the live validation and are dated to that milestone. RSS feed

Website updated

Repositioned around vendor-change impact, with Microsoft 365 as current coverage. Corrected the EWS validation timeline and added a validation note. Updated the EWS guide for Microsoft's phased disablement. Split security into platform safeguards and connector details. Made the pilot form more reliable.

Website published

Product, how it works, security, EWS guide and checklist, pilot request form, changelog.

Product screens captured

Screens captured from the running product: the demo workspace with sample customers, and Advina Labs' Microsoft test tenant.

EWS consent rule v2: controlled validation in Advina Labs' Microsoft test tenant

An operator granted an EWS application permission to a test application at 13:22:30Z. A product scan opened an Affected finding at 13:33:14Z. The grant was revoked at 13:41:29Z, and a later complete scan closed the finding and its task at 13:52:52Z. Microsoft reads were real; provider sign-in was simulated. Details

ews-retirement rule v2

EWS consent rule v2

Reads the Exchange Online service principal, the application-role assignments and delegated grants on it, and each matched holder. That is at least three Microsoft Graph requests, more with pagination, several holders or retries. Uses Application.Read.All and Directory.Read.All. An incomplete read is classified Unknown: it can never report Safe or close a finding.

ews-retirement rule v2

Rule approval bound to the exact version

An operator approves the exact rule version before it can scan customers. Approval is bound to the SHA-256 of the rule definition and a named reviewer, and recorded in the audit trail. Withdrawing approval stops customer scans.

Closure only by a later complete scan

No control resolves a finding by hand. Marking a task ready for verification records intent; the next complete scan that no longer finds the exposure closes the finding and the task together, attributed to impactfold.scan-engine.

Every pilot provider is told directly before a rule changes, and approves the new version themselves.