Bus-Factor Report

Small businesses have no idea who actually does what, and their directory is lying.

A read-only report from your Microsoft 365 tenant: the processes, systems, and mailboxes only one person touches, the job titles your directory gets wrong, and a printable continuity page per seat. Metadata only. Nothing is read from message bodies.

First reports ship in early 2027. One email at launch, nothing else.

The problem

Somebody in your firm is the only person who can do something that matters.

Payroll, the bank feed, the vendor portal, the one client system. Nobody wrote it down. The org chart says one thing, the directory says another, and you find out when that person is sick, on vacation, or gone. Insurers, banks, and buyers ask “who backs up X” and the honest answer is: we are not sure.

What you get

Three pages an owner actually keeps.

Single points of failure

Every system, vendor, shared mailbox, and recurring meeting that exactly one person owns or touches, with no observed backup.

Directory drift

Job titles and group memberships that disagree with what people actually do. Directory says, activity says, confidence.

A continuity page per seat

What only this person covers, what others also touch, and what stalls in a two-week absence. Printable.

What a finding looks like

Bus factor: how many people can carry each thing.

ObjectPeopleWhat we saw
Vendor payments mailbox1Only the office manager has ever sent from it.
Payroll provider portal1One owner in the app registry, no backup listed anywhere.
Client onboarding checklist site1Single site owner, last touched by anyone else 14 months ago.
Monthly close meeting2Organizer plus one recurring attendee. Covered, barely.

Illustrative rows. Every real finding carries its evidence, a confidence grade, and the date it was observed. Absence of evidence is reported as a gap, never as safety.

How it works

Read-only. Metadata only. Nothing kept.

Step 1

One consent click

A Global Admin (you or your IT provider) approves a read-only connection to your Microsoft 365 tenant. The scopes are listed on the consent screen and can be revoked any time.

Step 2

A metadata scan

We read who is in which groups, who owns which mailboxes and sites, who organizes which recurring meetings, and who emails whom, by header only. Never a message body.

Step 3

Your report, then deletion

You get the single points of failure, the directory drift table, and a continuity page for every seat. The tenant data is deleted once the report is delivered.

Read the full data-handling statement.

Simple pricing

$199.00 per report

One tenant, one dated report, every seat included. Re-run later for less. IT providers: ask about the ten-tenant pack.

Questions

Straight answers.

What do you read?

Directory attributes, group and Teams membership, mailbox and calendar metadata (who, when, how often), SharePoint and app ownership. Never message bodies or attachments.

What do you keep?

Nothing. Tenant data is processed in memory, the report is delivered, and the data is deleted.

Who can run it?

Anyone with Global Admin on the Microsoft 365 tenant, or their MSP. One consent click, read-only scopes, revokable any time.

What if the report finds nothing?

Then you have a documented continuity position, which is what an insurer, bank, or buyer will ask for anyway.