Operational recovery for AI-agent incidents in Microsoft 365.
KavachIQ runs downstream of your detection layer. When an agent's actions land — across Entra, SharePoint, OneDrive, Exchange, Teams, Conditional Access, and DLP — KavachIQ attributes every change to the agent's session, proposes an identity-first reversal plan, and validates the result after operator approval.
Incident to recovery flow
See agent-driven change move through identity, data, and recovery.
Platform overview
Where KavachIQ sits in your stack.
Three layers, three jobs. KavachIQ is the layer you don't have yet.
Detection
Microsoft Purview AI Observability, Defender for Cloud Apps, Microsoft Sentinel, Zenity, WitnessAI.
Tells you something happened.
Alert source for KavachIQ.
Backup
Microsoft 365 Backup, Rubrik, Cohesity, Veeam.
Restores data to a point in time.
Complementary — different blast radius, different remediation.
KavachIQ
Operational recovery of the specific configuration and access changes an AI agent made.
Reverses only the agent's actions, in dependency order, with operator approval.
The missing layer between detection and trusted state.
Detection vendors and backup vendors are partners, not competitors. KavachIQ runs between them.
The recovery surface
What KavachIQ recovers across your Microsoft 365 tenant.
Every agent-driven change in scope, mapped to the Microsoft surface it lives on. Recovery is dependency-ordered across all five.
Surface
Examples of agent-driven change KavachIQ handles
Identity
Entra ID
User membership in privileged groups · App registration and service principal ownership · Role assignments · Identity lifecycle changes
Conditional Access
Entra ID
Policy scope changes · Exemptions added · Sign-in risk thresholds modified · MFA bypass conditions
Permissions
Graph + M365
Microsoft Graph delegated and application permissions · Site-level and item-level access grants · OAuth consent grants
Sharing
SharePoint · OneDrive · Teams
External sharing links · Anyone links · File and folder permissions · Teams channel sharing
Data
Purview · Sensitivity labels
DLP label modifications · Sensitivity label changes · Retention label changes · Content policy alterations
KavachIQ attributes each change to the agent's session. Reversal happens in identity-first order. Operators approve, then KavachIQ executes and validates.
Agentic Identity Recovery for Microsoft Entra.
The control plane is the highest-leverage place for an agent to do damage.
When an AI agent changes a user, modifies a group, alters an app registration, adds a service principal owner, or updates a Conditional Access policy, every downstream Microsoft 365 surface inherits the effect. A single service principal ownership change can expand access across the tenant. A single Conditional Access exemption can bypass MFA for an attacker's session.
KavachIQ scopes every identity change to the originating agent's session, models the downstream dependency graph, and proposes a reversal sequence that doesn't break the tenant — including not locking out a Global Admin, not invalidating active sessions, and not undoing legitimate changes that happened in the same window.
What KavachIQ handles
Users and groups
Membership in privileged groups, lifecycle changes, group ownership.
Apps and service principals
App registration creation and modification, service principal ownership, credential additions, OAuth consents.
Conditional Access
Policy scope and conditions, exemptions, sign-in risk thresholds, named locations.
Roles
Directory role assignments, eligible vs active assignments, scoped roles.
Recovery order
Identity first. Permissions next. Sharing and Data after.
What KavachIQ handles
SharePoint and OneDrive
External sharing links, site-level permissions, file and folder access grants, item-level overrides.
Exchange
Mailbox delegations, send-as permissions, inbox rules, transport rule changes.
Teams
Channel and team membership, channel permission changes, guest access, app installations.
DLP and sensitivity labels
Label modifications, policy scope changes, exception rules, retention label changes.
Recovery posture
Coordinated with identity restoration, dependency-ordered, operator-approved.
Agentic Data Recovery for Microsoft 365.
Where agent damage shows up to end users.
Once identity is restored, the data and collaboration surfaces need their own coordinated recovery. An agent that added external sharing links to a SharePoint site, modified DLP labels on a finance folder, or changed Teams channel permissions has done damage that can't be reversed by snapshot restore without losing the legitimate changes that happened alongside.
KavachIQ reverses the specific agent-driven changes on data and collaboration surfaces — preserving everything else. Reversal is sequenced after identity is restored, so re-granting access in the wrong order doesn't reintroduce risk.
How the platform operates inside your tenant.
Same four-step flow as the homepage, with operator-grade detail.
Connect to your detection layer
KavachIQ ingests incident signals from Microsoft Sentinel, Microsoft Defender for Cloud Apps, Microsoft Purview, or your SIEM/SOAR. We run downstream of detection — your existing alert posture stays in place. Integrations are configured per tenant via Microsoft Graph and a webhook from your SOAR.
Map the blast radius
KavachIQ correlates the alert to the originating agent's session and walks the dependency graph across Entra ID, SharePoint, OneDrive, Teams, Exchange, Conditional Access, and DLP. Every change in the agent's window is attributed, classified, and graphed.
Propose an identity-first reversal plan
The plan is dependency-ordered: identity changes first, then permissions, then sharing and conditional access, then data. The graph respects what depends on what — so revoking access does not lock out a Global Admin, and undoing a share does not break an active collaboration.
Approve, execute, and validate
Your operator reviews the proposed plan and approves before any change is made. KavachIQ executes the reversal one step at a time and validates the result against expected state. The full operation — every step, every operator action — is recorded in an exportable evidence pack for the auditor, the board, and your post-mortem.
Trust and tenant safety
Built for tenant safety.
KavachIQ operates inside enterprise environments under operator and CISO oversight. The same four pillars as the homepage — with the control posture spelled out.
Approval-gated reversal
Every recovery is proposed for human review before any change. No automated rollback.
Platform control posture
Operators see the full proposed reversal — every step and its dependency — before any change runs. Approval is an explicit, scoped action; the platform does not act on its own.
Least-privilege Microsoft access
Scoped to what's required to attribute and reverse.
Platform control posture
Microsoft Graph access is admin-consented per tenant and scoped to the surfaces under recovery management. Detailed permission scopes are available for procurement review on request.
Tenant-scoped isolation
Strict per-tenant data boundaries enforced at the database layer.
Platform control posture
Tenant isolation is enforced at the data layer, with no shared tenant context across requests. Tenant-bound keys and access scopes prevent cross-tenant visibility.
Audit trail and evidence pack
Every step recorded with operator identity, timestamp, and outcome.
Platform control posture
Each recovery produces an exportable evidence record covering the agent's actions, the proposed plan, every approval, and the validated result — suitable for audit, SIEM ingest, and board reporting.
Recovery you can defend to your auditor, your board, and your own DFIR team.
Capabilities
What operators get.
What KavachIQ delivers to operators day-to-day.
Agent-session correlation
Every change in an agent's session is attributed back to it, with the supporting Microsoft 365 audit trail attached.
Cross-domain blast radius graph
Identity, sharing, permissions, Conditional Access, DLP, and data modeled as a single dependency graph per incident.
Dependency-ordered reversal plans
Recovery proposals respect what depends on what, so reversal does not leave the tenant in an inconsistent state.
Operator approval workflow
Plans are proposed for review, not executed automatically. Operators approve before any change is made.
Post-reversal validation
Each step is checked against expected state and any mismatch is surfaced before sign-off.
Exportable recovery evidence
A complete, exportable record of every operation, suitable for audit review, SIEM ingest, and board reporting.
Detection-layer ingestion
Subscribes to your existing detection (Microsoft Sentinel, Defender, Purview, or your SIEM/SOAR) as the alert source.
Documented Microsoft Graph access
Scoped, admin-consented per tenant; detailed scope inventory available on request.
Tenant-scoped isolation
Per-tenant data and access boundaries enforced at the data layer, with tenant-bound key material.
Audit-grade incident timeline
A chronological record of agent action → ingestion → mapping → approval → reversal → validation, anchored to verifiable enterprise identity.
Roadmap
Microsoft 365 today. More agent surfaces over time.
KavachIQ's recovery model extends past M365 — but only after we've earned the right.
Stage
What it covers
Status
Today
Microsoft Entra + Microsoft 365 (SharePoint, OneDrive, Teams, Exchange, Conditional Access, DLP)
ShippedQ3 2026
Copilot Studio agents · Entra Agent ID coverage · Custom-agent attribution via Microsoft Graph
In progressLate 2026
Salesforce Agentforce · ServiceNow Now Assist · Adjacent agent platforms
On the roadmapEach platform earns its place by depth, not breadth. We do Microsoft 365 better than anyone before we add anything else.
Walk through the platform with us.
We'll show you how KavachIQ runs inside a Microsoft 365 tenant — alert ingestion, blast radius mapping across all five surfaces, identity-first reversal proposal, operator approval, validation, and the evidence pack. Bring a scenario; we'll walk it.
In the demo, you will see
An agent-driven change in Microsoft 365, blast radius mapped across identity and sharing, and an operator-approved dependency-ordered reversal that restores trusted state
What you will walk away with
A clear picture of how KavachIQ proposes, approves, and validates recovery — with an exportable evidence trail for audit and the board
Request a demo