# Sightline — Microsoft 365 Compliance Visibility for MSPs

> Continuous Microsoft 365 posture across every customer tenant an MSP manages, with seven assessment frameworks, 556 mapped controls, reviewable remediation, and client-ready evidence.

**Canonical URL:** https://www.aixccelerate.com/platform/sightline

## What Sightline does

Sightline connects through Microsoft Partner Center GDAP or direct app registration, discovers managed customer tenants, and runs daily or on-demand read-only posture assessments. It never changes a tenant automatically. Failed controls become reviewable remediation playbooks, effort estimates, and scoped work for a human team to approve and execute.

## Framework coverage

- CISA SCuBA — 108 controls
- NIST CSF 2.0 — 100 controls
- CMMC 2.0 — 113 controls
- HIPAA Security Rule — 60 controls
- CIS Microsoft 365 Foundations — 81 controls
- US Cyber Insurance Readiness — 50 controls
- Microsoft 365 Copilot Readiness — 44 controls

Total: 556 mapped controls across seven frameworks.

## Built for MSP operations

- GDAP-native customer discovery
- Cross-tenant portfolio posture and risk tiers
- White-label reports, remediation playbooks, evidence packs, and scopes of work
- Configuration-change history and expiring attestations
- Webhooks and a versioned REST API for PSA, RMM, and BI integration
- Ask Alex, an AI advisor that explains findings in plain business language

## Deployment and control

Sightline is designed to deploy in the MSP's Azure subscription and use Microsoft Entra ID plus Partner Center GDAP. Assessment behavior is strictly read-only. Remediation is delivered as reviewable scripts rather than executed autonomously.

## Important qualification

Sightline assesses Microsoft 365 configuration and does not replace a formal compliance audit, certification, accreditation, legal review, C3PAO assessment, or HIPAA risk analysis. Framework mappings are directional guidance. Insurance evidence supports broker conversations; coverage decisions remain with the carrier.
