MSP-safe Microsoft 365 automation, built for trust
Automation only earns trust when it is safe. Avvi is built around approval controls, least-privilege access, full audit logging, and strict isolation between every client tenant.
Aligned with SOC 2 controls
SOC 2 is an AICPA examination framework covering Security, Availability, Processing Integrity, Confidentiality, and Privacy. Avvi uses these categories to organize its control posture. Avvi is aligned with SOC 2 controls; it has not completed an independent SOC 2 examination and is not SOC 2 certified.
Least-privilege access control via GDAP and fine-grained permission toggles, with no standing Global Administrator access and encrypted secrets.
Strict isolation between every client tenant, with least-privilege access throughout.
Role-based approvals and controlled execution, recorded in a full audit trail.
Every action stays bounded by MSP-controlled permissions assigned to the requester.
Durable long-term retention of action records. Uptime specifics on request.
Avvi is aligned with SOC 2 controls. This describes Avvi’s current control posture only; it is not an independent audit report, attestation, certification, or verification.
The controls behind every action
Avvi is designed so the safe outcome is the default one, across every tenant you manage.
Multi-tenant by design
Manage every client tenant from one place through GDAP, with strict isolation between them.
Four-level permission hierarchy
Granular control over who can do what, across every tenant.
least-privilege access controls
Access is verified and scoped to what each user is permitted.
Full audit logging
Every action is recorded with the confirmation and relevant action details for review and accountability.
Encrypted secrets management
Credentials and secrets are protected with industry-standard encryption, centrally managed.
Long-term retention
Audit records are retained for 400 days in the normal course and for seven years when maintained as compliance records.
How a safe request actually flows
Every request Avvi runs passes the same controls, in the same order. Nothing skips the line.
Ask in chat
A technician or an approved end user asks Avvi to run a Microsoft 365 task, in Teams or the web portal. No scripts to write, no admin console to open.
Delegated access with MSP controls
Avvi uses delegated GDAP admin access and limits each request through the permissions the MSP controls for that user.
Least privilegeYes or No confirmation before every action
Actions that warrant a second set of eyes route through a role-based approval before anything executes.
Role-based approvalControlled execution
Once cleared, Avvi performs exactly the requested task through Microsoft’s delegated APIs. It runs the specific task in front of it, nothing broader.
Logged and retained
The action is written to the audit trail with what changed, who approved it, and when, then retained as durable compliance evidence.
Full audit trailMulti-tenant isolation is the trust story
An MSP does not manage one Microsoft 365 tenant, it manages many, each belonging to a different client. Avvi manages them through GDAP with strict isolation between them, so one login never crosses a boundary it should not.
That isolation model is what lets you answer a security questionnaire without hedging. It is not a technicality, it is the product.
Read the multi-tenant guide →What Avvi can and cannot do in your tenants
Avvi does not sit above your Microsoft 365 environment with its own keys to everything. It acts through the delegated access you grant, scoped to the task in front of it, and it records what it did.
That boundary is deliberate. It keeps the answer to “what could this tool reach” short and honest.
See the security FAQ →Microsoft 365 security, the common questions
Is it safe to let AI automate Microsoft 365 administration?
How does Avvi access client Microsoft 365 tenants?
Does Avvi use Global Admin or standing admin access?
Is Avvi SOC 2 certified?
Are Avvi’s audit logs ready for a compliance review?
How does Avvi keep one client’s tenant separate from another?
What Microsoft 365 data can Avvi see?
Can an end user do more through Avvi than they are allowed to?
See safe automation for yourself
Book a walkthrough and watch Avvi run real Microsoft 365 work with approval controls, isolation, and a full audit trail.
