NO GUARANTEE. This package gathers and structures evidence, control by control; it documents your posture, it does not prove your agents are secure and is not a guarantee of any security outcome. It is a verification aid, not security, legal, or compliance advice. READ-ONLY ASSESSMENT SCRIPTS BY DESIGN. The four assessment scripts inspect posture and make no configuration or data changes; we do not ship attack or destructive-test scripts. That is the AI-prepares-humans-decide boundary as a feature: the tool prepares the finding, a human decides and acts. The verification kit's behavioral probes (the prompt-injection test and the destructive-action gate test) are different: they are active tests that send live prompts and can trigger agent actions, so run them against a non-production or explicitly consented agent, never blind against production. Refund expectation, stated up front so you can self-select out: this is a governance and verification reference for a security function, not a red-team toolkit. If you came for a script that deletes mail, changes a permission, or exercises an attack, this product does not ship one by design. When your security function has to defend a Copilot agent rollout to a board or a risk committee, one lead running a checklist is not enough. The people around that lead need the same source-cited account of what secures an agent, the same evidence of what defensible audit output looks like, and a license that covers everyone in the organization who needs it, with no seat count for anyone to track. This is that package: everything in the Core verification kit, plus the depth and the uncapped internal-use org license a security function needs. The audit instrument is the same control-by-control centerpiece as Core: the T1 to T8 verification kit, the mailbox-wipe board one-pager, and the four read-only assessment scripts plus the free sample as accelerators. On top of it, the Team tier adds the reference layer. The deep-research dossier runs to 30 typeset pages and roughly 10,000 words across seven chapters, carrying 56 numbered footnotes drawn from 28 named primary sources, so every load-bearing claim lands somewhere you can check it. The threat-to-standards crosswalk ships as a filterable workbook you drop straight into a risk-committee pack; its mappings are interpretive crosswalks, not primary facts. Sample audit-log artifacts show what defensible Purview evidence looks like so your team can build detections against it. A 52-row citation workbook lets any reviewer trace a claim back to its authoritative source (Microsoft Learn, MSRC, NVD, OWASP, MITRE, or NIST), with the EchoLeak CVE cited to its NVD record, the 9.3 Critical score attributed to Microsoft as the CNA and NVD's own 7.5 base score named alongside it. Everything is stamped and vendor-neutral: the documentary claims as of July 2026, the live-tenant measurements as of 15 to 18 August 2026, each dated in place so you can see which kind of evidence you are reading. Microsoft is cited as a source and never cheered; each control carries its residual risk. The governance position holds across every artifact: AI prepares, humans decide, which is the feature that keeps a destructive action behind a human. Every script inspects posture and makes no configuration or data changes. See it before you buy Gumroad has no file-preview mechanism, so rather than ask your team to take the read-only claim on trust, three of the files below are in the FREE Lite bundle instead. It is a $0 download on this same store, so your team can read them, and run the sample script in your own tenant, before you spend anything here: the FREE sample script sample-list-agent-identities-v1.ps1, which lists Entra Agent IDs and flags any with no named, active sponsor; the per-script sample outputs, showing what each script prints across the four assessment scripts plus the free sample. These are constructed illustrations rather than captures of a live tenant, on the fictional Northwind Grid Services tenant with no real data, and the verdicts, flag wording and column layout are reproduced exactly as the scripts emit them; the required-reader-roles matrix, which names the exact least-privileged READ scope each script needs. Get the free bundle first if that matters to you. It is on this same store, free, listed as Agent Security Verification Checklist for Microsoft 365 Copilot (Lite). The August tenant run Named here with its limit in the same breath, because it is the only real measurement in this package. The author ran every PowerShell script in this bundle, the three PowerShell assessment scripts plus the free sample, end to end against a purpose-built Microsoft 365 E5 tenant, with seeded canaries and with ground truth recorded out of band, from a separate administrator session, before each run. One tenant, one operator, and that operator is the author, 15 to 18 August 2026. That run found defects in the kit's own scripts and those defects were fixed before this went on sale, which is the whole of the claim: a process claim about how the package was built, never an assurance claim about your agents, and nobody outside has looked at any of it. Three limits travel with the name, and one Team-only artifact comes out of the same run. The fourth assessment script, the KQL query pack, was evaluated against records captured from that tenant rather than executed in Log Analytics, so "this query cannot return a row against this record shape" is established and "this query returned zero" is not. The sample outputs shown above stay constructed illustrations rather than captures; the one file in this package that is a real capture is sample-audit-log-artifacts-v1.json, redacted from Purview records that tenant emitted on 17 August 2026 and labelled as such. And the two dates do not merge: documentary claims are current as of July 2026, only the tenant measurements are 15 to 18 August 2026. The item-by-item bound list, including everything the run never touched, is in "What this kit does not prove", which the free tier also ships so you can read it before paying anything. What's inside Everything in the $69 Core tier, plus the Team reference layer: The Verification Kit, full T1 to T8 (PDF and Markdown): eight per-control test cards, numbered T1 to T8 consistently with the scripts (T1 prompt injection, T2 identity, T3 least privilege, T4 destructive-action gate, T5 DLP, T6 oversharing, T7 audit, T8 grounding), each with what-to-test, steps sourced to Microsoft Learn, then PASS/FAIL/Fix, a standards anchor, plus result tables, with the crosswalk as a static in-kit table. The mailbox-wipe board one-pager (PDF and Markdown): the five load-bearing controls in order, and the two the board should not count on. The four read-only assessment scripts plus the free sample with their run guide, required-reader-roles matrix, per-script sample outputs, and a checksum manifest: assess-agent-inventory-v1.ps1 (T2 inventory), assess-least-privilege-v1.ps1 (T3 least privilege / over-privilege), assess-audit-signals-v1.kql (T1 and T7 signals), assess-dlp-copilot-policy-v1.ps1 (T5 DLP posture), and the FREE sample sample-list-agent-identities-v1.ps1. The scripts ship as scripts; the run guide, the matrix and the sample outputs each ship as a typeset PDF as well as Markdown, so you can circulate them to people who will never open a terminal. The deep-research dossier agent-security-dossier-v1.pdf: a 30-page, roughly 10,000-word typeset reference, 56 numbered footnotes across 28 named primary sources. Seven chapters, each one a claim a security function has to be able to defend: filtering is probabilistic and not a boundary; confirmation prompts are configurable and not enforced; the per-tool gate defaults off while maker credentials overshare; delegated access is bounded by the user and app-only is not, including the additive-grant trap; agent inventory has four populations rather than one; data governance governs reading while audit records attribution rather than a transcript; and the human-decides boundary is the control that does not depend on luck. An introduction opens it and a residual-risk section closes it, naming where the boundary actually sits. Every chapter runs the same spine: the claim, why it matters, the Microsoft evidence, the standards anchor, the limit, and the operational consequence. The PDF carries a 51-entry bookmarked table of contents. The Threat Model and Standards Crosswalk, filterable threat-standards-crosswalk-v1.xlsx: the eight-threat mapping from OWASP LLM Top 10 2025 to MITRE ATLAS v5.4.0 (Feb 2026) technique IDs to NIST AI 600-1 category to mitigating Microsoft control, as a sortable workbook for a risk-committee pack; the mappings are interpretive crosswalks traceable to a cited control, not primary facts. Sample audit-log artifacts sample-audit-log-artifacts-v1.json: real Purview Copilot interaction records (RecordType 261) captured from a live Microsoft 365 E5 tenant on 17 August 2026 and redacted for publication, so the field names, nesting, casing, and cardinality are exactly what the platform emitted and only the values were changed. It shows the AccessedResources block where it actually lives, nested under CopilotEventData, the AgentId, AgentBlueprintId, and AppIdentity attribution fields, and a jailbreak detection in the form it is really recorded. It also carries an explicit list of the documented fields that were not present, including XPIADetected, JailbreakDetected, the Messages property, and AgentName, because this file replaces an earlier synthetic version written from the documented field list that invented a schema the platform does not emit. Build your detections against the measured shape, not the documented one. No real tenant identifiers, users, or prompt text. The citation workbook citation-workbook-v1.xlsx: a 52-row claim register, one row per load-bearing claim, each with a stable claim ID, the source title and URL, a confidence score, and an as-of date, plus a volatility rating and a re-check date on the 31 rows whose surface is version-sensitive enough to warrant one (a blank there means not rated, never "stable"). Sources span eight authorities (Microsoft Learn, MSRC, the Microsoft Security Blog, MITRE, NIST, NVD, OWASP, arXiv). Filter by authority, by volatility, or by the kit section a claim sits in, then open the URL and confirm the behavior still holds. The internal-use org license org-internal-use-license-v1.md, as a typeset PDF and its Markdown source: covers your whole organization with no headcount limit, staff plus contractors acting on your behalf, across any of your security, IT, risk, and governance functions, for internal use of the kit and the read-only scripts against your own tenants, with no redistribution and no resale. There is no seat count to track and nothing to report to us. The limit is the entity rather than the headcount: separate legal entities inside a group are not covered, and neither is paid assessment work for clients. The agent incident runbook, one page incident-runbook-v1.md, as a typeset PDF you can pin up and its Markdown source: six steps in the order that keeps the evidence, contain by origin and type, preserve the audit trail and apply holds BEFORE any destructive step, disable by origin, revoke grants and credentials, investigate, then delete only once evidence is preserved. It carries an expected-latency box so revocation and hold timings are not a surprise at the worst moment. Written for a function with handoffs, which is why it sits in this tier. Price and ladder rationale $97. The free Lite checklist is the front door, and the $69 Core verification kit is the solo unit. Team costs $28 more than Core, and the gap is deliberately that small, because the alternative is a security lead doing seat arithmetic in the week before an audit. If more than one person is going to touch this, buy Team: it adds the 30-page source-cited dossier, the filterable crosswalk workbook, the audit-log samples and the citation workbook, and it replaces the single-user grant with an internal-use license that covers your whole organization with no headcount limit. What it is not is a redistribution or resale grant, and it does not stretch across separate legal entities in a group or cover paid assessment work for clients. Both of those are an email to us, not a checkbox here. It feeds a future, gated tenant-assessment engagement, which is not sold here. Freshness and updates Two dates here, because there are two kinds of evidence. Documentary claims are current as of July 2026, each one traced to a page you can open yourself. The live-tenant measurements were taken against a purpose-built Microsoft 365 E5 tenant from 15 to 18 August 2026, one tenant and one operator, and that operator is the author. Every one of the four PowerShell scripts in this kit was changed by what that run found, and the checks it could not exercise are listed in "What this kit does not prove". Re-verification is semi-annual and the next re-verify is due February 2027. The Team tier includes updates to the current edition free. Re-verify each cited page against its primary source before each internal audit cycle. FAQ Q1: What is the difference between this and the $69 Core tier? Core is the individual audit instrument: the T1 to T8 kit, the mailbox-wipe one-pager, plus the four read-only assessment scripts and the free sample, twenty-two files. Team is thirty files: all of that, plus the reference layer a security function shares. The 30-page, 10,000-word dossier and its 56 footnotes, the filterable crosswalk workbook, the sample audit-log artifacts, the citation workbook, the one-page incident runbook, plus an internal-use org license so everyone in your organization who needs it can use it without buying separately. Every document in both tiers ships as a typeset PDF as well as its Markdown source, because the people who sign off on this are not the people who run the scripts. Q2: What does the org license actually allow, and what does it forbid? It covers your organization with no headcount limit, across any of your security, IT, risk, and governance functions, and it reaches contractors acting on your behalf. It grants internal use: read and print the documents, run the read-only scripts against your own tenants, and adapt the checklists and crosswalk into your internal audit and risk-committee materials with attribution. There is no seat count to track and nothing to report to us. What it does not cover is a separate legal entity inside a group, a parent or a subsidiary included, which needs its own arrangement. It forbids reselling, sublicensing, or publishing the product, and it forbids using it to deliver a paid assessment or training service to third parties. The Trainer and Reseller tier is a separate, deferred tier, because reselling security guidance carries a liability chain. Full terms ship in the license file and at kesslernity.com/license. Q3: Will the scripts run in my setup, and what access do they need? They are PowerShell for Microsoft Graph and Exchange, plus KQL for Application Insights and Log Analytics. Every one runs read-only, and the required-reader-roles matrix, which you can read for free in the Lite bundle before you buy anything here, gives one of two answers per check. For two checks it is a role: View-Only DLP Compliance Management (inside Security Reader) for the DLP check, and Reader on the Application Insights resource and the Log Analytics or Sentinel workspace for the KQL. For the three Graph scripts it is not a role. They need the delegated read scopes AgentIdentity.Read.All, Directory.Read.All, and Application.Read.All, all three of which are admin-consent scopes, so a one-time tenant-wide admin consent is the actual gate. It fires before a token is issued, no reader role substitutes for it, and a tested run confirmed a zero-role operator succeeds once it is granted. Arrange consent before the first run. Nothing needs a *.ReadWrite scope or an admin write role. The KQL header carries a caveat: confirm your own ingestion's table and column names, and note that a live capture on 17 August 2026 found several documented audit flag fields absent, which is why Section B keys on the element type measured to work instead. A missing field is inconclusive, not a PASS. Q4: Is this just AI-generated fluff? The prose was drafted with AI agents inside a gated factory pipeline, and it is more honest to say so. It then passed a deterministic slop scanner and a build checker, and it was fact-checked against authoritative sources, cross-checked by multiple web-capable models and a vendor-diverse model council to catch fabrication, with load-bearing security claims held to the highest bar. The dossier carries 56 numbered footnotes across 28 named primary sources, and the included citation workbook holds a 52-row claim register that traces each load-bearing claim to a primary source with its confidence and its next re-check date; the EchoLeak CVE is cited to its NVD record with the 9.3 Critical score attributed to Microsoft as the CNA and NVD's own 7.5 base score named alongside it, and the threat-to-standards mappings are interpretive crosswalks, not primary facts. The scripts were verified read-only against the Microsoft API documentation (Graph, Purview, Entra). The limits of all of it are written down in the kit's own "What this kit does not prove" page, including what the live-tenant test did not cover. Q5: What about refunds? It is a Gumroad purchase, so refunds go through Gumroad. The refund expectation is stated at the top: this is a governance and verification reference, and the scripts are read-only by design, so if you wanted a destructive or attacking script, please self-select out before buying. Who it's not for This is not for someone who wants software: there is no dashboard here, no connector, no automated pipeline. The scripts are read-only assessment tools, not remediation runbooks. It is not for a single individual who only needs the kit; that is the $69 Core tier. It is M365 Copilot specific, not for other agent stacks. It is not legal, compliance, or regulatory sign-off. It is not a live assessment of your tenant. And it does not include a reseller or training-delivery license; that tier is deferred pending counsel. Disclaimer This product is an orientation and verification-methodology aid. It is not security, legal, compliance, or regulatory advice. It is not a guarantee of any security outcome. The read-only assessment scripts are run at the buyer's own discretion under least-privileged reader roles. Microsoft changes product behavior and control defaults over time, and standards versions move too; claims are stamped as of July 2026, so re-verify each cited primary source before relying on it. Nothing here authorizes an AI agent to hold standing authorization for a consequential or irreversible action; a human decision must sit before any such action.