Productised fixes. Not consulting under another label.
A catalogue, not a quoting cycle.
Every finding in the assessment report maps to one remediation package. Packages are predefined: fixed scope, fixed fee, fixed turnaround. You pick which ones to run, and when.
We only offer packages for the problems we see in ~80% of assessments. The long-tail isn't part of the catalogue. That work belongs with your internal team or a specialist.
Three categories. Fixed price. Fixed scope.
The packages below cover the bulk of what comes up in assessments. Each one has a fixed fee. No hourly rate, no scope creep.
Reservations & savings plans cleanup
Audit of existing Azure reservations, repurchase against the right SKUs, and savings-plan allocation. Includes a 12-month forecast.
Licence rationalisation
M365 and Entra ID licence audit. Unused licences removed, downgrades to the right SKU, and group-based assignments set up.
Privileged Identity Management rollout
PIM for every privileged role in Entra ID. Just-in-time access, approval workflows, and MFA enforcement, including a breakglass procedure.
Conditional Access hardening
Baseline conditional access policies covering location, device compliance, MFA, and sign-in risk. Includes a breaking-change plan and a phased rollout.
Backup verification & restore test
Coverage verification and an actual restore test of Azure Backup and M365 backup. Written RPO/RTO report.
Monitoring & alerting baseline
Azure Monitor and Application Insights baseline. Alerts wired to oncall, runbooks for the top-10 alerts, weekly health report.
From finding to handover, in four steps.
Per package: same four steps, same timelines. Standardisation makes the price work and the delivery predictable.
Package selection
You pick one or more packages from the assessment report. We send a SOW per package: fixed price, fixed scope, schedule.
Signed SOW(s) within one business day.
Temporary write access
For remediation we need temporary write access within the package's scope. Time-limited, minimum required role. Everything else stays read-only.
Access written into the SOW. Expires automatically once the package ships.
Execution
We deliver the package within the published timeline. Every change via infrastructure-as-code where possible, documented and versioned.
Changes live, code in your own repo, runbook included at handover.
Handover + walkthrough
A 30-minute walkthrough call. We show what changed, how to keep it healthy, and what's left on your side.
Handover report, before/after evidence, written confirmation that write access has been removed.
Five things that aren't part of a package.
No retainer
No monthly subscription, no 'managed service'. Per package, per engagement.
No hourly rate
Every price is a fixed fee. No surprises, no overrun debates.
No long-tail
Packages cover the common 80%. Genuinely bespoke work belongs elsewhere.
No permanent access
Write access is time-limited and tied to one package. Removed in writing after handover.
No vendor lock-in
Code lives in your repo, documentation comes with the handover. Nothing hidden, no tooling of ours needed to keep it running.
Questions about the packages.
Accepting engagements.
One intake call. 30 minutes. No prep, no pitch.