Identity and access evidence

Turn access into defensible evidence.

From Microsoft 365 / Entra ID to a sealed pack: snapshot, PDF, and verifiable fingerprint ready for the auditor.

For security, compliance, and internal audit teams. Start in minutes—no sales call required.

Evidence pack · M365 privileges Sealed

Real question

Who had administrative privileges on 27/09?

Trastii does not show another dashboard: it delivers verifiable proof with scope, date, and traceability.

SourceMicrosoft Graph
Snapshot2026-09-27 · 09:14 UTC
Privileged identities47
ScopeGlobal roles · PIM · Guest
The problem

You already know how it goes.

Audit time arrives and the screenshots, spreadsheets, and manual reconstruction begin. Who had privileges that day? Nobody wants to rely on improvised proof that will not survive a serious review.

Your team is in control. But it cannot prove it in time.

Before / After

Evidence should not depend on screenshots.

Trastii is not another dashboard: it turns operational data into proof that survives over time.

The fragile way

✕One-off regenerable exports
✕Screenshots pasted into Word
✕Manual spreadsheets with no chain of custody
✕Hard to show what changed and when
✕The auditor has to rebuild the story

The Trastii way

✓Dated snapshot from an official API
✓Readable PDF for the auditor, with declared scope
✓Verifiable fingerprint, manifest, and immutable storage
✓Continuity across packs and historical comparison
✓Objective narrative for review and oversight
Evidence chain

From source to defensible proof.

A visual path: Graph → pack → fingerprint → answer. Operational detail lives in how it works.

01 · Source

Microsoft Graph

Official API, declared scope.

02 · Pack

Snapshot + PDF

Sealed JSON and a readable report.

M365-PRIV-…09-27-2
03 · Seal

Verifiable fingerprint

Integrity against tampering.

70719f0b…74b7f
04 · Answer

Defensible proof

Who, when, and traceability.

01 · Source

Microsoft Graph

Official API, declared scope.

02 · Pack

Snapshot + PDF

Sealed JSON and a readable report.

03 · Seal

Verifiable fingerprint

Integrity against tampering.

04 · Answer

Defensible proof

Who, when, and traceability.

How it works

Three phases to demonstrate control.

Collect, seal, and answer. No improvised spreadsheets or screenshots as the source of truth.

Evidence source

Collect the real state

Connect the Microsoft 365 / Entra ID evidence source, declare the scope, and generate a dated snapshot of identities, roles, and privileges.

  • Authorization of the source system
  • Exact scope of the evidence source
  • Reproducible snapshot—not a one-off export
Questions that matter

Designed around real audits.

Each product block answers a question that usually appears when control must be demonstrated.

Access

Who had privileges?

Inventory of privileged identities, assigned roles, source system, and snapshot date.

Evidence packM365-PRIV-2026-09-27-2
Integrity

Was the proof altered?

Verifiable fingerprint (SHA-256) and integrity manifest to detect later modifications.

Verifiable fingerprint70719f0b…f45a74b7f
Continuity

What changed since the last review?

Snapshot comparison and an evolution narrative to explain privilege additions, removals, and changes.

Comparison+3 roles · +2 identities
Security and frameworks

Objective evidence for frameworks that require demonstrable control.

Verifiable support for evaluation, oversight, and periodic review of identity, privileges, and traceability.

ENS

Identity, access, privileges, and traceability with declared scope.

What Trastii provides → dated, verifiable proof
ISO 27001

Access, identity, and rights management backed by evidence.

What Trastii provides → inventory and continuity
NIS2

Continuous risk management with objective, reviewable proof.

What Trastii provides → reviewable history
FAQ

Frequently asked questions

Direct answers so you can start in self-service—no sales conversation required.

Does Trastii replace Microsoft Entra ID or the IdP?

No. Trastii does not manage identities or replace the directory. It collects evidence from the source (for example Microsoft Graph) and turns it into a verifiable pack for audit.

Where is evidence stored?

Packs are kept durably and immutably on the platform, with generation metadata, scope, and a verifiable fingerprint so they can be retrieved in later reviews.

What is the verifiable fingerprint?

It is the SHA-256 reference of the sealed pack (evidence artifact). It detects whether the file was altered after generation. It is not a generic screenshot “hash”.

Does it help with ENS, ISO 27001, or NIS2?

Trastii provides objective evidence on identity, privileges, and traceability. It does not certify compliance by itself: it supports evaluation, oversight, and periodic review.

Can I start with Microsoft 365 alone?

Yes. The self-service flow is designed to connect the Microsoft 365 / Entra ID evidence source and generate the first pack in minutes.

Generate your first evidence pack in minutes.

Start free, connect the evidence source, and leave behind spreadsheets, screenshots, and manual proof hunting.

↑