Tenant Context & Scan Follow-Ups
Microsoft can report a setting, count, policy, or assignment, but that evidence often cannot prove why it exists, whether its scope is complete, or whether another product or process provides the intended protection. Calibrant combines the Microsoft evidence with focused administrator context instead of pretending the configuration alone tells the whole story.
Two places for context
Tenant Context — before a scan
Healthcheck → Tenant Context records stable facts Microsoft cannot determine reliably. Examples include the organization's incident-response process, separate administrator accounts, release preference, Office Cloud Policy review, Viva operating choices, and settings for which Microsoft exposes no suitable read API.
Completing Tenant Context in advance is recommended, but it does not block collection. If a required answer is still missing, the scan collects Microsoft evidence first and then pauses at Context needed. An owner or administrator can answer inside that exact scan.
Scan follow-ups — after Microsoft evidence arrives
Configuration-dependent questions do not appear in Tenant Context. Calibrant asks them inside the scan that produced the evidence. Each prompt shows what Microsoft returned and asks for the missing decision: intended scope, justified exclusions, policy quality, business ownership, or an allowed outside safeguard. The saved answer is also reviewable from Tenant Context and can be cleared by an owner or administrator.
Examples include Conditional Access user and application coverage, PIM activation design, Purview label and DLP scope, guest-review coverage, Teams collaboration settings, Exchange transport-rule ownership, backup and restore testing, Power Platform governance, and Intune compliance or Windows provisioning scope. They also include the separate OneDrive sharing slider: Graph returns the SharePoint level but not the OneDrive level, so Calibrant shows the SharePoint evidence and asks whether OneDrive is equal or more restrictive.
How the final verdict is decided
| Situation | What Calibrant does |
|---|---|
| Microsoft cannot determine the fact | Uses the administrator's registered answer, with required notes or evidence where the choice needs support. |
| A machine foundation must pass first | A failed or missing Microsoft foundation remains a gap. A Yes answer cannot turn that machine-confirmed failure into a pass. |
| Microsoft evidence needs interpretation | Shows the observation and asks whether scope, intent, ownership, testing, or an explicitly supported alternative meets the rule. |
| The machine result is complete by itself | Publishes that result without asking a redundant question. A follow-up appears only when the rule permits context or a documented alternative. |
| The product is proven unlicensed | Marks the control Not Licensed and excludes it from scoring. The administrator is not asked to select No. |
| Required data could not be collected | Does not guess and does not let an answer hide the technical gap. The result is unavailable or provisional until collection is corrected. |
Completing an inline follow-up
- Open a scan labelled Context needed.
- Review What Microsoft showed and expand the collected evidence if useful.
- Select the answer that matches the organization's actual posture.
- Add the required explanation or evidence reference. Do not paste secrets or sensitive document contents.
- Save the answer. After the final request is saved, Calibrant resumes analysis against the same frozen Microsoft evidence; no new scan is required.
Only workspace owners and administrators can see or answer scan-specific context. Members can see the shared final verdict but not the exact answer, notes, evidence reference, actor, or preliminary raw evidence.
Licensing and applicability
Administrators do not choose a generic Not Licensed answer. Each scan reads Microsoft's service-plan inventory and maps the underlying capability rather than relying only on bundle names such as E3, E5, Business Premium, or E7. That matters when the same capability comes from an add-on or a newer bundle.
A negative licensing decision requires a complete, verified inventory. If Calibrant cannot prove absence, it does not remove the control from the score. The Tenant Context page may show a dated preview from the latest verified scan, but the current scan is always the authority. A positive tenant-wide capability also does not claim that every user has a compliant seat assignment; Healthcheck is a configuration assessment, not a licensing compliance audit.
Audit history and reuse
Every answer is frozen into the scan it helped resolve. Later edits cannot rewrite that audit. Stable Tenant Context may be reused by a new scan for up to 90 days when its exact question definition still matches; after that it must be reconfirmed. An inline answer is tied to a SHA-256 identity of the relevant Microsoft evidence and Calibrant evaluation version. A later scan reuses it only when both are unchanged; changed evidence asks again. The identity contains no raw customer evidence. Clearing a current saved answer stops future reuse but does not alter any completed historical audit.
A material change to the related Calibrant evaluation also changes that identity, because the old answer reviewed a different decision process. This can cause a one-time reconfirmation after an evaluation update or when an older answer predates evidence-based reuse. Once reconfirmed, later scans reuse it normally until the evidence or evaluation changes again. Calibrant does not ask every question again merely because a prior scan failed; reuse depends on the saved answer and its evidence identity.