Envyously
Scout·Teams Chain of custody

Field kit·Microsoft Teams·Investigation

Drop the email you're scared of. Get the truth in sixty seconds.

Scout is Envyously's security analyst, and it lives in your Microsoft Teams channel. Drop a suspicious email or paste a link — Scout triages it and answers in plain English, right in the thread. When it's bad, it tells you who else got it, and offers to contain it. A human confirms before anything runs.

§ 01 / The idea

The security question, answered where you already ask it.

Most people forward a scary email to IT and wait. Scout removes the wait.

It watches a Teams channel your staff already sit in. Someone drops a questionable .eml or pastes a link, and Scout answers in the thread — a plain-English verdict, the two or three things that tipped it, and exactly one thing to do next. No IOC soup, no jargon, no ticket to file.

Behind that calm one-liner is a real forensic pipeline: sender-authentication checks (SPF, DKIM, DMARC), link, address and file-hash enrichment against threat intelligence, and a verdict from a private, on-premises model — nothing about your mail leaves for a public chatbot. The depth is an analyst's; the answer is a colleague's.

And every red verdict thanks the person who reported it by name. That's deliberate. The fastest security control a campus or county can build is a culture that forwards the thing instead of clicking it — and Scout rewards that, every time, with a "nice catch."

§ 02 / The moment

One drop. A campus-wide save.

A help-desk tech drops one invoice. Four minutes later, an incident is over.

Scout doesn't stop at "that email is malicious." On a bad verdict it sweeps the whole tenant — the same message across every mailbox, and who clicked the link — and lays the blast radius out in the thread. Then it offers the fix as a single reply.

@Scout contain is the whole approval. An Envyously analyst confirms, the mailboxes are purged, the clickers' sessions revoked, and a signed evidence folder is sealed — with the full date and time on every action. The traditional monitoring service's measured median time to a human is thousands of minutes. Scout's answer is in the thread, timestamped.

§ 03 / The discipline

It asks before it acts.

Autonomy without a leash is a liability. Scout has a leash, and it's held by a person.

Reading is instant and free — triage, verdicts, blast-radius sweeps, all read-only against your own tenant. But nothing that changes your environment happens on Scout's say-so. A Teams reply can request a containment; only a named operator, through a per-tenant policy gate, can run it. Same evidence discipline as every Envyously engagement.

  • § i
    Human-reviewed before action.Every reply and every write is confirmed by a person. Scout drafts; a human sends.
  • § ii
    Containment is gated per tenant.Green runs, amber notifies, red never acts. The setting lives in data, not a promise.
  • § iii
    Read-only by default.Triage and sweeps change nothing. Only an explicit, logged approval writes.
  • § iv
    Your own audit log.Every action lands in your tenant's log, sealed to a case folder with full date and timezone.
  • § v
    Your mail never leaves.Verdicts come from a private, on-premises model. No public chatbot ever sees your email.
  • § vi
    Nothing installed to start.You join our secure, invite-only channel as a guest. Scout touches your tenant only read-only, through an app you consent to separately.
§ 04 / Entry

Put Scout in your channel.

Pilot · One channel · About a week

Scout in a Teams channel.

We stand Scout up in one channel — your help desk, your SOC, or a shared "is this real?" room. Onboarding is a guest invite to our secure, invite-only channel — nothing installed in your tenant to begin. Staff start dropping suspicious mail the day it's live; you keep the case folders on everything it finds.

  • Email + link + attachment triage in the thread
  • Blast-radius sweep on every malicious verdict
  • Gated one-reply containment, human-confirmed
  • Weekly digest of what Scout caught
Request a pilot

Complimentary · Real work · About a week

Or start with an investigation.

Not ready for the channel? Start where Envyously does — a free, read-only mailbox and identity investigation of your top privileged users, returned as a signed case folder. Same engine that powers Scout's verdicts.

  • Auto-forward and inbox-rule audit
  • Sign-in anomaly sweep, last 30 days
  • Read-only unless you approve an action
  • Yours to keep, either way
Request the investigation