z3roday Day zero · before anyone asks

Microsoft 365 & Google Workspace · Australia and New Zealand

Your team can now ask AI anything. Including things they were never meant to see.

Turn on Copilot or Gemini and it reads every file the person asking already has access to. In most companies that is far more than anyone realises. We find out exactly what is exposed, show you the list, and close it — and when a customer or tender asks you for SOC 2 or ISO 27001, we do that too.

What a scan usually finds 7 of 3,412
HRSalary bands FY26 — readable by 1,240 staffExposed
FINANCEBoard pack — link works for anyone, never expiresExposed
LEGALSettlement agreements — permissions copied from the parent siteOver-shared
SALESCustomer list with personal details — anyone with the linkExposed
ITPasswords typed into a how-to documentOver-shared
ARCHIVE40,000 files from an old migration — no ownerOver-shared
MARKETINGLogo and brand files — open to everyone, on purposeFine
Typical findings. Yours will be different, and countable.

How it happens

Nothing gets hacked. The AI just does what your permissions allow.

  1. Files get shared, year after yearSomeone sends a link. A folder inherits access from the one above it. A team dissolves and its site stays. An old system gets migrated in and nobody sets permissions. None of this is anyone's fault, and none of it causes a problem — because nobody is searching.
  2. You switch on the AI assistantIt reads everything each person is allowed to read, so it can answer their questions. That is the whole design. It does not ask whether they should be allowed — only whether they already are.
  3. Someone asks a completely normal question“What do people in my role get paid?” And it answers, because a spreadsheet from 2019 is technically readable by everyone. No warning, no log entry that looks unusual, no way to take it back.
ONE EMPLOYEE “What do people in my role get paid?” AI assistant READS WHAT THEY CAN READ EVERY FILE IN YOUR TENANT REACHED

The assistant did nothing wrong. It answered with what that person was already allowed to open.

One employee · what they need vs what they can reach

What they need for their jobTheir team's files and current projects

9%

What they can actually openPlus everything inherited, shared by link, or left behind

74%

That gap was there before the AI arrived. Switching it on does not widen the gap — it just makes it searchable, in plain English, by everyone who has it. Shape is illustrative; on your setup it is countable, and the next section starts you off.

Free · no signup · nothing leaves your browser

Don't take our word for it. Go and count.

Six numbers from your own admin centre, about fifteen minutes, no special tools. Type them in and the maths happens in front of you. If it comes back fine, you have spent fifteen minutes and can stop worrying. That is a perfectly good outcome for us.

01How many SharePoint sites do you have?

SharePoint admin centre → Sites → Active sites, and read the total. Count Teams sites too — each one holds files.

Connect-SPOService -Url https://YOURTENANT-admin.sharepoint.com (Get-SPOSite -Limit All).Count
02How many have no sensitivity label?

Same screen, add the Sensitivity column. A label is how you mark something confidential. With no label, nothing can tell that site apart from the lunch menu.

(Get-SPOSite -Limit All | Where-Object { -not $_.SensitivityLabel }).Count
03How many haven't been touched in six months?

Sort by Last activity. Finished projects, teams that no longer exist. Nobody owns them — and the AI reads them just as happily as today's work.

(Get-SPOSite -Limit All | Where-Object { $_.LastContentModifiedDate -lt (Get-Date).AddDays(-180) }).Count
04How many “Anyone” links are still live?

Microsoft 365 admin centre → Reports → Usage → SharePoint → Sharing. These open without signing in at all. If this is not zero, start here.

05How many staff have a licence?

Microsoft 365 admin centre → Billing → Licences. Everyone who can sign in and ask a question.

06Roughly how many files per site?

Most companies land between 800 and 2,000. Everything below scales with this number, so it is the one worth checking rather than guessing.

What these six numbers cannot tell you: which files are exposed, who exactly can open them, or how that happened — a link someone sent, a folder copying its parent, a team that was deleted but left its files behind. Each is fixed a different way and takes a different amount of time, so that is the part that matters. These numbers are a thermometer. Finding the actual files is the job.

Send us your numbers for a second opinion Runs in your browser. Nothing is sent anywhere.

What we do

We look, we hand you the list, and we close it.

One thing, done properly. You can stop after step one and give the list to your own team — plenty of people do, and it is written to be handed over.

Step one · fixed price

The exposure check

We look at your setup, read-only, and find what an AI assistant would surface. No changes made, nothing switched off, no disruption to anyone's day.

How long
5 working days
What we need
Read-only access, time-limited, removed when we finish
Works with
Microsoft 365, Google Workspace, or both
Your time
About 3 hours, in two sessions
Price
AUD 4,500 fixed
  1. The listEvery file that is open to people who should not have it, ranked worst first, with who can reach it and how it got that way.
  2. What each person can seeWhat a new starter could pull up on day one. What a contractor can reach. What someone who left three years ago could still open if their account were used.
  3. A plan you can actually followWritten for your setup and your licence, ordered so the biggest problems close first, with how long each will take. If you want us to do it, this is also the quote.
  4. Simple rules going forwardWhich AI tools staff may use, who signs off on new ones, and what to keep a record of — so this does not quietly build back up.
Step 02

Fix it

Labels set up, over-shared sites closed, open links killed, old sites cleared out, and the AI pointed at what it should see. Hands on the keyboard, not advice about keyboards.

Fixed price, quoted from the list

Step 03

Keep it that way

Permissions drift back as people share, join and leave. A short monthly check keeps the number near zero instead of letting it climb again. Most clients start this only after the first fix, once they can see it is worth it.

From AUD 900/month, optional

Also

Certification

If a customer or a tender has asked you for ISO 27001, SOC 2, ISO 42001 or Essential Eight — or you need your privacy policy sorted before 10 December — that is a separate piece of work.

See what that involves →

How we price it

One fixed price, agreed before we start. No hourly billing, no surprise extras, and nothing charged for time we spend learning your setup. If it takes longer than five days, that is our problem.

The list is yours to keep and written so your own IT team can act on it without us.

Who you would be dealing with

People who have done this from the inside, not a call centre.

Our team has run security for an Australian technology firm serving banks and insurers, and taken it through ISO 27001 certification and a SOC 2 audit. We have been the ones assembling the evidence at 11pm, so we know which problems are genuinely hard and which just look bad in a report.

  1. Read-only, and you can watchAccess is limited to what the agreement says, granted through your own systems, and switched off when we finish. Everything we do shows up in your logs, and we will show you where to look on day one.
  2. InsuredProfessional indemnity and cyber liability cover. We sign your NDA, not ours.
  3. Or we never touch itIf you would rather, your own admin runs our scripts and sends us the output. Slower and slightly less precise, and about a third of clients prefer it.
  4. The same people throughoutWhoever looks at your setup is who fixes it. Nothing gets handed to a pool of juniors once you have signed.

Before you ask

The questions we get on every first call.

Why would we give strangers access to all our files?

You should not have to trust us to start. The access is read-only, limited to what is written in the agreement, granted through your own system, and removed when we finish. Every action appears in your own audit log and we will show you how to read it. If you would still rather not, your admin can run our scripts and send us the results instead.

Can't we just buy software that does this?

Not really, and anyone selling you one is selling a dashboard. The settings that fix this live inside Microsoft 365 or Google Workspace, and they are different in each. Most of what you need is already in your licence and switched off. The hard part is deciding who should see what, which is a judgement call, not a product.

We already turned Copilot on. Is it too late?

No, and it is the more common situation. Nothing has necessarily gone wrong. We do the same check, plus we read the usage logs you already have to see what has actually been asked and answered, and we close the worst things first.

Our IT is outsourced. Does that change anything?

Only in who we talk to. Most managed service providers keep your systems running well and were never asked to review who can see what — it is a different job. We work alongside them, and hand them the fixes if that is how you would rather do it.

We're a small company. Is this overkill?

Size does not change the maths much. A 40-person company that has been running Microsoft 365 for eight years usually has the same permission mess as a 400-person one, just fewer files. If anything it is easier and cheaper to fix, and there is less chance anyone has ever looked.

What happens after you hand over the list?

Entirely up to you. Give it to your own IT team or provider — it is written for that. Ask us to do it, and we quote a fixed price from the list. Or do the urgent items yourself and give us the rest. Nobody is locked into anything.

What will it cost in total?

The check is AUD 4,500 and that is the whole price. Fixing it depends entirely on what turns up — a few open links is a day, redoing permissions across hundreds of sites is weeks. You get a specific number from the list before deciding anything.

Next step

Half an hour, and a straight answer either way.

Tell us what you are running and what prompted the question. If we are not the right fit we will say so and point you somewhere better.

Emailhello@z3roday.com

Phone+61 420 814 130

ResponseWithin one business day

CoverageAustralia and New Zealand

Goes straight to a person, answered within one business day. Please don't put anything sensitive in this form — we'll set up a secure channel on the first call. See our privacy statement.