Organization Automation Systems

How OA6 got its name

Organization Automation Systems, and six pillars.

We started with Microsoft's security. But no organization runs on Microsoft alone, and leaders need to see quickly what is happening across every tool they run, then automate the six pillars of the NIST Cybersecurity Framework 2.0 across the whole organization.

That is why we started Organization Automation Systems. OA6 joins that name with CSF 2.0's six pillars: Govern, Identify, Protect, Detect, Respond and Recover.

Status Microsoft works today. The other platforms are in preview, read-only first, and Automations is a build in progress.

For CIOs, CISOs and CTOs

From finding to fixed, without the detour.

Most of the time between spotting a problem and fixing it goes into working out why it happened. OA6 does that work on the Microsoft 365 and Azure pages your teams already use, explains it in plain language, and makes the fix only after an administrator approves it.

  • A person starts every change
  • Works as you
  • AI off until you turn it on
  • No copy of your tenant

The impact

Faster fixes, shared understanding, nothing new to run

Time to remediation

Less time finding out why

The fix is rarely the slow part. The slow part is opening blade after blade to learn which policy, license or sign-in caused the problem. OA6 puts that evidence on the page where the question started, with the proposed change next to it.

Organization-wide understanding

One explanation everyone can read

Portal screens make sense to the person who knows the portal. A plain-language account of what happened and why makes sense to the service desk, the security team and leadership alike, so fewer findings wait on the one expert who can read them.

Control and accountability

Nothing changes unless a person chooses it

Every change is started by an administrator, under the roles they already hold, and anything that can do harm waits on an approval card first. Each action is recorded in an activity log that each administrator can send to your own SIEM.

Where the time goes

The answer is in the portal. The reasoning is not.

A user has an alert against them. A device shows as non-compliant. The page tells you what, not why, so someone rebuilds by hand something the tenant already knows.

OA6 does that work where your people already are, using the access they already have, with no agents on devices and no new console to staff.

Without OA6

Piece it together

  • Open the alert, then the user
  • Check sign-ins in another blade
  • Check Conditional Access and licenses
  • Decide, then go somewhere else to act
With OA6

Decide and approve

  • Open the user
  • See the related alert, sign-ins and policies together
  • Read the why in plain English when you enable Ask OA6
  • Approve the proposed fix on the same page

Illustration These are the steps involved, not a measured time saving.

What it does

Three things, in that order

01 · Automatic

Reads your tenant in place

Open a device, a user, a policy or an alert and OA6 recognizes the subject and pulls the related objects through Microsoft Graph. This part needs nothing from you.

02 · If you turn it on

Explains what it found

Turn on Ask OA6, connect the model you choose, and OA6 reasons over what it read: which policy actually decided the outcome, what the alert involved, where a setting is contradicted somewhere else.

It is off until you turn it on. When you ask, names, addresses and IDs are masked in your browser before anything is sent to your model.

03 · Once you approve

Acts on it

Where a fix is the obvious next step, OA6 proposes the exact change and shows you what it would do. Nothing is written to your tenant until an administrator chooses that action, and anything that can do harm waits for you to approve it.

How it works →

The OA6 framework

Six pillars. One loop.

OA6 keeps all six functions of the NIST Cybersecurity Framework 2.0, one for each side of the hexagon. Around them is Automate, the circle that connects every corner, because if we can see it, we can automate it.

It doesn't replace the framework. It automates it.

Explore the framework →
01 GOVERN02 IDENTIFY03 PROTECT04 DETECT05 RESPOND06 RECOVER OA6 AUTOMATE

Across your clouds

One overlay. Every platform that holds part of the story.

The same person and the same device live in several systems, and each one knows something the others don't. OA6 pairs those records and fixes the problem where it lives, rather than asking you to move to another console.

Works today

Read, explained and acted on, with approval.

  • Microsoft Entra ID
  • Intune
  • Defender for Endpoint
  • Purview
  • Azure RBAC

In preview

Built read-only, not yet proven on a real account. Not available yet.

  • ServiceNow
  • Okta
  • Google Workspace
  • ChromeOS
  • Jamf
  • CrowdStrike
  • Darktrace
  • Proofpoint
  • Mimecast
  • Cloudflare Zero Trust
  • AWS
  • Google Cloud
  • Oracle Cloud

Build in progress: Patch My PC and Tanium. Being built, not available yet.

Watch each integration →

Status Microsoft works today. The others are in preview or a build in progress, and none of them is available yet.

Start with the tenant you already run.

OA6 is in preview. Ask for your organization to be added, and once it is, one administrator registers OA6 in your tenant, adds the extension, signs in with a work account and opens any admin page.