Frequently Asked Questions

Straightforward answers about our security and guardrails.

Everything you need to know about how Axon handles permissions, confirm gates, and Microsoft Graph integrations.

Can Axon make changes to Microsoft 365 on its own?
No. The AI model only receives read-only schema inspection tools. It is mathematically incapable of executing mutating API calls directly. All modifications require an authorized human administrator to review and click Approve.
What happens if I decline or ignore a proposed plan?
Nothing happens. Your Microsoft 365 tenant remains untouched. The plan remains saved in your draft history if you want to review it later, but Axon never executes unapproved requests.
How are Conditional Access policy changes handled?
All newly created Conditional Access policies are strictly deployed in "Report-Only" mode first. Enabling live enforcement is always an explicit, separate confirmation step to prevent accidental lockouts.
Is our company data isolated from other organizations?
Yes. Every organization is partitioned at the database layer with strict tenant isolation. Furthermore, your internal directory data is never used to train generalized foundation models.
Can executed operations be rolled back?
Most actions, including group memberships, license assignments, and mailbox permissions, support one-click rollback directly from the audit log. The few actions that cannot be reversed (such as immediate password resets) are prominently flagged before you confirm.
Does Handoff replace our external MSP or IT provider?
Handoff is designed to handle routine, everyday identity and access workflows (onboarding, offboarding, license cleanup, and group changes). It frees your team or outsourced IT provider to focus on complex hardware and network infrastructure.