Handoff
Product Security Pricing FAQ
Get started
IT admin, without the IT department
Say what you need.
Pip maps it to a plan
you can confirm.
No scripts. No arbitrary access. Every Microsoft 365 change runs through a pre-approved workflow — and nothing moves until you click Confirm.
Start free See how it works
See it in action
Five real workflows, unscripted.
"Your own words here — what changed for you, in one or two sentences."
— Your name, your role
The gap
A ten-person company doesn't have an IT department. It still has IT problems.
Nobody owns offboarding, so a leaver's access quietly outlives their last day.
Licences pile up because removing one feels riskier than just paying for it.
Access requests get "yes"-ed in a hallway, with no record of who approved what.
How it works
Nothing runs until a human says so.
01
Say what you need
Describe it to Pip in plain English — no forms, no ticket queue.
02
Pip proposes a plan
Every step is shown up front, with where each suggestion came from.
03
You confirm
Nothing changes until a human clicks Confirm. Say no and nothing happens.
04
It runs, and it's logged
A pre-approved Microsoft 365 workflow executes, with a full audit trail.
Product
A fixed set of workflows. Not a chatbot that can do anything.
Pip only ever proposes one of these — every one auditable, every one reversible or clearly flagged when it isn't.
Onboarding & offboarding
New starter to leaver, one business-event sentence away.
Licence & cost control
Assign, swap, or remove licences without spreadsheet-chasing.
Access management
Group membership and permission changes, always shown before they run.
Conditional Access
New policies are always created report-only first — enforcing is a separate, deliberate step.
Enterprise app risk review
Flags high-risk permissions, unverified publishers, and 90+ day unused apps.
Compliance nudges
MFA gaps, stale access, and licence drift surfaced before they become a problem.
New starter — Marketing
Create Microsoft 365 account
Assign Business Premium licence
Add to Marketing team + shared drive
4 Notify manager
Offboarding — Leaver
Disable sign-in
Reassign mailbox to manager
Remove group memberships
4 Revoke licences
Security
The AI proposes. It structurally cannot execute.
Structural confirm gate
Mutating actions are never exposed to the model — only read-only plan tools are. The only thing that triggers a change is a human clicking Confirm.
Report-only, then enforce
New Conditional Access policies are always created in report-only mode. Enforcing is a separate, explicit step you take later.
Tenant isolation
Every organisation's data is scoped at the database layer — one tenant never sees another's.
Full audit trail
Every plan and every execution is logged — who asked, what was proposed, what actually ran.
One-click undo
Group membership, licence assignments, mailbox and drive access, and more can be reversed in one click straight from the plan's history. The few actions that genuinely can't be undone — like a password reset — are flagged before you confirm, not after.
Say what you need. See the plan. Decide for yourself.
Start free See pricing