The module library

Every module, in detail.

One outbound-only agent collects, one console decides, one audit trail proves it. Each module below is a signed catalogue script rather than a separate product, so a new capability arrives without an agent rebuild, an inbound port or a change window. New modules are added continuously; this page is the current library.

One agentHMAC-signed, outbound only, hash-pinned scripts
Advisory by defaultRemediation proposes, you approve, autonomy is a tier you switch on
Per clientEvery module is enabled, scoped and evidenced per client tenant
Group 01

Compliance and risk

Continuous scoring against the control framework you are held to, and a register that knows which of your real installs are actually exposed.

CE+

Control Assessment (CE+)

Continuous scoring of every device against Cyber Essentials Plus v3.3, CIS, Essential Eight or a baseline of your own.

Flagship

What it does

  • Scores every device daily against the five control themes: firewalls, secure configuration, access control, malware protection and patch management.
  • Keeps the snapshot history, so a pass today and a failure six weeks ago are both on record with the dates in between.
  • Maps a single set of collected facts to more than one framework, so the same evidence answers more than one auditor.

What it produces

  • Assessor-ready report with pass and fail per control, plus the device sample the assessor will ask for.
  • Per-device remediation list, ranked, with the owning module for each fix.
  • Readiness percentage for the executive page and the board pack.

Needs: the agent on the device. No inbound ports, no ConfigMgr dependency.

Read the full Cyber Essentials Plus module page →

RR

Risk Register

NVD, CISA KEV and EPSS correlated to the software you actually have installed, refreshed every four hours.

What it does

  • Matches advisories to the real installed version on each device rather than to a generic product feed.
  • Prioritises by known exploitation first, then EPSS probability, with confidence filtering to drop low-signal guesses.
  • Runs an SLA clock per exposure, with breach alerts before the window closes rather than after.

What it produces

  • A live register of exposures with install counts, owning devices and days remaining.
  • A remediation proposal handed straight to Package Creator or Security Patches.
  • Closed-exposure history for the evidence pack.

Needs: the agent and its inventory. Correlation happens server side.

CD

Configuration Drift

Forty-eight security-relevant configuration facts snapshotted daily on every device and diffed on the server.

Pilot

What it does

  • Takes an authoritative nightly snapshot rather than trusting the device to report what changed.
  • Diffs server side and maps each fact to the control theme it belongs to.
  • Turns the change that would have failed you at assessment into a finding the next morning.

What it produces

  • Per-device timeline of configuration changes with before and after values.
  • Per-theme compliance movement, so a regression is visible as a trend, not a surprise.
  • Advisory findings with a proposed corrective action.

Needs: the agent. Advisory mode by default; enforcement is opt-in per client.

EV

External Vulnerabilities

Your attack surface seen from the outside, on the same schedule as the internal picture.

What it does

  • Enumerates certificates and DNS, checks SPF and DMARC, TLS configuration and security headers.
  • Finds risky open ports and publicly exposed JavaScript libraries with known issues.
  • Tracks change over time, so a newly exposed service is an alert rather than an annual finding.

What it produces

  • An external posture score alongside the internal one on the same console.
  • Expiry and misconfiguration warnings with the owning domain.
  • Evidence that the perimeter was checked continuously, not once a year.

Needs: your domains and public ranges. No agent involvement.

Group 02

Applications and packaging

The part most platforms hand back to you. Assure decides what should exist, then builds and ships the fix to your own standards.

5R

Applications and the 5Rs

Retain, Reduce, Replace, Remove or Replatform every product, from real per-user usage rather than an install count.

What it does

  • Normalises the raw inventory into products and publishers, so eleven versions of one tool are one decision.
  • Scores each product on usage, licence cost, risk and support state.
  • Lets you override the recommendation at product, department or device level, with the reason recorded.

What it produces

  • A rationalisation plan with the saving attached to each decision.
  • A retirement queue that Package Creator can action directly.
  • An audit trail on every decision and every override.

Needs: the agent for usage telemetry. Licence costs entered once per product.

PK

Package Creator

MSI inspect and transform, PSADT generation to your own standards, documentation, then publish.

What it does

  • Inspects the vendor MSI, surfaces properties and features, and builds the transform rather than hand-editing it.
  • Generates a PSADT wrapper against your house template, so every package your estate receives looks the same.
  • Publishes the finished package to Intune or Configuration Manager from the same console.

What it produces

  • A deployable package with detection logic, install and uninstall, and user handling.
  • Package documentation generated from what was actually built.
  • A version history per application, so the next release is a repeat, not a rebuild.

Needs: your PSADT template defined once, plus the Intune or ConfigMgr connection you already have.

SP

Security Patches

Windows Update scan and install carried out by the agent, with no Configuration Manager dependency.

What it does

  • Scans for missing updates on the device itself and reports what is genuinely absent.
  • Installs on approval, within a window you set, on devices that are off the corporate network as readily as on it.
  • Re-scans afterwards, so the claim that a patch landed is verified rather than assumed.

What it produces

  • Before and after report per device and per update.
  • Patch compliance feeding straight into the control assessment.
  • Failure reasons decoded, rather than a raw error code.

Needs: the agent. Works alongside your existing update infrastructure or without it.

M3

Microsoft 365 Licences

Who uses what on desktop, mobile and web, and what the unused seats are costing.

What it does

  • Measures real activity per user across desktop, mobile and browser rather than assigned-licence counts.
  • Finds inactive seats, duplicate entitlements and users who only ever use the web client.
  • Models the resize before you commit to it, then tracks the saving after renewal.

What it produces

  • A costed resize proposal per licence type.
  • A tenant health check covering assignment hygiene and orphaned accounts.
  • A saving figure the board can see on the executive page.

Needs: read access to your Microsoft 365 tenant via Graph.

In practice

A recent Microsoft 365 resize and health check across an estate of 1,400 devices identified over £115k of reclaimable licence spend, from inactive seats, duplicate entitlements and users who needed only the web client.

Group 03

Endpoint health

The management estate itself, checked and repaired. A compliance score means nothing if the client that reports it is broken.

CM

Configuration Manager Health

Estate rollup, twelve health checks per client, a failed-deployment decoder and one-click Unstick.

What it does

  • Runs twelve checks on every client: service state, policy, inventory cycles, cache, certificate and management point contact.
  • Decodes failed deployments into the actual cause rather than a status code.
  • Repairs the common failures from the console, without a remote session or a desk visit.

What it produces

  • An estate-wide client health percentage with the failing devices named.
  • A remediation history per device.
  • The AssureCM toolkit for the engineers who want to work at the command line.

Needs: an existing Configuration Manager site and the agent on the clients.

IN

Intune Health

Device health synced from Graph, failures decoded, and remediation scripts your first line can actually run.

What it does

  • Pulls device, compliance and app-install state from Graph on a schedule.
  • Translates install and compliance failures into a cause and a next action.
  • Offers a set of remediation scripts scoped so a first-line engineer can run them safely.

What it produces

  • A decoded failure list rather than a dashboard of red tiles.
  • Co-management visibility where devices are in both worlds.
  • Remediation outcomes on the same audit trail as everything else.

Needs: Graph read access to your Intune tenant.

DF

Defender Health

Protection state, signature age, tamper protection and the exclusions nobody remembers adding.

What it does

  • Checks real-time protection, signature currency and tamper protection per device.
  • Surfaces risky exclusions, including the broad path exclusions added years ago for an application that has since gone.
  • Pulls Defender for Endpoint alerts alongside the estate picture where that licence exists.

What it produces

  • Malware-protection evidence for the control assessment.
  • An exclusion review list with the age of each entry.
  • Devices unprotected today, named, rather than a percentage.

Needs: the agent. Defender for Endpoint alerts need the corresponding licence.

WA

Workplace Automation

A catalogue of hash-pinned automations, from disk cleanup to update repair, simulated before they run.

What it does

  • Runs published automations through the agent, each pinned by SHA-256 so an altered script simply does not execute.
  • Simulates first and shows what would change, before anything is committed.
  • Targets a device, a collection or the whole estate, on approval.

What it produces

  • Per-run results on the console with output captured.
  • Repeatable fixes that stop being tribal knowledge in a script folder.
  • A complete record of who ran what, where and when.

Needs: the agent. The catalogue grows without an agent rebuild.

Group 04

Visibility and support

The newer modules. Each is consent-gated, scoped per client, and built so the privacy position holds up before the capability ships.

NE

Network Egress

Where every device is talking to, per process, every fifteen minutes.

New

What it does

  • Captures flows at kernel level and aggregates by process, destination, port and protocol.
  • Enriches destinations with country and flags the regions you care about.
  • Drops private ranges and keeps metadata only. No payload, ever.

What it produces

  • Top talkers by volume, and new destinations seen in the last 24 hours.
  • Flagged-region activity with the owning process named.
  • An early signal on software phoning home that nobody approved.

Needs: the agent, and opt-in per client.

WB

Web Activity

Sites visited, with two honest time figures always shown together: Span and Active.

New

What it does

  • Runs in the user's own session, never as SYSTEM, across Edge, Chrome and Firefox.
  • Reports Span and Active time side by side, so a tab left open is not counted as four hours of work.
  • Cannot be enabled for a client until an impact-assessment reference and notice acceptance are recorded. The database refuses, not just the button.

What it produces

  • Category and site-level usage for licence and acceptable-use decisions.
  • Evidence of the consent position alongside the data itself.
  • Input to application rationalisation where a web app has quietly replaced a licensed desktop one.

Needs: the agent, a recorded impact assessment and notice acceptance, per client.

RS

Remote Support

Consent-based screen sharing over your own LAN or VPN, with no relay and no third-party cloud.

New

What it does

  • Connects directly over your network. Nothing traverses a vendor relay.
  • Prompts the user with a PIN and holds a red banner on screen for the whole session.
  • Offers view, or view and control, as separate permissions.

What it produces

  • An audit log entry per session: who, which device, how long, and which mode.
  • A support path that does not add another agent to the build.

Needs: LAN or VPN reachability, pinned TLS 1.2 or above. Deployed by Intune or ConfigMgr like any other package.

Group 05

Intelligence and reporting

What turns the other modules into a decision, and then into something you can hand to a board or an assessor without assembling it by hand.

AI

Proactive AI Remediation

Signals from every module, a proposal per finding, autonomy as a tier you switch on rather than a default you switch off.

What it does

  • Reads across modules, so an exposure, a drift finding and a broken client are one story rather than three tickets.
  • Proposes the specific fix, names the module that will carry it out and estimates the blast radius.
  • Waits for approval by default. Autonomy is granted per client, per action class.

What it produces

  • A ranked queue of proposals with the reasoning attached.
  • A plain-English weekly narrative of what mattered and what was done.
  • An approval record on every autonomous action.

Needs: at least one collecting module. It gets better as more are enabled.

EX

Executive Summary

Board posture on one page: readiness, exposure, spend and what changed.

What it does

  • Draws readiness, open exposure, licence position and rationalisation progress from live data, not a monthly export.
  • Narrates the change since last month rather than only the current state.
  • Redraws per client for service providers running more than one estate.

What it produces

  • A page you can forward unchanged to the board.
  • Branded exports for a customer service review.
  • The one number the CIO opens first.

Needs: nothing of its own. It reflects whichever modules are on.

AT

Audit Trail

Every decision, action and result, recorded as it happens rather than reconstructed afterwards.

What it does

  • Records the proposal, the approver, the action and the verified outcome for every change.
  • Keeps overrides and the reasons given for them.
  • Holds the snapshot history behind every compliance claim.

What it produces

  • An evidence pack that is a download rather than a project.
  • Full coverage of rationalisation, governance and remediation decisions.

Needs: nothing. It is on for every module, always.

The library keeps growing

Modules ship as signed catalogue scripts, so a new capability reaches your estate without an agent rebuild, an inbound port or a change window. If something you need is not here yet, it is usually a module rather than a project.

See these running on your own estate.

Forty-five minutes on your data, or ours. Onboarding in days, no procurement friction.

Book a demo How it works