Per-tenant comparison
Workspace baselines and drift
Import hardened Conditional Access templates from GitHub, tailor them in your workspace, and assign a comparison baseline per customer tenant.
Create your account, set up a workspace, and get 14 days of Pro - connect tenants, detect drift, and run impact analysis. No credit card required.

Per-tenant comparison model
New tenants default to an imported CA snapshot baseline (drift = changed since adoption). Assign a workspace baseline per tenant when you standardize on a catalog you imported and edited. Community baselines on GitHub are templates - not a single global baseline shared by every customer.
Fleet policy matrix and catalog pages show coverage across connected tenants, each evaluated against its own effective baseline.
- Community baselines import live from GitHub into workspace baselines
- Auto-remediate payloads built for drift categories - still through change workflow
- Fleet policy matrix in the console for MSP-wide baseline enforcement view
Bring your own baseline
Policytab ships no bundled catalog you are forced to adopt. You decide what "correct" means for each tenant: the tenant's own imported CA snapshot, a community baseline pulled from GitHub, or a JSON definition you author yourself.
Whatever you import lands in your workspace, where you can edit it before it governs anything. The GitHub presets are starting points - hardened templates to tailor - not opinions baked into the product that every customer inherits.
- Import from a tenant snapshot, a GitHub baseline, or JSON
- No shipped catalog - the workspace baseline is yours to define
- Edit policies, groups, and named locations before assignment
- Reuse one tailored baseline across the tenants that share a standard
One baseline per tenant, drives drift
Each tenant carries exactly one assigned comparison baseline. Drift is the diff between that tenant's latest snapshot and the baseline it points at - so the same portal edit can be drift in one tenant and expected in another, depending on what each was assigned.
Reassign a tenant from its imported snapshot to a workspace baseline the moment you standardize it, and drift re-bases against the new target on the next resync. The baseline is the contract; the snapshot is reality; drift is the gap between them.
Workspace baselines and drift
Import open CA baselines from GitHub into your workspace, assign per tenant, and compare drift on every resync.