---
title: "Mesh for Organisations — Tenant Audit, Integration & MCP"
description: "Mesh for your organisation: audit your own Microsoft tenant across ten domains, connect line-of-business systems, and work from Copilot and Claude with delegated MCP tools."
url: "https://lucidlabs.com.au/products/mesh/organisations"
---

Coming to Microsoft Marketplace

# Mesh for your organisation

Audit your own Microsoft tenant, connect the systems around it, and operate it from Copilot

Find out what state your tenant is in, read it in one portal, and keep it current. When you are ready, Mesh Pro adds integration for your line-of-business systems and AI tools that act as you, never with more access than you hold.

[Talk to us about Mesh](https://lucidlabs.com.au/#contact)[Compare the plans](https://lucidlabs.com.au/products/mesh/organisations#plans)

Are you an MSP? [Mesh for MSPs](https://lucidlabs.com.au/products/mesh)

![The Mesh Tenant Audit page for a demo tenant. Tiles show 5 findings needing attention, 3 new since the last audit, estimated savings and 9 of 11 areas covered. A Fix first list starts with a critical finding that legacy authentication is not blocked.](https://lucidlabs.com.au/screenshots/mesh/tenant-audit-overview-1280.webp)

Each tenant’s audit opens on the findings that matter most, what changed since the last run, and how much of the tenant was covered.

What Mesh does

## Audit, integrate and operate, on one platform

Running a tenant well takes the same jobs every time: find out what state it is in, keep that picture current, connect it to the systems the business runs on, and do the operational work. Mesh puts them behind one sign-in and one set of permissions.

### Tenant audit

Find out what state your Microsoft tenant is in, then keep that picture current.

-   Ten domains, from Entra security and email to licensing, cost and Fabric
-   Each domain marked covered, not collected or failed
-   Baselined, so the next run measures drift
-   Consent to the app and start it from the portal: nothing to install

### Integration

Connect the systems your business runs on, with mapping rules the process owner can read. In Mesh Pro.

-   Onboard systems from their OpenAPI or REST definitions
-   Proposed field mappings with a confidence score, approved by a person
-   Bidirectional sync with retries, notifications and schema change detection
-   Credentials in Azure Key Vault, and every run retained

### MCP tools and Lucy for Mesh

Do the operational work from Microsoft 365 Copilot or Claude, without giving an AI more access than you hold. In Mesh Pro.

-   Mail, calendar, Teams, SharePoint, OneDrive, Planner, Excel and Lists
-   CRM, timesheets, documents, invoicing and bid responses
-   Lucy for Mesh, the Microsoft 365 Copilot agent, for multi-step work
-   Delegated only: every action runs as you, within your rights

### The ten audit domains

-   Azure resources
    
-   Azure security
    
-   Cost management
    
-   Email security
    
-   Entra security
    
-   Fabric
    
-   Governance
    
-   Licensing
    
-   Microsoft 365 adoption
    
-   Microsoft 365 configuration
    

Inside the portal

## What you see

Screens from the Mesh portal, on a demo tenant.

1.  ![The Mesh page Areas the audit looks at. Cards for identity and access, Microsoft 365 settings, email, licensing, Azure resources, Azure cost and governance are marked Covered. Microsoft 365 usage is marked Collection failed with a 403 error, and Azure security is marked Not collected because the audit had no access.](https://lucidlabs.com.au/screenshots/mesh/audit-coverage-1280.webp)
    
    ### Covered, not collected or failed
    
    Every area the audit looks at says whether it was read. A gap shows as a gap, with the reason, never as a clean result.
    
2.  ![The Mesh API Field Alignment page mapping Dynamics 365 Dataverse fields to Microsoft Fabric fields. A bar shows 17 high, 5 medium and 4 low confidence mappings, and each field pair shows its match confidence, such as 99 percent.](https://lucidlabs.com.au/screenshots/mesh/field-alignment-1280.webp)
    
    ### Mappings you approve
    
    The integration service proposes field mappings between two systems with a confidence score. You approve, adjust or override each one.
    

Plans

## Plans compared

Three plans for an organisation running its own tenant. Each covers your own tenant only.

What each Mesh plan includes for your own tenant
| Feature | Mesh FreeGiven to you by your MSP or Lucid Labs | MeshAudit your own tenant | Mesh ProAudit, integrate and operate |
| --- | --- | --- | --- |
| The Mesh portal for your own tenant | Read-only | Included | Included |
| Audit results, by domain | Included | Included | Included |
| Run audits yourself | Not included | Included | Included |
| Baselined results that measure drift | Included | Included | Included |
| Integration service (iPaaS) | Not included | Not included | Included |
| MCP tools for Copilot, Claude and other clients | Not included | Not included | Included |
| Lucy for Mesh | Not included | Not included | Included |
| How you get it | Issued to you | Marketplace | Marketplace |

Mesh is coming to Microsoft Marketplace, where every plan’s price and terms will be published. Until it lists, [ask us](https://lucidlabs.com.au/#contact).

Mesh Free

## Your MSP or Lucid Labs gives you a Free seat

If an MSP looks after your tenant, or you are a direct customer of Lucid Labs, you may not need to buy anything to start. They run the audit and give you a Free seat to read the results.

-   Your MSP, or Lucid Labs if you are our direct customer, runs the audit on your tenant and gives you a Free seat
-   You read the results in the Mesh portal, for your own tenant only
-   There is nothing to buy and no charge
-   When you want to run audits yourself, or add integration and AI tools, move to Mesh or Mesh Pro

![The Mesh page Areas the audit looks at. Cards for identity and access, Microsoft 365 settings, email, licensing, Azure resources, Azure cost and governance are marked Covered. Microsoft 365 usage is marked Collection failed with a 403 error, and Azure security is marked Not collected because the audit had no access.](https://lucidlabs.com.au/screenshots/mesh/audit-coverage-1280.webp)

On a Free seat you read your own results, area by area.

How it works

## Where Mesh runs, and how it reaches your tenant

Mesh is multitenant SaaS in Lucid Labs’ own Azure subscription. Nothing runs in your tenant: Mesh reaches it only through the Entra apps you consent to.

### Your tenants

-   People sign in with Microsoft Entra ID
-   The Mesh portal in the browser
-   Lucy for Mesh in Microsoft 365 Copilot and Teams
-   Claude, VS Code and other MCP clients

### Mesh, in Azure Australia East

-   Azure Front Door and WAF in front of every entry point
-   The Mesh portal and integration service
-   The Hub and MCP server: tenants, plans and the MCP tools
-   The audit runner: one Container Apps job per audit, signing in by federated credential
-   Cosmos DB, Storage and Key Vault, reached by managed identity

### Microsoft services

-   Microsoft Marketplace: subscription and usage
-   Partner Center: GDAP relationships
-   Microsoft Graph, Dataverse and Azure Resource Manager

How Mesh fits together.

1.  Users sign in with Entra ID. The portal, Lucy and MCP clients all come in through Front Door.
2.  MCP tools act on a tenant with an on-behalf-of token, so Graph and Dataverse enforce the user’s own rights.
3.  An audit runs as a queued job that reads the tenant read-only through Microsoft Graph and Azure Resource Manager.
4.  Results land in Mesh, shown per tenant. An MSP sees each client it manages under GDAP.

Security and data residency

## Who can reach what, and how

The questions a compliance reviewer asks first, answered on the page. Each one describes how Mesh is built today.

### The tools act as the person signed in

MCP tools and Lucy use delegated, on-behalf-of access. Every call runs as the signed-in user, so Microsoft Graph and Dataverse apply that person’s own roles and permissions. Nothing reaches further than the person asking.

### The audit only reads

The tenant audit signs in as its own app with read-only application permissions. Optional checks ask for their permissions separately, when you turn them on, rather than in one large consent up front.

### Revocation is honoured straight away

The MCP tools and Lucy support Continuous Access Evaluation. When Entra revokes a session or a Conditional Access policy stops being met, Mesh drops that user’s cached tokens immediately instead of waiting for them to expire.

### One tenant per conversation

Once a session touches one customer tenant it cannot pull another customer’s data into the same thread. A request that cannot be resolved to exactly one tenant is refused.

### A label check before anything is sent

Every outbound mail and Teams send passes a sensitivity-label-aware data loss prevention check first. Escalations ask for confirmation, and an override is recorded.

### Hosted in Australia

Mesh runs in Microsoft Azure, Australia East. Audit results and integration run history are stored there, and connection credentials stay in Azure Key Vault. No Lucid code runs in your tenant.

Ways to buy

## Ways to buy

Coming soon

### Microsoft Marketplace

Buy Mesh or Mesh Pro yourself. It bills on your existing Microsoft invoice, and the listing carries each plan’s price and terms.

Ask your provider

### Through your MSP

If an MSP manages your tenant, it can audit it with Mesh and give you a Free seat. It can also run the integration service for you on Mesh Pro.

By arrangement

### Private offer

For an organisation that needs its own terms. Talk to us and we will set it up.

Mesh is coming to Microsoft Marketplace, where every plan’s price and terms will be published. Until it lists, [ask us](https://lucidlabs.com.au/#contact).

Already true

## In use today

-   Lucid Labs runs its own business on the Mesh MCP tools, and runs the same audit on its own customers’ tenants.
-   The audit has been run on customer tenants with two steps each: the customer consents to the app, and the run starts from the Mesh portal. Nothing installed, no scripts.
-   The audit covers ten domains, and every one is reported as covered, not collected or failed.

## Common questions

What is the difference between Mesh and Mesh Pro?

Mesh is the portal and self-run tenant audits on your own Microsoft tenant. Mesh Pro adds the integration service, MCP tools for Microsoft 365 Copilot, Claude and other MCP clients, and Lucy for Mesh, all on your own tenant. Prices are on the Microsoft Marketplace listing.

How do I get a Free seat?

Your MSP gives it to you, or Lucid Labs does if you are our direct customer. It is read-only access to the Mesh portal, to see the results of the audits they ran on your tenant. There is no charge, and you do not buy it yourself.

What happens to my Free seat if I leave my MSP?

You keep read-only access to your last results, and you can move to Mesh or Mesh Pro yourself on Microsoft Marketplace. Your audit history comes with you, and from then on you are billed directly, never through your former MSP.

What happens when the audit cannot collect a domain?

The domain is marked not collected, or failed, with the reason, rather than left blank. A missing result never reads as a clean one, so you can tell a domain with no findings from one the audit could not reach, usually because a consent or permission is missing.

What permissions does Mesh need?

The audit uses its own app with read-only application permissions, consented once by an administrator, and optional checks ask for theirs separately. The MCP tools and Lucy use delegated permissions only, so every action runs as the person signed in and within that person’s rights.

Do I need anything extra to use Lucy for Mesh?

Lucy for Mesh is included in Mesh Pro and needs it to work. Lucy runs inside Microsoft 365 Copilot and Teams on the same delegated MCP tools as the rest of Mesh, so she acts as the signed-in user and within that user’s rights.

Where is the data held?

Mesh is hosted in Microsoft Azure, Australia East, and stores audit results and integration run history there. Connection credentials stay in Azure Key Vault. The AI-assisted parts of the integration service, such as proposed field mappings, call an Azure OpenAI deployment that Lucid Labs runs in the United States.

Already running it? [Mesh support](https://lucidlabs.com.au/products/mesh/support) has the diagnostics to run before raising a ticket.

## Start with an audit of your own tenant

We will show you the audit on a real tenant and the plan that fits, before anything is bought.

[Talk to us about Mesh](https://lucidlabs.com.au/#contact)

Coming to Microsoft Marketplace. Prices will be on the listing.
