Ward Agent by SaberGuard logoWard Agentby SaberGuard

Collect. Evaluate. Review. Report.

Ward Agent reads your Microsoft 365 or Google Workspace security settings on a schedule, checks them against the HIPAA Security Rule, and turns drift into findings SaberGuard's compliance team reviews before you hear about them. Nothing to install. No portal.

  • Microsoft 365
  • Entra ID
  • Outlook / Exchange
  • Teams
  • SharePoint / OneDrive
  • Intune

Ward Agent

collect · normalize · evaluate

  • Google Workspace
  • Google Admin
  • Gmail
  • Google Drive
  • Windows devices
  • Apple devices

Practice systems · covered through the attestation and business associate review

  • SimplePractice
  • TherapyNotes
  • Dentrix
  • Open Dental
  • eClinicalWorks
  • athenahealth

Read-only configuration inchecked against the Security Rulereviewed by SaberGuard's compliance teamyour signed report

Never read: email content, files, calendars, chat, or patient records. Your administrator can revoke access at any time.

Reads security settings only: MFA state, admin roles, sharing, device compliance, audit settings. Never email, files, calendars, chat, or patient records.

How a run works

Read-only settings in. Signed findings out.

  1. 01

    Connect

    Your administrator · 15 minutes

    Your admin grants Ward a read-only, configuration-only connection. One isolated credential, revocable at any time.

    Scoped read-only access
  2. 02

    Collect and normalize

    Automated · on a schedule

    Security settings become plain facts: who has MFA, who holds admin rights, how sharing is set, whether devices are managed.

    Timestamped, hashed evidence
  3. 03

    Evaluate

    Rules engine · not an AI

    Each fact is checked against hand-written rules mapped to the Security Rule. A rule, not an AI, decides whether a control is met.

    Candidate findings with citations
  4. 04

    Review and report

    Jonathan DeLeon, CISM®

    A person reads every candidate finding, rejects what doesn't hold up, and signs what does. You receive the report and summary.

    Signed findings and executive summary

Key benefits

What changes when the assessment never stops

Your baseline risk analysis, running on a schedule instead of once a year.

Continuous HIPAA compliance monitoring

Collection runs on a schedule, not once a year. A new admin account or a disabled MFA policy becomes a finding within days.

Compliance evidence collection

Every observation is timestamped, hashed, and archived immutably. When an auditor asks how you know, the evidence is already there.

Security visibility

Which controls are met, which have gaps, and what changed since last time, by safeguard family.

Risk reduction

Findings arrive ordered by severity with the fix attached. Drift gets caught and closed while it is still small.

Executive reporting

A plain-language summary on your schedule: what changed, what was fixed, what is open. Written for owners, signed by the reviewer.

Preview

What SaberGuard sees, and what you receive

Compliance status, risk findings, the monitoring timeline, and the executive summary that lands in your inbox.

Ward Agent · reviewer console · sample data

35of 44 met

Overall

9 gaps across 44 evaluated controls

Baseline Jun 2026 · 23 gaps

  • Administrative safeguards §164.30818/22
  • Physical safeguards §164.3106/7
  • Technical safeguards §164.31211/15

Open findings

9

↓ from 23

Evidence items

312

timestamped

Next collection

Mon 06:00

scheduled

Illustrative sample. SaberGuard reviews this console; you receive the signed report and executive summary. There is no client login.

Scope of access

Ward reads configuration, not patients

Read-only, limited to security settings, revocable by your administrator at any time.

What Ward reads

  • MFA registration state
  • Conditional access and security defaults
  • Admin role assignments
  • Stale and unused accounts
  • External sharing settings
  • Device compliance
  • Audit logging settings
  • Licensing

What Ward never reads

  • Email
  • Files
  • Calendars
  • Chat
  • Patient records
  • Anything a patient wrote

No portal, no client login, no software to install. You receive the report; SaberGuard runs the tool.

The evidence chain

Every finding points at the configuration that produced it, when it was observed, and the rule that fired.

Ward Agent · evidence pipeline · sample
read-only · 0 errors
SCHEDULECollection runevery 24h · read-onlySNAPSHOTConfigurationsha256 3f9a…c21eRULES ENGINEEvaluating164.312(d)-01 · not an AIFinding draftedExpert reviewReport delivered
›
Collection started · Microsoft 365 tenant · read-only · 06:00 UTC
Controls
44
Evidence items
312
Last run
2h ago
Reviewer
Jonathan DeLeon, CISM®

Why healthcare organizations use it

Less audit scramble. More proof.

01

Reduced audit preparation effort

The evidence an auditor asks for is already attached to each finding. Preparation becomes assembling what exists, not reconstructing a year.

02

Continuous oversight

A risk analysis is a photograph; your practice keeps moving. Monitoring keeps the signed report true between annual refreshes.

03

Better reporting

Owners get the three numbers that matter and what changed. Boards, insurers, and hospital partners get something they can read.

04

Improved compliance posture

Gaps get closed while they are small. Over a year the open-finding count goes down and stays down, with dates to prove it.

How Ward itself is secured

Built to be trusted with the keys

One credential per client

Each practice gets its own isolated credential. Your administrator can revoke it at any time.

Immutable evidence

Collected configuration is hashed and stored immutably. Review history cannot be edited after the fact.

No patient data, ever

Ward never requests, receives, or stores patient records or anything a patient wrote. Hosted in Microsoft Azure.

Security practices, subprocessors, and disclosure guidance are published in the SaberGuard Trust Center.
Questions

Before you ask

See Ward Agent on your own tenant.

Monitoring starts after a baseline risk analysis. The scoping call covers both.

SaberGuard assesses and advises; it does not warrant compliance.