Live in production — deployed in client tenants today

Meet Helix

Onboarding and offboarding that actually finish. Helix turns your joiner, mover and leaver process into a runbook — one reviewed job that runs across Microsoft 365 and, where it matters, on-prem Active Directory, with a tamper-evident record of every change.

What it does

Runbooks, Not Checklists

Joiner, mover and leaver encoded as ordered runs — automatic steps, conditional steps, tracked manual items, and holds where a human decision is genuinely needed.

Fast Onboarding

Create a user with the right groups, licenses, manager and department — pulled live from the tenant, no typos.

Clean Offboarding

Sessions revoked, licenses reclaimed, groups cleared, mailbox handled — in a defined order, with nothing left to memory.

Tamper-Evident Audit Log

Every action is cryptographically chained — operator, tenant, target, result. Any alteration to the record is detectable.

Secretless Authentication

Federated managed identity — no stored client secret to leak, expire or walk out the door. Sensitive actions require step-up MFA.

White-Label Ready

Client edition rebrands completely — name, logo, colors and footer — so it looks like the client’s own tool.

Helix — Runbook
JOINER MOVER LEAVER
DK
Devin Kerr
IT · dkerr@acme.com · hybrid (AD-mastered)
PREVIEW
Revoke all sign-in sessions Entra
Disable user & move OU On-prem AD
Convert mailbox to shared Exchange
Remove from all groups & licenses Entra
Hold — manager confirms mailbox owner Wait
Chain verified — every step logged, untampered

Most of an offboarding isn’t Microsoft

Disabling the account is the easy part. The rest is endpoint management, device encryption, application control, remote access and DNS filtering — and if your directory is hybrid, on-prem Active Directory, where a change made in the cloud gets silently overwritten on the next sync.

Helix checks each user to find where their identity actually lives and routes every change to the system that owns it. Every runbook can be executed in preview first: you see exactly what will change, in which system, before anything is touched.

Preview before live
Every run can be executed end to end in dry-run first.
Hybrid-aware
Knows when on-prem AD is the source of truth, and writes there.
Fully logged
Every step chained and verifiable — proof, not memory.
Two editions, one repo

Host it for everyone — or hand it to one client

Same engine, two deployment modes — different tenancy and branding.

APP_MODE = multi

MSP Edition

One instance hosted by Evo IT, connecting out to many client tenants. Pick the active client and manage it from a single console.

Manage unlimited client tenants in one place
One-click client onboarding via consent link
Per-tenant Graph scoping on every call
Every action logged to a per-tenant audit chain
APP_MODE = single

Client Edition

Deployed inside the client’s own Azure tenant — their identity, their sign-in policies, their conditional access. No shared credential between environments. Evo IT just ships updates.

Runs entirely within the client’s tenant
Secretless — federated managed identity, nothing stored
Fully white-label — their name, logo & colors
Governed by their existing conditional access policies
In production today

Helix isn’t a preview. It runs the MSP console Evolution IT uses across its own client base, and a white-label client edition is deployed and in daily use inside a customer’s Microsoft 365 tenant.

See Helix on Your Tenant →

Twenty minutes, your environment, no obligation. Bring your current offboarding checklist and we’ll show you what Helix would run — and what it would catch.

In production · Secure by design · Built by Evolution IT Services