Skip to content

See clearly: your free readout of the AI in place.

Your first AI inventory in ten minutes.

Your administrator authorizes read access to your tools; we deliver the three counts in your Ojja workspace. No commitment; you keep your readout.

Request a readout

The readout and Ojja Watch are in French for now.

The readout in 20 seconds

Arvenne, a fictional company · sample data

  1. Authorization requested. Ojja would like to read, without changing anything: Subscriptions and the organization's identity; Accounts and assigned licenses, with their department; each account's identifier is hashed on reading and never kept; Microsoft's announcements to your administrator (Message Center); Microsoft 365 Copilot usage, counted by application and by department; Applications in your tenant and the consents granted to them. Never your emails, documents or conversations.
  2. Reading in progress. Read in your tools, read-only. Licenses and subscriptions: read; Authorized applications: read; Settings and AI features: read; Aggregated usage reports: read. 412 accounts read; 37 applications; 14 AI features.
  3. Readout ready · the three counts. 7 AI connected by your employees to your data; 1 AI enabled by your vendors without a decision; 2 AI that trains its models on your data or sends it outside the EU.
  4. A feature to decide on. Meeting recaps · Microsoft Teams. On by default. Regularized. Left to decide: 11. Your administrator applies it; the next snapshot records it.
  5. See clearly, free. The three counts, read in your tools. ojja.ai/en/readout

See an example: Arvenne

The three counts

  1. AI connected by your employees to your data.
  2. AI enabled by your vendors without a decision.
  3. AI that trains its models on your data or sends it outside the EU.

Facts, no rating. The full list, feature by feature, comes with Ojja Watch, within seven days.

The AI included in your licenses shows separately, with its usage; so does a price increase of your suite. Microsoft 365 is read today; Google Workspace coming soon.

How it works

  1. You fill in the form below.
  2. We reply within one business day and open your workspace.
  3. You receive the email to forward to your administrator, with the authorization link.
  4. Your administrator authorizes read access: about ten minutes.
  5. We get back to you to deliver your three counts in your workspace.

On Google Workspace: we take your request now, and we get back to you as soon as Google reading opens.

What your administrator authorizes

We read licenses, settings and the AI features turned on. Never your documents, your emails, your conversations or your business data.

Ojja Reader

We never touch it

  • Organization.Read.All: Subscriptions and the organization's identity. Read the subscriptions and the organization's identity, that is, what you pay for.
  • User.Read.All: Accounts and assigned licenses, with their department; each account's identifier is hashed on reading and never kept. Count assigned licenses by SKU and by department, without keeping a single line per person.
  • ServiceMessage.Read.All: Microsoft's announcements to your administrator (Message Center). Read the announcements Microsoft publishes to your administrator, to know what turns on without a decision on your part.
  • Reports.Read.All: Microsoft 365 Copilot usage, counted by application and by department. Count how many people use Microsoft 365 Copilot, by application and by department, without keeping a single line per person.
  • Application.Read.All: Applications in your tenant and the consents granted to them. List the applications in your tenant and the consents granted to them, with the data they reach.
  • AuditLog.Read.All: Sign-in logs only, aggregated by application and by department. Count sign-ins to applications over 28 days, by application and by department, without keeping a single line per person.

Endpoints

  • GET https://graph.microsoft.com/v1.0/subscribedSkus
  • GET https://graph.microsoft.com/v1.0/users
  • GET https://graph.microsoft.com/v1.0/directory/subscriptions
  • GET https://graph.microsoft.com/v1.0/admin/serviceAnnouncement/messages
  • GET https://graph.microsoft.com/v1.0/organization
  • GET https://graph.microsoft.com/v1.0/copilot/reports/getMicrosoft365CopilotUsageUserDetail(period='D28')
  • GET https://graph.microsoft.com/v1.0/copilot/reports/getMicrosoft365CopilotUsageUserDetail(period='D180')
  • GET https://graph.microsoft.com/v1.0/servicePrincipals
  • GET https://graph.microsoft.com/v1.0/applications
  • GET https://graph.microsoft.com/v1.0/oauth2PermissionGrants
  • GET https://graph.microsoft.com/v1.0/auditLogs/signIns

Manifest v1.0, September 30, 2026

Once the readout is delivered, we read nothing more; we remind you on day 14 to remove access, and the raw extraction is purged on day 30.

Email to forward to your administrator

Subject: Authorize Ojja to read our tenant Hello, we have asked Ojja for a free readout of the AI in place in our company. Its application needs read access to our tenant: about ten minutes, with an administrator account. Ojja reads licenses, settings and the AI features turned on, never our documents, our emails or our business data. The exact list of permissions is published at ojja.ai/en/readout#autorisations. Ojja will send you the authorization link. Thank you.

Request a readout

We reply within one business day. Your address is only used for this request and is never shared.

Privacy (in French)

Who it is for

For organizations with 150 to 499 accounts, where someone owns the topic: DPO, AI lead, CFO or executive.

Below 150 accounts: Receive the feed (in French)

Questions

We already track our software.
A software management tool tracks invoice lines and seats. Ojja tracks AI feature by feature, inside each piece of software: the AI you pay for separately, the AI that is included and turned on by default, the AI billed on usage, and what sits idle, vendor by vendor. The two complement each other.