{"kind":"atlas-fold-dated-history","notice":"Documentation research, not measured product performance. The first snapshot is a baseline, not a trend. Compare unchanged scope and rubric; research corrections are not product momentum.","segment":"email-security","snapshots":[{"id":"2026-09-21","publishedAt":"2026-09-21","kind":"baseline","research":{"segment":"email-security","reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"m365-email-detection-response","name":"Microsoft 365 email detection and response","scope":"Commercial Microsoft 365 inbound email protection configured for reviewable verdicts and mailbox response. Compare the stated native, integrated or API configurations as alternative operating workflows. This is not a latency or detection-efficacy ranking; inline and post-delivery paths remain explicit. Collaboration, archiving, managed response and unrelated identity products are excluded."}],"dimensions":[{"id":"maturity","name":"Operational maturity","description":"Documented progression from message inspection to controlled response. Native and API paths can satisfy the same operational stage; delivery timing remains a constraint.","question":"Can an operator inspect a verdict, apply policy-driven response and recover from a false positive?","anchors":["The vendor explicitly states that email inspection is unavailable in the selected configuration.","Documented setup for receiving and inspecting email.","Stage 1 plus reviewable verdicts and a documented manual message action.","Stage 2 plus configurable automated detection or response policy, including approval-based remediation.","Stage 3 plus an eligible-message restore path, explicit operating limits and policy scope restricted to users, groups or domains.","Stage 4 plus documented end-to-end outage recovery and controlled policy promotion."],"refinements":[{"base":3,"criteria":[{"id":"restore","label":"Documented return of an eligible remediated message to its mailbox or approved release","weight":4},{"id":"limits","label":"Explicit action recovery, delivery or provider-dependency limitations","weight":2},{"id":"scope","label":"Documented restriction of enforcement policy to named users, groups or domains","weight":4}]}]},{"id":"innovation","name":"Shipped innovation","description":"Shipped workflow beyond the established email analysis-and-response baseline, not an estimate of vendor research investment.","question":"What documented workflow advances beyond ordinary analysis, verdict review and policy-driven remediation?","anchors":["The vendor explicitly states that no automated inspection is available.","Automated message inspection.","Stage 1 plus automated classification or a guided analyst action.","Established baseline: stage 2 plus policy-driven message handling or investigation. No novelty is inferred.","Stage 3 plus a specific shipped beyond-baseline workflow with evidence of its distinction and operating limits.","Stage 4 plus multiple evidenced beyond-baseline workflows with controls and independently evaluated results."]},{"id":"breadth","name":"Capability breadth","description":"Documented threat-analysis surfaces in the selected inbound email configuration, not detection rates or the size of the surrounding suite.","question":"Which types of inbound email analysis are established?","anchors":["The vendor explicitly states that no inbound email threats are analyzed.","A documented spam or malicious-message classification.","Stage 1 plus phishing, spoofing or impersonation analysis.","Stage 2 plus documented attachment and URL inspection in the selected configuration.","Stage 3 plus account-compromise context explicitly connected to the email investigation.","Stage 4 plus documented handling and limits across forwarded, shared-mailbox and internal-mail cases."]},{"id":"ecosystem","name":"Ecosystem & integration","description":"Documented connections and interfaces for the selected Microsoft 365 message workflow.","question":"How can the mail protection workflow exchange context and actions with existing tools?","anchors":["The vendor explicitly states that external integration is unsupported.","A documented Microsoft 365 integration or native service path.","Stage 1 plus integration permissions and an external API or security-tool connection.","Stage 2 plus documented authentication and supported action or event interfaces.","Stage 3 plus operational limits and interface compatibility or deprecation guidance.","Stage 4 plus a documented extensibility lifecycle and independently exercised failure recovery."]},{"id":"governance","name":"Governance & control","description":"Authority over message inspection and response; no certification or regulatory-conformance inference.","question":"Who can inspect content, change handling and approve a release?","anchors":["The vendor explicitly states that administrative controls are absent.","Configurable message handling or release policy.","Stage 1 plus documented separation of user and administrator action permissions.","Stage 2 plus documented actor-attributed audit of administrative or response actions.","Stage 3 plus scoped administrative delegation and controlled exception approval.","Stage 4 plus exportable change evidence and documented review of access over time."]},{"id":"operations","name":"Operator enablement","description":"Procedures that help an analyst deploy, investigate and safely act on email findings.","question":"Can a practitioner follow the documented workflow and understand important failure limits?","anchors":["The vendor explicitly states that operating guidance is unavailable.","Documented onboarding or configuration steps.","Stage 1 plus instructions to inspect verdicts and take a message action.","Stage 2 plus an eligible-message recovery procedure and stated action or deployment limits.","Stage 3 plus integration diagnostics and a repeatable pilot or rollout procedure.","Stage 4 plus outage recovery, training and a documented exit procedure."]}],"assessments":[{"vendor":"microsoft-defender-office-365","cohort":"m365-email-detection-response","edition":"Microsoft Defender for Office 365 Plan 2 for Exchange Online; native threat policy, Threat Explorer and AIR; other Defender products excluded","asOf":"2026-09-21","status":"research-preview","summary":"Native Plan 2 investigation and permissioned response are documented. The assessment does not treat every AIR action as unattended or infer superior detection.","dimensions":{"maturity":{"score":3.6,"confidence":"medium","rationale":"Explorer and AIR establish review and policy-driven response. Release permissions add 0.4 and documented AIR trigger/approval limits add 0.2; scoped rollout was not independently established in this pass.","sourceIds":["s2","s3","s5"],"refinement":{"base":3,"evidence":[{"criterion":"restore","rationale":"Quarantine guidance defines administrator release and user release requests.","sourceIds":["s3"]},{"criterion":"limits","rationale":"AIR documents eligible triggers, approval behavior and required audit logging.","sourceIds":["s5"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"AIR connects automated investigation to reviewable response decisions. This is the comparison baseline, not a novelty or efficacy claim.","sourceIds":["s5"]},"breadth":{"score":3,"confidence":"medium","rationale":"The overview and Safe Attachments guidance establish phishing, URL and attachment controls. Account-compromise context across the selected workflow was not fully audited for the next anchor.","sourceIds":["s1","s4"]},"ecosystem":{"score":1,"confidence":"medium","rationale":"The native Microsoft 365 path is established. External action APIs and their permission contract were not reviewed for this offering.","sourceIds":["s1","s2"]},"governance":{"score":2,"confidence":"medium","rationale":"Quarantine policies distinguish user release requests from administrator authority; AIR specifies operator permissions. Actor-attributed change-audit coverage was not verified.","sourceIds":["s3","s5"]},"operations":{"score":3,"confidence":"medium","rationale":"Configuration, investigation and release guidance include explicit action restrictions. A complete diagnostic and pilot procedure was not established.","sourceIds":["s2","s3","s4","s5"]}},"constraints":["Plan 2 is required for the assessed investigation workflow. Some AIR actions require approval; documented cluster auto-remediation has narrower behavior.","Public documentation review only; no tenant deployment, detection benchmark, performance measurement or procurement quote was performed.","A score describes documented workflow in this selected scope. Unknown cells do not mean the capability is absent."],"sources":[{"id":"s1","title":"Defender plans and capabilities","url":"https://learn.microsoft.com/en-us/defender-office-365/mdo-about","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Plan 2 investigation and response","url":"https://learn.microsoft.com/en-us/defender-office-365/office-365-ti","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Quarantine policy permissions","url":"https://learn.microsoft.com/en-us/defender-office-365/quarantine-policies","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Safe Attachments","url":"https://learn.microsoft.com/en-us/defender-office-365/safe-attachments-about","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"AIR operation and permissions","url":"https://learn.microsoft.com/en-us/defender-office-365/air-about","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"checkpoint-email-security","cohort":"m365-email-detection-response","edition":"Check Point Email Security for Microsoft 365 with threat policy, Mail Explorer and quarantine release; selected enforcement mode must be declared","asOf":"2026-09-21","status":"research-preview","summary":"Public procedures establish configurable email handling and approval-based release. Adjacent collaboration and account-protection modules are not silently included.","dimensions":{"maturity":{"score":3.8,"confidence":"medium","rationale":"Setup, Mail Explorer and threat policy establish stage 3. Administrator-approved restoration adds 0.4 and user/group policy scope adds 0.4; comprehensive action-limit evidence was not established.","sourceIds":["s1","s2","s3","s4"],"refinement":{"base":3,"evidence":[{"criterion":"restore","rationale":"The approver can restore or decline a quarantined message.","sourceIds":["s4"]},{"criterion":"scope","rationale":"The policy walkthrough identifies included users and groups.","sourceIds":["s2"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"Configurable detection, remediation and inline prevention modes implement established email handling. No additional innovation credit follows from machine-learning language.","sourceIds":["s2","s3"]},"breadth":{"score":2,"confidence":"medium","rationale":"Phishing and impersonation analysis are explicit. Detailed attachment-and-URL operating scope was not fully audited beyond the guide’s overview.","sourceIds":["s1","s2"]},"ecosystem":{"score":1,"confidence":"medium","rationale":"The Microsoft 365 integration is documented. An authenticated external action interface was not part of this evidence set.","sourceIds":["s1","s2"]},"governance":{"score":2,"confidence":"medium","rationale":"Message policy and administrator approval of user release requests establish separated action authority. Actor-attributed audit coverage is unverified.","sourceIds":["s2","s4"]},"operations":{"score":2,"confidence":"medium","rationale":"Policy setup, Mail Explorer and release procedures are available. Detailed restoration limits were not verified, so the next operational anchor remains unestablished.","sourceIds":["s1","s2","s3","s4"]}},"constraints":["Detect, detect-and-remediate and inline prevention have different delivery behavior. The chosen tenant configuration must be verified.","Some policy and Explorer evidence is a vendor demonstration guide, not a hands-on evaluation; it supports workflow existence only.","Public documentation review only; no tenant deployment, detection benchmark, performance measurement or procurement quote was performed.","A score describes documented workflow in this selected scope. Unknown cells do not mean the capability is absent."],"sources":[{"id":"s1","title":"Email Security overview and administration scope","url":"https://sc1.checkpoint.com/documents/Harmony_Email_and_Collaboration/Email_Security/Admin_Guide/Topics/introduction/introduction-to-Email-Security.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Policy modes","url":"https://sc1.checkpoint.com/documents/Sales_tools/DemoPoint/Harmony_Email_Collaboration/Topics/Step2-Create_Policy.htm?TocPath=Demo+Steps%7C_____2","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Mail Explorer","url":"https://sc1.checkpoint.com/documents/Sales_tools/DemoPoint/Harmony_Email_Collaboration/Topics/Step3-Mail-Explorer.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Admin release process","url":"https://sc1.checkpoint.com/documents/Harmony_Email_and_Collaboration/Email_Security/Admin_Guide/Topics/admin-quarantine-release/admin-quarantine-release-process.html","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"cloudflare-email-security","cohort":"m365-email-detection-response","edition":"Cloudflare Email Security with Microsoft 365 Graph API integration and auto-moves; MX/inline features excluded","asOf":"2026-09-21","status":"research-preview","summary":"The API workflow documents post-delivery inspection, disposition-based moves and provider limitations. A mailbox move is not described as an inline gateway quarantine.","dimensions":{"maturity":{"score":3.6,"confidence":"medium","rationale":"Message investigation and auto-move policy establish stage 3. The API supports an eligible-message move to Inbox (+0.4); provider and recovery limitations add 0.2. Scoped enforcement rollout was not established.","sourceIds":["s2","s3","s4","s5"],"refinement":{"base":3,"evidence":[{"criterion":"restore","rationale":"The move endpoint accepts Inbox as a destination with an active integration; purged or unavailable messages are not promised recoverable.","sourceIds":["s5"]},{"criterion":"limits","rationale":"API deployment documents post-delivery timing, throttling, provider dependence and read/write access.","sourceIds":["s2"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"Disposition-based automated moves and message investigation meet the established baseline. No novelty or pre-delivery claim is made.","sourceIds":["s3","s4"]},"breadth":{"score":2,"confidence":"medium","rationale":"Documented malicious, spoof and suspicious dispositions establish multiple inbound threat classes. The chosen API evidence does not establish the complete attachment-and-URL anchor.","sourceIds":["s3"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"Graph integration permissions, authenticated action endpoints and explicit API field deprecations establish the interface lifecycle through stage 4. Recovery testing was not performed.","sourceIds":["s2","s4","s5"]},"governance":{"score":1,"confidence":"medium","rationale":"Disposition-based handling policy establishes stage 1. A complete separation of end-user and administrator release authority was not established for the next anchor.","sourceIds":["s3"]},"operations":{"score":3,"confidence":"medium","rationale":"Setup, message actions and an eligible Inbox move are documented with provider and recovery boundaries. A complete integration diagnostic/pilot procedure was not verified.","sourceIds":["s1","s2","s3","s5"]}},"constraints":["API messages reach the inbox before inspection. Graph outages and throttling can extend that interval.","API mode cannot supply the selected inline modification or gateway-quarantine behavior. Recovery depends on mailbox state and provider retention.","Public documentation review only; no tenant deployment, detection benchmark, performance measurement or procurement quote was performed.","A score describes documented workflow in this selected scope. Unknown cells do not mean the capability is absent."],"sources":[{"id":"s1","title":"Deployment comparison","url":"https://developers.cloudflare.com/cloudflare-one/email-security/setup/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"API deployment limitations","url":"https://developers.cloudflare.com/cloudflare-one/email-security/setup/post-delivery-deployment/api/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Configure auto-moves","url":"https://developers.cloudflare.com/learning-paths/secure-your-email/enable-auto-moves/configure-auto-moves/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Email Security API","url":"https://developers.cloudflare.com/api/resources/email_security/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"Move a message API","url":"https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/subresources/move/methods/create/","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"cisco-secure-email-threat-defense","cohort":"m365-email-detection-response","edition":"Cisco Secure Email Threat Defense with Microsoft 365 read/write remediation enabled for the selected domains; gateway products excluded","asOf":"2026-09-21","status":"research-preview","summary":"The selected service documents message actions and their limits, including Exchange Online-only remediation and recovery restrictions after deletion or purge.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"Read/write setup, automated handling, reversible message moves, explicit recovery limits and domain-scoped enforcement together establish stage 4. Outage recovery and controlled promotion remain unverified.","sourceIds":["s1","s2","s3"]},"innovation":{"score":3,"confidence":"medium","rationale":"Automated verdict handling and analyst reclassification meet the established workflow baseline. No independent novelty evidence was reviewed.","sourceIds":["s1","s2"]},"breadth":{"score":2,"confidence":"medium","rationale":"BEC, scam, phishing and malicious classifications are documented. Attachment analysis is described, but the complete selected URL-inspection contract was not verified for stage 3.","sourceIds":["s1","s2"]},"ecosystem":{"score":2,"confidence":"medium","rationale":"Microsoft permission scopes and a documented remediation/reclassification API connection establish stage 2. The external API’s authentication details were not audited.","sourceIds":["s2","s3"]},"governance":{"score":3,"confidence":"medium","rationale":"Handling policy and administrator-only permanent deletion establish stages 1–2. The message timeline attributes verdict changes and response actions to their actor, meeting stage 3. Scoped delegation with controlled exception approval remains unverified.","sourceIds":["s1","s2","s4"]},"operations":{"score":3,"confidence":"medium","rationale":"Setup, verdict review, reversible moves and explicit on-premises/purge limits satisfy stage 3. End-to-end integration diagnostics and rollout were not audited.","sourceIds":["s1","s2","s3"]}},"constraints":["Read mode cannot remediate. Read/write mode still requires the relevant policy to be enabled.","Hybrid on-premises mailboxes cannot be remediated by this service; permanent deletion or quarantine purge cannot be undone through its restore workflow.","Public documentation review only; no tenant deployment, detection benchmark, performance measurement or procurement quote was performed.","A score describes documented workflow in this selected scope. Unknown cells do not mean the capability is absent."],"sources":[{"id":"s1","title":"Threat Defense policy","url":"https://www.cisco.com/c/en/us/td/docs/security/email-threat-defense/user-guide/secure-email-threat-defense-user-guide/policy.html","accessedAt":"2026-09-21","kind":"product"},{"id":"s2","title":"Move and reclassify messages","url":"https://docs.cmd.cisco.com/en/Content/secure-email-threat-defense-user-guide/Messages/Move_and_Reclassify_Mess.htm","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Administration and setup guide","url":"https://www.cisco.com/c/en/us/td/docs/security/email-threat-defense/user-guide/secure-email-threat-defense-user-guide.pdf","accessedAt":"2026-09-21","kind":"product"},{"id":"s4","title":"Message report: actor-attributed verdict and action timeline","url":"https://docs.cmd.cisco.com/en/Content/secure-email-threat-defense-user-guide/Messages/Message_Report.htm","accessedAt":"2026-09-21","kind":"documentation"}]}],"scenarios":[{"id":"payment-change","name":"Verify a payment-change request","description":"Compare a synthetic impersonation with an authenticated but fraudulent-looking request. Technology supplies evidence; the payment owner still verifies the business instruction.","questions":["Can an analyst explain the sender and message evidence?","Which independent verification step protects the payment process?","Can a false-positive action be reversed safely?"],"priorities":["maturity","operations","governance"]},{"id":"mailbox-response","name":"Contain a delivered message","description":"Inspect the time between delivery, verdict and completed action across shared or forwarded training mailboxes.","questions":["Which copies are within the product’s supported scope?","What happens when the mail provider throttles the integration?","Which actions need approval or cannot be undone?"],"priorities":["maturity","ecosystem","breadth"]}],"researchNotes":["Baseline established 2026-09-21 from current public primary sources; no historical momentum is inferred.","A common Microsoft 365 outcome makes these workflows comparable, but their mail paths differ. Do not interpret proximity on the chart as equal protection latency or efficacy.","Integer ties are preserved. The shared maturity refinement awards only documented parts of the next anchor; weights total ten tenths. Documentation alone earns at most medium confidence.","Public documentation availability affects confidence and coverage. API functionality, licensing and tenant behavior require a controlled pilot; unsupported higher-anchor claims are not guessed."]},"changes":[]}]}