glacierr get in touch
typical engagement
2–8 weeks · fixed fee

stage · 02build

the hands-on part.

Hands-on configuration, implementation, automation, agent development. Anything that has to be built or shipped lives here — Sentinel cost work, Purview deployment, Defender hardening, Security Copilot agents, automations from your backlog, custom integration.

sentinel cost purview defender hardening security copilot automations

01what sits in build

hands on the keyboard.
change-controlled throughout.

Every Build engagement is consultant-led and change-controlled — the plan is signed before we touch your tenant, every change has a rollback path, and the runbook walks out the door with you, not us.

capability · 01

sentinel cost optimisation

Rebuild your ingestion strategy connector by connector. Tier moves, DCR rewrites, basic-vs-analytics splits, archive policy. Before/after invoice comparison — saving lands on the next bill, not in a slideshow.

  • per-source ingestion ranking
  • dcr design + deploy
  • tier & archive policy
  • invoice-anchored evidence
capability · 02

purview & defender implementation

Label architecture, sensitivity-based DLP enforcement, audit-trail wiring. Defender for Endpoint, Office and Identity configured against current baseline. The posture you've meant to land — landed.

  • label taxonomy + rollout
  • dlp policy enforcement
  • attack surface reduction
  • conditional access alignment
capability · 03

security copilot agents

Microsoft Security Copilot agents — off-the-shelf agents from our Security Store catalogue tuned to your tenancy, or bespoke agents built ground-up against a runbook you already trust.

  • cost & usage analyst (live)
  • identity application analyst (live)
  • bespoke agent development
  • tenant-tuned + transferred
capability · 04

automations & custom integration

The work that gets deprioritised until it causes a breach. Logic Apps, Power Automate, Sentinel playbooks, custom connectors, third-party tool integration. Four-week automation sprints or scoped per opportunity.

  • automation sprints (4 weeks)
  • sentinel playbooks
  • custom connectors
  • siem-to-soar wiring

02packages

three ways in.
fixed scope, fixed fee.

The three most-chosen packages are below. Starting prices assume standard tenancy complexity. Full menu of Build engagements — Defender Hardening Sprint, Bespoke Agent, Purview Implementation, Custom Integration — quoted on the first call. We don't charge by the day.

· fixed scope · fixed fee · milestones not hours
pkg · 01

agent · tenant-tuned

from £18k2–3 week engagement · gbp · ex vat
2–3 weeks · 2 milestones

Pick one of our Security Store agents. We deploy it into your tenant, tune it to your data and naming conventions, and hand it over.

  • cost & usage analyst, or
  • identity application analyst
  • tenant-tuned, transferred
  • two operator-training sessions
pkg · 03

sentinel cost optimisation

from £42k4–6 week engagement · gbp · ex vat
4–6 weeks · 3 milestones

Connector-by-connector ingestion rebuild. Saving lands on your next invoice, evidenced against the last one.

  • per-source ingestion ranking
  • dcr design + deploy
  • tier & archive policy
  • invoice-anchored before/after

All packages are billed against milestones, net 14 from acceptance. Travel within the UK is included. Microsoft licensing (Sentinel, Defender, Purview, Security Copilot) is held by the client.

forged on real work. shipped to the store.

Two of our Build patterns are live in the Microsoft Security Store today, both forged on real client engagements. The challenges we're handed keep our tools sharp — hardened on real problems before they reach the next team. See Evolve for how that works.

cost & usage analyst identity application analyst

03proof

three engagements.
millions saved, hardened postures.

Anonymised on purpose — references available under NDA at the second call. Sentinel cost work is the deepest track record line; the £4.2m headline is cumulative across the founder's prior engagements.

cumulative · sentinel

millions saved without reducing coverage

Cumulative annualised Sentinel ingestion reduction across the founder's prior Build engagements — fintech, healthcare, public sector. Detection coverage held or improved in every case.

£4.2m cumulative
annualised saving
manufacturing

incident triage automation, end to end

Mid-market manufacturer, Sentinel queue running 200 alerts/day at a team of three. Four-week automation sprint: enrichment, dedupe, suppression for known-benign patterns.

73% alerts handled
without analyst
financial services

defender hardening — gap closed in a month

UK challenger bank. Defender for Endpoint licensed at E5 but configured to default. Four-week sprint moved baseline posture score from 41 to 78 — no impact to user experience.

+37 defender
secure score

got a pattern you keep running by hand?

Bring it on the first call. We'll tell you on the spot whether it's a tenant-tune, an automation sprint, a Sentinel cost rebuild, or a bespoke agent — and whether it's the kind of challenge that sharpens one of our tools along the way.

also from glacierr.