One square per observed check · unavailable data is never scored as safe
Credibility, a plan, and trust. A domain scan produces expertise and earns the appointment. The consented cloud review produces the facts the plan is built on.
What does an MSP need to close a security deal?
Credibility, a plan, and trust. A domain scan produces expertise and earns the appointment. The consented cloud review produces the facts the plan is built on.
We put a hundred dollars on the table for the beta group. Close a deal on the domain scan alone and the money is yours. Domain scan only. No cloud review, no tenant evidence, nothing but the outside view.
They tried. These are working operators with real pipelines, not people looking for a reason to fail.
Nobody won it.
That was the answer I wanted, and not because I kept the money.
Said by the company that builds one
We make a domain scanner. That belongs at the top of this, because the argument is convenient for us in one direction and inconvenient in another, and you should be able to see both.
A vendor claiming its own entry product cannot close a deal is either being honest or setting up the larger sale. Field Note 30 makes the same admission from the other side: the scanner is the acquisition mechanism, not the product. This note is that sentence tested against a pipeline instead of argued from a stage.
The claim is half right
Every domain scanner on the market promises the same thing. Run the tool, win the deal. The vendors making that claim are partially right, which is what makes it hard to argue with.
A domain scan does something real. It shows a prospect that you know where to look, that you looked before you arrived, and that you can read what you found. That is expertise, and expertise is worth having.
Expertise is not trust. A business owner can believe you are competent and still not hand you the company. The scan closes the competence question. It does not touch the other one.
What the scan is actually for
It gets the appointment. That is the whole job.
Done well it is quiet and specific. Two observations, the source, the date, and an honest statement of what cannot be seen from outside. The prospect learns something about their own business in the first five minutes and agrees to a longer conversation.
The version that does not work is loud. Picture the slide. An employee's name under the word BREACH, and a room that has gone quiet.
The record is from Hot Topic. The year is 2005. She made an account to buy a studded belt and has not thought about it since. It is not a work credential. It is not the company's domain. It is not connected to anything the MSP was asked to look at. She runs finance now, she is sitting four feet away, and she has started doing the math on what else you pulled before this meeting.
She does not still have the belt. The slide is the only thing in the room that has not moved on.
No one in that example is real. Every MSP reading it has either sat through that slide or built one.
A breach match proves an address appeared in somebody else's stolen database. It does not prove current compromise, it does not prove this company has a problem, and it does not become more true in a larger font.
That slide does not establish expertise. It establishes that you will put a colleague's name on a screen to make a point.
Three other ways to waste it. Do not use the report as a club to sell security. Do not use it to take apart the incumbent provider, who may be competent and underfunded. Do not pad it with generated language that says nothing, because the one person in the room who can tell will tell everyone else.
Why the flow works this way
The fair question is why we did not build a better external scanner and skip the second step.
Because the second step is not a packaging decision. Conditional Access coverage, enterprise application permissions, real license assignment, device state, internal OAuth relationships. None of that is hidden behind a puzzle a cleverer collector could solve. It sits behind an authorization boundary, and Field Note 32 walks the two reviews side by side for anyone who wants the detail.
So the Domain Review earns the right to ask. The Cloud Review, once the owner approves it, replaces assumptions with supported evidence. The hundred dollars tested the first half of that sentence. Nobody winning it is the reason the second half exists.
What closes
Now there are facts. Identity, permissions, licensing, what is enforced and what is merely purchased. From facts you build a plan: what to do, in what order, who owns it, and how anyone will know it worked.
Credibility comes from the facts. The plan comes from the credibility. Trust comes from how you handled the whole sequence, including the parts where you said you could not see something.
That is what closes a deal. A domain scan cannot produce any of it alone, and a hundred dollars of my own money is the cheapest proof I have that this is true.
THE SCOUTz METHOD · State the condition. Show the evidence. Name the boundary. Identify the owner. Offer the next choice.
Connected capability: Explore the consented cloud review →
Related: #30 The Scanner Is Not the Product · #32 Domain Review vs Cloud Review · #23 A Domain Scan Won't Win the Deal · What a Breach Match Actually Proves
