A Full Admin authorizes our read-only Service App from Control Hub. Minutes, not a project — no write scopes, nothing installed.
OmniCanary keeps a complete mirror of your org — people, licenses, devices, workspaces, locations, trunks — and re-examines it every day against 14 curated policies.
Each issue says what's wrong, why it matters, and what fixing it does. Act in Control Hub — or, if you later opt in, with a previewed one-click fix.
No rule codes, no query builder. Every policy explains what it checks, why it matters, and what fixing it does — before you enable it.
Users holding multiple Calling or Meetings licenses where one would do.
Workspaces configured with no devices in them — bookable, but nothing answers.
Rooms where every device is offline. Meetings there will fail.
IP phones still assigned to disabled or deleted users.
Licenses whose owners haven't hosted a meeting in 90 days.
Configured phones that have never reached the network — usually a wrong MAC.
Monitoring uses a read-only app. Fixing uses a different app you may never authorize. They are never combined into one permission grant.
An organization that hasn't opted into remediation cannot be written to. There is no flag to flip — the capability doesn't exist.
Our CI permanently proves that every write operation is refused for read-only organizations — on every code change we ship.
Pilots are set up personally, with a Webex specialist — not a signup form. Connect read-only, run the first scan, and keep the findings either way.