When One Person Becomes Your Reporting Bottleneck

Sep 1, 2026

Reading Time: 2 minutes

Account activity investigation shouldn’t depend on whether the right engineer happens to be at their desk — but for a long time, ours did.There’s a specific kind of request that comes up more often than you’d think: a client needs to understand exactly what happened on an account over a given period. Maybe there’s a suspected compromise and they need a timeline. Maybe it’s a compliance question about who accessed what, and when. Whatever the trigger, the request usually lands the same way, urgently, and with an expectation that someone can just pull the answer together quickly.

When Account Activity Investigation Depends on One Person

For a while, that someone was one specific engineer on our team. He knew where to look across Teams messages, email activity, document access, and sign-in locations, and he could stitch it all together into something useful. That’s a good skill to have. It’s a bad way to run a service. If he was on leave, or already stretched across three other things, that request either waited or landed on someone with far less context, who then had to learn the process from scratch under time pressure.

Turning Account Activity Investigation Into a Repeatable Tool

So we built the process into a tool instead of leaving it in one person’s head.

It’s a straightforward idea. Give it a user and a time frame, and it goes through the relevant Microsoft 365 activity, correlates sign-in locations, messages sent and received, and documents opened, and produces a clear picture of where that person was active and when. What used to take one engineer significant focused time to compile manually now takes minutes, and it doesn’t matter who on the team is asked to run it.

Faster Account Activity Investigations, Without the Bottleneck

The value isn’t really the time saved, though that’s real. It’s that the answer no longer depends on one person’s availability or memory of how they did it last time. A client asking for this kind of detail is usually already dealing with something stressful, an incident, an investigation, a compliance deadline, and the last thing that situation needs is a delay caused by internal bottlenecks that have nothing to do with the actual problem.

Building Repeatable Capability From Individual Expertise

This is a small example of something we try to do consistently: when we notice that a piece of client work only works because of one person’s expertise, we treat that as a gap to close rather than a strength to rely on. Individual expertise still matters enormously, someone still had to know what to look for and how to interpret it in the first place. But once that knowledge exists, building it into something repeatable means it’s available whenever a client needs it, not just when the right person happens to be free.

It’s not a dramatic change. Nobody’s system got faster, nothing got more secure overnight. But the next time a client needs a clear answer about what happened on an account, they’ll get it in minutes instead of waiting for a gap in one engineer’s day.
author avatar
Rudie De Vries

Let’s connect