Who we are not
The honest boundary. The parts we cannot make cryptographic, we name rather than hide.
Most vendors publish what they are. This page is what Watchtower is not, because the boundary is the part a security-accountable buyer actually needs, and stating it is the same discipline as everything else we do.
Not a SIEM
Watchtower is not a log aggregator or a detection engine. It does not replace your SIEM and does not want your event firehose. It answers a different question: not "what happened in the last hour" but "what is the compliance state of every tenant right now, and how did it get there." It integrates with your SIEM; it is not one.
Not an MDM, and not a config manager
Watchtower reads Microsoft 365 and Intune configuration to evaluate it against your controls. It is not a device management plane and does not replace Intune. It can restore configuration to a known-good signed state, but that is a deliberate, narrow, audited operation, not ongoing configuration management.
Not lights-out automation
Watchtower can restore tenant state, apply templates, and model changes. It does not silently and autonomously remediate your environment. A write into your tenant is irreversible and externally visible, so it is gated, opt-in per tenant, attributable to a named actor, and accompanied by a cryptographic receipt for every value that moves. Autonomy is never the differentiator here. Provenance and reversibility are.
Not a vendor cloud you take on faith
Watchtower does not require you to trust someone else's cloud with your audit record. It deploys inside your boundary, and its audit trail is built so that you, not we, can verify it.
Where the boundary is contractual, not cryptographic
This is the part most vendors would leave out. Microsoft's admin-consent model grants application permissions all-or-nothing. When you consent to the Watchtower application, the write capability it may use for restore is present on the service principal even if you never enable restore. We cannot make that capability technically absent, because Microsoft does not offer a consent model that would let us.
So we do the next most honest thing. The opt-in is recorded as verifiable state. Every exercise of the capability is gated at the application layer, signed, and written to the tamper-evident audit chain. And we tell you, here, in plain language, exactly where the boundary is contractual rather than cryptographic, and why. A platform that hid that distinction would be asking for the same unexamined faith it claims to replace.
The per-tenant opt-in that gates restore and template-apply is enforced in Watchtower's own application layer, not by Microsoft - a contractual and operational boundary, not a cryptographic one.