The report that shows exactly what you're paying for.
Why this exists
The hardest part of a managed relationship is knowing what you're paying for.
You sign an agreement, the work happens in the background, and the only artifact that reliably shows up afterward is the invoice. When nothing is on fire, it is hard to tell whether that is because everything is genuinely fine, or because nobody is watching closely enough to say otherwise.
So we answer it every month, in writing, whether the month was quiet or not. The report shows the exact format: SLA attainment, every incident we handled, every access change, and the advisory work behind it. It is not a summary written the night before your call. It is the record of the work.
It is the same commitment behind the math on the stack: real numbers, sourced, every time.
The sample
One month, in full.
Everything below is illustrative: a fictional company, Northwind Logistics, standing in for your environment. The format is real. The numbers are not.
Northwind Logistics: monthly service report
Coverage period: June 1 to 30, 2026 · prepared by Priya Nair, your named operator
Sample report. Northwind Logistics is a fictional demo company; nothing on this page describes a real client or a real Cloud Sentry outcome.
SLA attainment
109 of 110 requests within commitment, up from 97.9% in May
Incidents handled
11 resolved, 2 escalated and resolved, 1 monitoring
Access lifecycle
6 joiners, 3 movers, 2 leavers
Advisory activity
Recommendations delivered this month
Incidents handled
14 incidents this month, 5 shown below.
Phishing email reported by a user
Contained before anyone clicked through; the sender was blocked and the reporting employee thanked.
Elevated sign-in risk flagged on Dana Whitfield's account
Session revoked, MFA re-verified, no data access confirmed.
Suspicious PowerShell execution flagged by Defender
Investigated and confirmed a benign admin script; the detection rule was tuned to cut noise.
Recurring mail delivery delays
Escalated to Microsoft support; root cause was a transport rule conflict, corrected the same week.
Firewall rule drift on the AWS edge
Reverted to baseline configuration; watching for recurrence through July.
5 of 14 incidents shown. The other 9 followed the same pattern: triaged, actioned, and closed with a note in your record.
Access lifecycle
Joiners, movers, and leavers, tracked the same way every month.
Joiners
6
- Lena Fischer, Support analystDay-one access: email, helpdesk tools, VPN.
- Avery Lin, Field technicianDay-one access: email, mobile device enrollment, field service app.
Plus 4 more this month, same day-one pattern.
Movers
3
- Sam Okafor, Support to Security operationsAccess re-scoped the same day: case management tools added, support-queue access removed.
Plus 2 more this month.
Leavers
2
- Support contractor, engagement endedAccess revoked the same day notice was received.
- Marketing coordinator, departedAccess revoked the same day; shared files reassigned to their manager.
Advisory activity
- Reviewed the Conditional Access gaps behind May's mail-delay tickets; two policy changes recommended, one already approved.
- Completed the quarterly access review for the finance team; two stale permissions were found and removed.
- Flagged 12 unused Microsoft 365 E5 licenses for downgrade at renewal.
Reviewed with Marcus Cole, your named operator, during this month's check-in call.
What changed since last month
- Incidents: 14 this month, down from 18 in May. The drop traces to the transport rule fix that ended a run of repeat mail-delay tickets.
- SLA attainment: 99.1% this month, up from 97.9% in May.
- One of May's advisory recommendations, the finance access review, is now closed. A new one opens above.
Your version would show your own environment, not Northwind's.
Talk to us about your reportWhat makes ours different
A report is easy. A report that traces to real work is not.
Any provider can hand you a monthly report. The hard part is what sits behind it: does every line trace to something an operator actually did in your environment, or did someone assemble slides the night before the call?
Ours comes from the same system our operators work in every day. The incidents are the incidents they closed. The access changes are the requests they approved. The advisory notes are the calls we actually had. Nothing on the page was written for the report; the report was written from the work.
Typical monthly reporting
- Assembled the night before the call
- Summarizes activity in general terms
- SLA numbers you can't trace to a request
- Built to look good, not to hold up
Cloud Sentry
- Generated from the same queue our operators work in
- Every incident and access change is a real, timestamped record
- SLA state traces back to the request it came from
- The report and the work are the same record
Runs on the platform
The report comes from the same platform you'd use.
SLA state, incident records, and access changes all live in the platform first. The monthly report is a read of that record, not a separate document assembled by hand.
See it for your own environment.
Read the published plan structure, or walk the full operated partnership.
Published tiers, a written annual escalator cap, and an entry rung you can start today.
The scope, the visibility, and the work we do not take on, laid out section by section.