See what's shared.Across Microsoft 365.

A central permissions map for SharePoint, OneDrive, and Exchange Online, so IM, ICT, and security can answer exposure questions before Copilot or the next audit amplifies them.

Admin consent once. Pick the workloads that matter. Run a scoped scan. Leave with an offline report pack for the readout room, without installing anything into your SharePoint farm.

3Workloads in one pack
1Admin consent to connect
ZIPHTML + CSV report pack

Self-serve trial is the demo estate · Fixed-fee workshop · Live tenant when you are ready

The problem

Microsoft 365 access is hard to explain, and AI makes it urgent

Sites, personal drives, and mailboxes each hide who can open what. Inheritance, groups, guests, anyone-links, calendar delegates, and folder permissions stack until nobody can answer a simple question. Copilot then searches everything a user can already reach.

SharePoint maze

Broken inheritance and unique permissions hide who can open a library. PowerShell theatre does not help a readout room.

OneDrive sprawl

Personal drives accumulate Anyone and org-wide links, often outside the sites ICT shortlisted for a SharePoint-only review.

Mailbox and Copilot blast radius

Calendar delegates and Inbox folder permissions grant quiet access. Oversharing that sat quiet for years becomes an answer in chat.

Outcomes

What a first Access Evaluation delivers

Not another platform to learn. A workshop week that leaves IM, ICT, and security with the same map across the workloads you enable.

A shared answer

Critical Anyone links, High guests and delegates, Medium unique-permission density, ranked with location and who-has-access evidence, filterable by workload.

An offline pack

HTML, CSV, and ZIP you can forward to privacy, audit, or the executive without granting another admin console.

A clear next step

Deep Library Audit, Mailbox Access Evaluation, Remediation Sprint, or Quarterly Re-scan, only where the evidence says it is needed.

Workloads

SharePoint · OneDrive · Exchange

One product, three collectors. Toggle workloads after connect. Leave with a single evidence pack and workload filters on Review.

SharePoint

Sites, libraries, Anyone / org / specific links, and unique permissions. Prefer least-privilege connect so you do not hand over the keys to the whole tenant by default.

OneDrive

Personal drives by owner, without pasting cryptic my.sharepoint URLs. Same link and guest classifiers as SharePoint.

Exchange Online

Calendar delegates plus well-known folder permissions (Inbox, Tasks, Contacts). Mailbox-only packages when that is the job.

How it works

Connect to Microsoft 365, do not sit in it

Your ICT admin grants consent to the Trustholm app. ShareSight reads sharing and permissions from our hosted control plane. Nothing installed in your farm.

01

Connect

Admin consent once. Prefer narrow SharePoint access when it still answers the question. Document OneDrive and Exchange scopes honestly.

02

Workloads and scope

Toggle SharePoint, OneDrive, and Exchange. Shortlist sites, people, and mailboxes with depth and sampling you agree in the workshop.

03

Scan and review

Risk-ranked findings, who/where boards, and honest coverage notes. Then HTML, CSV, and ZIP for the readout.

04

Harden over time

Propose remediations with human approval, save snapshots, and track drift on a retainer when you are ready.

Capabilities

What ShareSight looks for

Built for the access question competitors market as oversharing governance, scoped across workloads, evidence-ranked, and honest about depth.

Sharing links

Anyone / anonymous links, organisation-wide links, and specific-people sharing on sites and personal drives that open records beyond intent.

Guests, delegates, and external

Guest users, external identities, Everyone-style principals, and Exchange calendar/folder delegates ranked by severity.

Unique permissions and folder access

Broken inheritance and unique-permission density on libraries and OneDrive folders; well-known mailbox folder permissions on Exchange.

Who / where boards

Every finding points back to a site, personal drive, or mailbox location and principal so the readout stays factual, filterable by workload.

Coverage honesty

Depth, sampling, permission gaps, and per-workload blind spots listed in the pack. We do not claim continuous estate-complete crawls by default.

Remediation with approval

Propose revoke and harden actions across workloads; execute only with human approval and an audited change log.

What you see

Evidence-ranked access findings

Severity language your security team recognises, packaged for people who will never live in the SharePoint, OneDrive, or Exchange admin centres.

Critical

Anyone links and passwordless anonymous sharing

High

Guests, external users, delegates, Everyone-style principals

Medium

Unique permission density, folder access drift, orphaned principals

Coverage

Honest notes on depth, sampling, and blind spots per workload

Compare

How ShareSight sits beside the market

Honest fit. We compete on the access map and engagement, not on becoming a Migrate clone or a full governance platform.

NeedShareSightShareGate Protect / SysKitMicrosoft SAMConsulting DIY
Answer this workshop weekBest fit Access Evaluation + pack Licence + onboard first Admin reports if Copilot/SAM ready Possible, uneven packs
SharePoint + OneDrive + Exchange in one packCore M365 Access Evaluation Platform breadth (licence-led) SharePoint-focused admin reports Separate scripts per workload
Offline HTML/CSV/ZIP for IM/privacyCore Core deliverable Exports / product UI Admin centre exports Ad hoc
Continuous tenant crawl + owner reviews Retainer / roadmapBest fit Best fit DAG + site access reviews Project-based
Least-privilege connectPreferred Preferred Broad SaaS consent models Native admin roles Often full-control scripts
AU gov / records packaging Primary GTM Global SaaS voice Native Microsoft Firm-dependent
Content migration Migrate (sibling product) ShareGate Migrate (separate) Not the job Separate SoW

Large enterprise governance suites that focus on provisioning, policy enforcement, and recertification solve a different buying centre than a scoped Access Evaluation.

Built for

IM, ICT, cyber, and privacy

One access map that each function can take into their own conversation.

IM / records

Know whether records libraries, personal drives, and mailboxes are overshared, and forward the HTML pack without teaching three admin centres.

ICT / Microsoft 365

Find unique-permission sprawl, OneDrive links, and calendar delegates without PowerShell theatre or full-control consent by default.

Cyber and privacy

Anonymous links, org-wide sharing, external principals, and folder access ranked with evidence for audit and incident playbooks.

Trust

Security posture we will stand behind

Competitor pages lead with SOC badges. We lead with what is actually built, and what is not yet claimed.

Shipped

  • Hosted connect via Microsoft 365 admin consent
  • SharePoint + OneDrive + Exchange workloads in one product
  • Encrypted token storage and redaction on exports
  • Consultant sessions and engagement audit log
  • Human-approved remediation path
  • Default retention window (typically 90 days)

Honest gaps

  • No SOC 2 / ISO certification claims yet
  • Not a continuous Protect-class tenant crawl today
  • Teams channel files via underlying SharePoint sites (not a separate collector)
  • Nested group expansion is limited (not infinite)
  • Exchange subfolders beyond well-known Calendar/Inbox/Tasks/Contacts are out of scope

Engagements

Start with Access Evaluation

Fixed-fee workshop: connect, pick workloads, scoped scan, report pack, and readout. Typical delivery within one workshop week once consent exists. Payment default: 50% kickoff / 50% report.

M365 Access Evaluation

Fixed fee · SharePoint + OneDrive + Exchange · one offline pack

  • Workload picker after admin consent
  • Sites, OneDrive people, and mailbox shortlist
  • Combined Review with workload filters
  • HTML/CSV/ZIP evidence pack + executive readout

Access Evaluation

Fixed fee · SharePoint-scoped workshop + pack

  • Kickoff + site shortlist
  • Least-privilege connect path preferred
  • Government-default policy pack options
  • Optional OneDrive / Exchange add-on to M365 AE

Mailbox Access Evaluation

Fixed fee · Exchange calendars and folder access

  • Calendar delegates + Inbox/Tasks/Contacts
  • Mailbox-scoped workshop path
  • Offline pack + optional remediation proposals

Deep Library Audit

Fixed per library band · Full unique-permission walk

  • Named high-risk libraries
  • Complete unique-permission walk
  • Evidence URLs per finding

Remediation Sprint

Fixed or T&M cap · Guided revoke and harden

  • Human-approved writes only
  • Audited change log across workloads
  • No silent background strip

Quarterly Re-scan

Retainer · Snapshot drift vs last baseline

  • Scheduled re-scan
  • Drift report + Critical alerts path
  • Retainer readout

Pair with Migrate

Use ShareSight before records land, during hypercare, or as a standalone estate health review for agencies already on Microsoft 365. Migrate moves content; ShareSight proves who can see it, on sites, personal drives, and mailboxes.

Explore Migrate

Ready for a clear Microsoft 365 access map?

Book an Access Evaluation with Trustholm, or try the synthetic demo estate in minutes. No credit card, no farm install.

Frequently asked questions

How is ShareSight different from ShareGate Protect or SysKit Point?

Those platforms are continuous Microsoft 365 governance products: tenant crawls, permissions matrices, day-2 remediation. ShareSight is the fastest path to a trustworthy answer for a scoped estate: connect, pick SharePoint / OneDrive / Exchange workloads, scan, review, and leave with an offline HTML/CSV/ZIP pack.

Start with a fixed-fee Access Evaluation; expand to deep audits and retainers when you need ongoing drift.

We already have Microsoft SharePoint Advanced Management / Copilot. Do we still need this?

Native Data Access Governance reports are a strong baseline when Copilot is licensed. Use them first for admin-centre visibility. ShareSight is for when IM, privacy, or security need a forwardable evidence pack across SharePoint, OneDrive, and Exchange, a workshop readout with honest coverage notes, not another admin console export.

Do you cover OneDrive and Exchange as well as SharePoint?

Yes. After connect, toggle SharePoint sites, OneDrive by person, and Exchange calendars/folders. One offline pack with workload filters on Review. Mailbox Access Evaluation is the Exchange-only package; M365 Access Evaluation covers all three.

Do you install anything in our Microsoft 365 tenant or Azure subscription?

Not for the main path. ShareSight is hosted by Trustholm. Your ICT admin grants consent; we read sharing and permissions from our control plane.

How complete is a first scan?

Access Evaluation uses scoped sites, OneDrive people, and/or mailboxes with depth and sampling you agree in workshop. Coverage notes list what was walked, what was sampled, and blind spots per workload. Deep Library Audit is the paid full unique-permission walk on named high-risk libraries. We do not pretend every first scan is estate-complete.

Can you revoke sharing links and fix permissions?

Remediation Sprint proposes changes and executes only with human approval and an audited change log. We do not silently strip permissions in the background.

Where does data live, and for how long?

Scan artefacts live in the Trustholm control plane for the engagement retention window (default 90 days unless the statement of work says otherwise). See the company trust hub for broader Trustholm posture.

How does this relate to Trustholm Migrate?

Migrate moves and validates content from TRIM / Content Manager into SharePoint. ShareSight proves who can see what across sites, personal drives, and mailboxes, before records land, during hypercare, or as a standalone estate health review. They share branding and consulting motion; they are separate engagements.