SharePoint maze
Broken inheritance and unique permissions hide who can open a library. PowerShell theatre does not help a readout room.
A central permissions map for SharePoint, OneDrive, and Exchange Online, so IM, ICT, and security can answer exposure questions before Copilot or the next audit amplifies them.
Admin consent once. Pick the workloads that matter. Run a scoped scan. Leave with an offline report pack for the readout room, without installing anything into your SharePoint farm.
Self-serve trial is the demo estate · Fixed-fee workshop · Live tenant when you are ready
The problem
Sites, personal drives, and mailboxes each hide who can open what. Inheritance, groups, guests, anyone-links, calendar delegates, and folder permissions stack until nobody can answer a simple question. Copilot then searches everything a user can already reach.
Broken inheritance and unique permissions hide who can open a library. PowerShell theatre does not help a readout room.
Personal drives accumulate Anyone and org-wide links, often outside the sites ICT shortlisted for a SharePoint-only review.
Calendar delegates and Inbox folder permissions grant quiet access. Oversharing that sat quiet for years becomes an answer in chat.
Outcomes
Not another platform to learn. A workshop week that leaves IM, ICT, and security with the same map across the workloads you enable.
Critical Anyone links, High guests and delegates, Medium unique-permission density, ranked with location and who-has-access evidence, filterable by workload.
HTML, CSV, and ZIP you can forward to privacy, audit, or the executive without granting another admin console.
Deep Library Audit, Mailbox Access Evaluation, Remediation Sprint, or Quarterly Re-scan, only where the evidence says it is needed.
Workloads
One product, three collectors. Toggle workloads after connect. Leave with a single evidence pack and workload filters on Review.
Sites, libraries, Anyone / org / specific links, and unique permissions. Prefer least-privilege connect so you do not hand over the keys to the whole tenant by default.
Personal drives by owner, without pasting cryptic my.sharepoint URLs. Same link and guest classifiers as SharePoint.
Calendar delegates plus well-known folder permissions (Inbox, Tasks, Contacts). Mailbox-only packages when that is the job.
How it works
Your ICT admin grants consent to the Trustholm app. ShareSight reads sharing and permissions from our hosted control plane. Nothing installed in your farm.
Admin consent once. Prefer narrow SharePoint access when it still answers the question. Document OneDrive and Exchange scopes honestly.
Toggle SharePoint, OneDrive, and Exchange. Shortlist sites, people, and mailboxes with depth and sampling you agree in the workshop.
Risk-ranked findings, who/where boards, and honest coverage notes. Then HTML, CSV, and ZIP for the readout.
Propose remediations with human approval, save snapshots, and track drift on a retainer when you are ready.
Capabilities
Built for the access question competitors market as oversharing governance, scoped across workloads, evidence-ranked, and honest about depth.
Anyone / anonymous links, organisation-wide links, and specific-people sharing on sites and personal drives that open records beyond intent.
Guest users, external identities, Everyone-style principals, and Exchange calendar/folder delegates ranked by severity.
Broken inheritance and unique-permission density on libraries and OneDrive folders; well-known mailbox folder permissions on Exchange.
Every finding points back to a site, personal drive, or mailbox location and principal so the readout stays factual, filterable by workload.
Depth, sampling, permission gaps, and per-workload blind spots listed in the pack. We do not claim continuous estate-complete crawls by default.
Propose revoke and harden actions across workloads; execute only with human approval and an audited change log.
What you see
Severity language your security team recognises, packaged for people who will never live in the SharePoint, OneDrive, or Exchange admin centres.
Anyone links and passwordless anonymous sharing
Guests, external users, delegates, Everyone-style principals
Unique permission density, folder access drift, orphaned principals
Honest notes on depth, sampling, and blind spots per workload
Compare
Honest fit. We compete on the access map and engagement, not on becoming a Migrate clone or a full governance platform.
| Need | ShareSight | ShareGate Protect / SysKit | Microsoft SAM | Consulting DIY |
|---|---|---|---|---|
| Answer this workshop week | Best fit Access Evaluation + pack | Licence + onboard first | Admin reports if Copilot/SAM ready | Possible, uneven packs |
| SharePoint + OneDrive + Exchange in one pack | Core M365 Access Evaluation | Platform breadth (licence-led) | SharePoint-focused admin reports | Separate scripts per workload |
| Offline HTML/CSV/ZIP for IM/privacy | Core Core deliverable | Exports / product UI | Admin centre exports | Ad hoc |
| Continuous tenant crawl + owner reviews | Retainer / roadmap | Best fit Best fit | DAG + site access reviews | Project-based |
| Least-privilege connect | Preferred Preferred | Broad SaaS consent models | Native admin roles | Often full-control scripts |
| AU gov / records packaging | Primary GTM | Global SaaS voice | Native Microsoft | Firm-dependent |
| Content migration | Migrate (sibling product) | ShareGate Migrate (separate) | Not the job | Separate SoW |
Large enterprise governance suites that focus on provisioning, policy enforcement, and recertification solve a different buying centre than a scoped Access Evaluation.
Built for
One access map that each function can take into their own conversation.
Know whether records libraries, personal drives, and mailboxes are overshared, and forward the HTML pack without teaching three admin centres.
Find unique-permission sprawl, OneDrive links, and calendar delegates without PowerShell theatre or full-control consent by default.
Anonymous links, org-wide sharing, external principals, and folder access ranked with evidence for audit and incident playbooks.
Trust
Competitor pages lead with SOC badges. We lead with what is actually built, and what is not yet claimed.
Engagements
Fixed-fee workshop: connect, pick workloads, scoped scan, report pack, and readout. Typical delivery within one workshop week once consent exists. Payment default: 50% kickoff / 50% report.
Use ShareSight before records land, during hypercare, or as a standalone estate health review for agencies already on Microsoft 365. Migrate moves content; ShareSight proves who can see it, on sites, personal drives, and mailboxes.
Explore MigrateBook an Access Evaluation with Trustholm, or try the synthetic demo estate in minutes. No credit card, no farm install.
Those platforms are continuous Microsoft 365 governance products: tenant crawls, permissions matrices, day-2 remediation. ShareSight is the fastest path to a trustworthy answer for a scoped estate: connect, pick SharePoint / OneDrive / Exchange workloads, scan, review, and leave with an offline HTML/CSV/ZIP pack.
Start with a fixed-fee Access Evaluation; expand to deep audits and retainers when you need ongoing drift.
Native Data Access Governance reports are a strong baseline when Copilot is licensed. Use them first for admin-centre visibility. ShareSight is for when IM, privacy, or security need a forwardable evidence pack across SharePoint, OneDrive, and Exchange, a workshop readout with honest coverage notes, not another admin console export.
Yes. After connect, toggle SharePoint sites, OneDrive by person, and Exchange calendars/folders. One offline pack with workload filters on Review. Mailbox Access Evaluation is the Exchange-only package; M365 Access Evaluation covers all three.
Not for the main path. ShareSight is hosted by Trustholm. Your ICT admin grants consent; we read sharing and permissions from our control plane.
Access Evaluation uses scoped sites, OneDrive people, and/or mailboxes with depth and sampling you agree in workshop. Coverage notes list what was walked, what was sampled, and blind spots per workload. Deep Library Audit is the paid full unique-permission walk on named high-risk libraries. We do not pretend every first scan is estate-complete.
Remediation Sprint proposes changes and executes only with human approval and an audited change log. We do not silently strip permissions in the background.
Scan artefacts live in the Trustholm control plane for the engagement retention window (default 90 days unless the statement of work says otherwise). See the company trust hub for broader Trustholm posture.
Migrate moves and validates content from TRIM / Content Manager into SharePoint. ShareSight proves who can see what across sites, personal drives, and mailboxes, before records land, during hypercare, or as a standalone estate health review. They share branding and consulting motion; they are separate engagements.