Method

How ShareSight worksConnect, scope, pack

Hosted control plane. Entra consent. Graph and Exchange reads. Offline HTML/CSV/ZIP for the readout room. No farm install on the main path.

Your ICT admin consents once. You toggle workloads and shortlist scope. ShareSight scans, ranks findings, and exports an offline pack. Remediation proposes changes and waits for human approval.

Sites.Selected preferred - Four workloads - Honest coverage notes - Not continuous Protect crawl

Connect without sitting in the farm

ShareSight is hosted SaaS. Your Microsoft 365 admin grants consent to the Trustholm multi-tenant app. We prefer Sites.Selected for SharePoint so the workshop does not open with a request for FullControl. Broader Graph read is available when the estate question needs it, and we document that choice.

Tokens are encrypted at rest in the Trustholm control plane. Nothing is installed into your SharePoint farm or Azure subscription for the main path.

Live scans need the Entra app registration configured so doctor reports liveReady. Until then, the demo estate still shows the Review UX and pack shape.

National clouds are documented for Entra cloud selection. That is configuration honesty, not a localisation certification claim.

Analytics dashboard with charts for fleet and monitoring operations

Workloads and scope

After connect, toggle SharePoint, OneDrive, Teams, and Exchange Online.

SharePoint walks sites and libraries for links, guests, and unique permissions. OneDrive targets people by UPN instead of cryptic my.sharepoint URLs. Teams covers membership, private and shared channel sites, guest and template-drift findings, then reuses SharePoint classifiers on team file ACLs. Exchange covers calendar delegates and well-known folder permissions (Inbox, Tasks, Contacts).

Access Evaluation is scoped on purpose. You agree depth and sampling in workshop. Coverage notes list what was walked, what was sampled, and blind spots. Deep Library Audit is the paid full unique-permission walk on named high-risk libraries. We do not pretend every first scan is estate-complete.

Permissions matrix, boards, and the offline pack

Review surfaces severity filters, who/where boards, sharing-link centre views, and permissions matrix style site/library by principal evidence. Nested Entra groups expand within a bounded depth so guest-via-group paths show up without pretending infinite recursion.

The deliverable executives forward is the HTML/CSV/ZIP pack. That is the wedge versus another admin console. IM and privacy can read the pack without four Microsoft admin centres and without granting another SaaS seat to every stakeholder. Cyber can filter Critical Anyone links and High guests for the audit conversation. Policy pack options tune workshop defaults; they are not framework certification claims.

Remediation and re-scan

Remediation Sprint proposes revoke and harden actions by finding code. Execution waits for human approval and writes an audited change log. We do not silently strip permissions in the background. That matters for government and regulated buyers.

Quarterly Re-scan and scheduled alerts cover drift after the first baseline. That is retainer motion, not continuous Protect-class crawl marketing. If your RFP requires near-real-time estate matrix freshness on day one, say so early and keep Protect-class tools in the shortlist.

How this differs from PowerShell theatre

Many estates already have partial scripts for sharing reports. Those scripts rarely produce a consistent multi-workload pack with coverage honesty, nested group notes, Teams membership findings, and a readout room agenda. ShareSight productises that workshop so MSPs and internal teams stop rebuilding the same brittle inventory every audit cycle.

The method stays the same whether you are an agency, an MSP delivering for a named client, or a mid-market IM team under Copilot pressure: connect, scope, scan, pack, decide the next engagement from evidence. Permissions matrix views support the access job without claiming continuous estate-fresh Protect matrix marketing.

What you take into the readout

Critical Anyone links, High guests and delegates, Medium unique-permission density, and Coverage notes. Who/where boards tie each finding to a site, team, personal drive, or mailbox. Sharing-link centre views help filter Anyone versus organisation-wide versus specific-people links. The HTML/CSV/ZIP pack is what leaves the room with IM and privacy.

If the pack shows a hot library, Deep Library Audit is the paid full walk. If remediations are clear, Remediation Sprint proposes and waits for approval. If leadership wants drift watch, Quarterly Re-scan starts from the baseline you just created.

Workshop sequence

The Access Evaluation week is designed for a readout, not a twelve-week platform rollout.

Kickoff and consent

Name the question, confirm workloads, complete Entra consent, agree Sites.Selected versus broader read.

Scope and scan

Shortlist sites, people, teams, mailboxes. Run the scan with agreed depth and sampling.

Pack and readout

HTML/CSV/ZIP plus severity boards. Decide Deep Audit, Remediation, or retainer from evidence.

Shipped versus honest gaps

Shipped

  • Entra consent connect path with Sites.Selected preferred
  • SharePoint, OneDrive, Teams, Exchange workloads
  • Permissions matrix / who-boards and sharing-link centre
  • Offline HTML/CSV/ZIP pack
  • Human-approved remediation and scheduled re-scan path

Honest gaps

  • Live AE blocked until customer Entra secrets make doctor liveReady
  • Not continuous Protect-class crawl
  • Teams is not a Teams admin / app governance console
  • Exchange beyond well-known folders stays out of scope

Want the method on your estate?

Book an Access Evaluation, or try the demo estate first. Bring the workloads that matter and the question your readout room must answer.

Frequently asked questions

Do you install anything in our tenant?

Not for the main path. ShareSight is hosted. Your admin grants Entra consent and we read over Graph and Exchange APIs.

What Graph permissions do you prefer?

Sites.Selected for SharePoint when it still answers the question. Broader Sites.Read.All only when needed. Avoid FullControl until remediation writes are approved.

What is a permissions matrix in ShareSight?

A site or library versus principal view of who can access what, including nested group notes where expanded. It supports the Access Evaluation readout; it is not marketed as a continuous estate-fresh Protect matrix.

How long does an Access Evaluation take?

Typical delivery is within one workshop week once consent exists. Timing depends on scope size and Graph throttling.

Can we try before buying?

Yes. The demo estate on sharesight.trustholm.com shows Review UX and pack shape without live tenant consent.

Does remediation run automatically?

No. Propose, approve, execute, audit. Silent bulk revoke is an explicit non-goal.