Kickoff and consent
Name the question, confirm workloads, complete Entra consent, agree Sites.Selected versus broader read.
Method
Hosted control plane. Entra consent. Graph and Exchange reads. Offline HTML/CSV/ZIP for the readout room. No farm install on the main path.
Your ICT admin consents once. You toggle workloads and shortlist scope. ShareSight scans, ranks findings, and exports an offline pack. Remediation proposes changes and waits for human approval.
Sites.Selected preferred - Four workloads - Honest coverage notes - Not continuous Protect crawl
ShareSight is hosted SaaS. Your Microsoft 365 admin grants consent to the Trustholm multi-tenant app. We prefer Sites.Selected for SharePoint so the workshop does not open with a request for FullControl. Broader Graph read is available when the estate question needs it, and we document that choice.
Tokens are encrypted at rest in the Trustholm control plane. Nothing is installed into your SharePoint farm or Azure subscription for the main path.
Live scans need the Entra app registration configured so doctor reports liveReady. Until then, the demo estate still shows the Review UX and pack shape.
National clouds are documented for Entra cloud selection. That is configuration honesty, not a localisation certification claim.

After connect, toggle SharePoint, OneDrive, Teams, and Exchange Online.
SharePoint walks sites and libraries for links, guests, and unique permissions. OneDrive targets people by UPN instead of cryptic my.sharepoint URLs. Teams covers membership, private and shared channel sites, guest and template-drift findings, then reuses SharePoint classifiers on team file ACLs. Exchange covers calendar delegates and well-known folder permissions (Inbox, Tasks, Contacts).
Access Evaluation is scoped on purpose. You agree depth and sampling in workshop. Coverage notes list what was walked, what was sampled, and blind spots. Deep Library Audit is the paid full unique-permission walk on named high-risk libraries. We do not pretend every first scan is estate-complete.
Review surfaces severity filters, who/where boards, sharing-link centre views, and permissions matrix style site/library by principal evidence. Nested Entra groups expand within a bounded depth so guest-via-group paths show up without pretending infinite recursion.
The deliverable executives forward is the HTML/CSV/ZIP pack. That is the wedge versus another admin console. IM and privacy can read the pack without four Microsoft admin centres and without granting another SaaS seat to every stakeholder. Cyber can filter Critical Anyone links and High guests for the audit conversation. Policy pack options tune workshop defaults; they are not framework certification claims.
Remediation Sprint proposes revoke and harden actions by finding code. Execution waits for human approval and writes an audited change log. We do not silently strip permissions in the background. That matters for government and regulated buyers.
Quarterly Re-scan and scheduled alerts cover drift after the first baseline. That is retainer motion, not continuous Protect-class crawl marketing. If your RFP requires near-real-time estate matrix freshness on day one, say so early and keep Protect-class tools in the shortlist.
Many estates already have partial scripts for sharing reports. Those scripts rarely produce a consistent multi-workload pack with coverage honesty, nested group notes, Teams membership findings, and a readout room agenda. ShareSight productises that workshop so MSPs and internal teams stop rebuilding the same brittle inventory every audit cycle.
The method stays the same whether you are an agency, an MSP delivering for a named client, or a mid-market IM team under Copilot pressure: connect, scope, scan, pack, decide the next engagement from evidence. Permissions matrix views support the access job without claiming continuous estate-fresh Protect matrix marketing.
Critical Anyone links, High guests and delegates, Medium unique-permission density, and Coverage notes. Who/where boards tie each finding to a site, team, personal drive, or mailbox. Sharing-link centre views help filter Anyone versus organisation-wide versus specific-people links. The HTML/CSV/ZIP pack is what leaves the room with IM and privacy.
If the pack shows a hot library, Deep Library Audit is the paid full walk. If remediations are clear, Remediation Sprint proposes and waits for approval. If leadership wants drift watch, Quarterly Re-scan starts from the baseline you just created.
The Access Evaluation week is designed for a readout, not a twelve-week platform rollout.
Name the question, confirm workloads, complete Entra consent, agree Sites.Selected versus broader read.
Shortlist sites, people, teams, mailboxes. Run the scan with agreed depth and sampling.
HTML/CSV/ZIP plus severity boards. Decide Deep Audit, Remediation, or retainer from evidence.
Book an Access Evaluation, or try the demo estate first. Bring the workloads that matter and the question your readout room must answer.
Not for the main path. ShareSight is hosted. Your admin grants Entra consent and we read over Graph and Exchange APIs.
Sites.Selected for SharePoint when it still answers the question. Broader Sites.Read.All only when needed. Avoid FullControl until remediation writes are approved.
A site or library versus principal view of who can access what, including nested group notes where expanded. It supports the Access Evaluation readout; it is not marketed as a continuous estate-fresh Protect matrix.
Typical delivery is within one workshop week once consent exists. Timing depends on scope size and Graph throttling.
Yes. The demo estate on sharesight.trustholm.com shows Review UX and pack shape without live tenant consent.
No. Propose, approve, execute, audit. Silent bulk revoke is an explicit non-goal.