Service
Access control and permission review
Permission models drift. A site created for one project becomes the unofficial archive for a department. Guest links outlive the contractor. We read the live ACL, not the intended one.
Service
Permission models drift. A site created for one project becomes the unofficial archive for a department. Guest links outlive the contractor. We read the live ACL, not the intended one.
We extract group membership, sharing links, external users, and broken inheritance. We compare that picture with the roles named in your information security and records policies.
Where the application supports item-level permissions, we sample high-risk classes: personnel files, board packs, contracts, and medical or student records if they exist in the same tenancy.
Findings are written so an administrator can act: which groups to split, which links to revoke, which libraries should stop inheriting from a parent that is too wide.
A permission heat map, a revoke-and-restructure list, and a short briefing for IT and the records owner.