Service

Access control and permission review

Permission models drift. A site created for one project becomes the unofficial archive for a department. Guest links outlive the contractor. We read the live ACL, not the intended one.

Typical duration: Two to four weeks

People reviewing documents and a laptop in a meeting

We extract group membership, sharing links, external users, and broken inheritance. We compare that picture with the roles named in your information security and records policies.

Where the application supports item-level permissions, we sample high-risk classes: personnel files, board packs, contracts, and medical or student records if they exist in the same tenancy.

Findings are written so an administrator can act: which groups to split, which links to revoke, which libraries should stop inheriting from a parent that is too wide.

What we examine

  • Site, library, and item permission inheritance
  • Sharing links, anonymous access, and expiry
  • External and guest accounts still active
  • Privileged roles and service accounts
  • Separation between draft and declared records

What you receive

A permission heat map, a revoke-and-restructure list, and a short briefing for IT and the records owner.

Ask for a scope on this work