Microsoft 365 permission & sharing intelligence
We map who can actually reach every file in SharePoint - through every group, sharing link and broken-inheritance carve-out - plus every external share, down to the recipient. Read-only, interpreted by a named architect, and yours to keep. Config scoring is included; it is the floor, not the point.
Read-only, least-privilege Microsoft-verified publisher £1M professional indemnity
One account's real reach: Colin Rathbone lands on 16 sites - mostly through group nesting, two by direct grant - and inside them, 12 files where his access breaks from the site default. This is what a leaver, a contractor, or a busy admin account can actually get to. Static sample; the live report is fully interactive.
Independent, on the record
"You can't grade your own homework and hand it to your insurer."
A security score you generated about yourself is fine for internal tidying. But the moment someone external needs to trust your posture - a cyber-insurer, an auditor, your board, a client doing due diligence, an acquirer - self-assessment carries no weight.
An independent assessment, run by a named person who is accountable for the findings and carries £1M professional-indemnity cover, is evidence those parties will accept. That independence is structural: a tool you run yourself can never be independent of you.
Who this is for
The permission map nobody else shows you
This is the RBAC relationship map: every principal that reaches a site - the default SharePoint groups, the site admins, security groups and any direct grant - grouped by how far that reach goes, plus the libraries and the items inside where permissions break from the site default. Pick a person instead and the map reverses: everything they can reach, and exactly how they got it.
And it is honest about what it knows. Where a group's membership is only inferred from the site's nesting rather than independently confirmed, we mark it default rather than pretend certainty - the distinction an auditor actually cares about. Counts are shown both ways for the same reason: 6/43 scopes means six places on the site you are looking at, forty-three across the estate.
Default = group membership inferred from the site's nesting, not independently confirmed. Everything routes through the site (it is on the access path); the right column breaks inheritance from it. Static sample; the live report is fully interactive.
How to read the permission map
One panel compares a single folder or file against the site it lives in, at the same moment. It appears only where that item has unique permissions - inheritance from the site was broken and its access set on its own. A structural difference, not a change over time.
The site
Access everyone here inherits
This item · a carve-out
Unique permissions · inheritance broken
+ Added here
People granted access to this specific item, beyond the site's normal access - a deliberate carve-out that adds access.
− Removed here
People who can reach the wider site but have been excluded from this item - inheritance was intentionally broken. They are still on the site, just not this item.
Carve-outs are the exceptions to the rule - the exact spots where normal access has been overridden, tightened or loosened. That is where accidental over-sharing and awkward lockouts hide.
Not to be confused with drift, a separate view that shows what changed over time between assessments. One is structure; the other is time.
How to read the drift view
The retainer re-runs the whole assessment each quarter and compares it against the last run - on two axes. The assessment diffs your posture: findings closed, new and regressed, with the score as a trend. The permission map diffs your access: who gained reach, whose level went up, and what was removed. The opposite of the carve-out panel: that is structure at a single moment; this is change over time.
Posture drift · from the assessment
Last quarter
Where the prior run left things
This quarter · what changed
Closed, new and regressed since last run
Reachability drift · from the permission map
This quarter · what access changed
The permission map diffed against the prior run: who gained reach, and how
✓ Closed
Findings you fixed since last time - the proof that remediation landed and held.
+ New or regressed
A finding that appeared, or one that came back - caught the quarter it happens, not a year later.
↑ Access drift
The map diffed run over run: new reach, escalations and removals - the access changes no scanner reports.
Posture and access both become trend lines you can prove - fewer findings quarter over quarter, privilege creep caught the quarter it happens, and anything that slips back flagged the moment it does. That is what a retainer buys that a one-off PDF never can.
The layer no scanner touches
Free scanners and native scoring both grade your configuration. That is the floor - useful, and now table stakes. Our value is the layer above it, and it is three things nobody automates.
Not “sharing is on”. Who, what and how - across SharePoint and OneDrive, through every group, sharing link and broken-inheritance carve-out - plus the external-sharing deep-dive, down to the named recipient.
The same architect re-runs the whole engagement each quarter and reads you what moved - the config baseline tracked control by control, and your reachability and sharing re-mapped and read afresh - a real quarter-over-quarter read, not a dashboard auto-diffing a config file.
A named architect runs it, interprets it, prioritises it and sits with you to explain it - backed by professional indemnity. Free tools produce output and disclaim advice; we own the answer.
"Why not just run a free scanner?"
Run a free scanner and you will get a config score. We start where that stops: who can actually reach your data, what is over-shared, and what to do about it first - interpreted by a person who is accountable for the answer.
The floor is worth having - we simply do not stop there. What matters is who can actually reach what, and a person on the record for what to do about it first.
What we add
The floor · free scanners & native scoring
A configuration score - what is set, checked against a list. It cannot tell you who can reach what, or stand behind the answer.
The included foundation
The map and the trend sit on that config baseline: your posture across identity, email, Teams, devices and data protection, scored against the Glow Cloud M365 Security Framework. It is included in every engagement - and we do it straight. No false passes, no false fails, and features you are not licensed for are never marked against you.
The checks that can be evidenced from your configuration, scored and shown with the evidence.
The judgement calls, flagged with the exact portal page to check. Never a false auto-pass.
Licence-aware: features you do not own are marked not applicable, not failed.
A report you own, not a portal you rent
Most Microsoft 365 governance tools are subscription portals: a standing connection to your tenant, your data living in their cloud, and a bill that never stops. We work the other way round - a read-only look, a self-contained report you own and keep, and nothing left behind.
The working data behind an assessment stays on our own secured machine, never a standing dataset in someone else's cloud and never in a portal you have to sign in to. We sweep delivered copies on a regular cycle, and we delete everything for a client on request, in writing, at any time. Retainer clients keep prior runs by design, because the quarter-over-quarter drift is computed from them.
What lands in your inbox
| Glow Cloud Security A report you own | A governance portal A subscription you rent | |
|---|---|---|
| Your data | A report you own; delivered copies swept on a regular cycle, and everything deleted on request. | Lives in their cloud for as long as you keep subscribing. |
| What you get | A self-contained, interactive report - yours to keep for good. | A dashboard you log into, and lose the day you cancel. |
| Access | Read-only, point-in-time, and revocable the moment we're done. | A standing, always-on connection into your tenant. |
| The permission map | Who can reach which file, and exactly how they got there. | Setting-level flags - rarely the real-world consequence. |
| Scoring | Honest: features you are not licensed for are never marked against you. | One blunt score, often padded to look thorough. |
| Cost | A one-off fixed price, or a light quarterly retainer for drift tracking. | An open-ended per-tenant subscription. |
Comparison is with typical subscription-based Microsoft 365 governance platforms, described in general terms. No specific product is named or implied.
Focus, not a firehose
Always-on monitoring never stops talking. Most teams don't have someone watching a dashboard at 2am, so the alerts pile up unread and nothing actually gets fixed. We give you the opposite: a fixed, prioritised picture of where you stand, and a short list of what to change first - work you can finish, not a stream you have to babysit.
This is posture, not an alarm. Live monitoring answers "is someone in my tenant right now?"; our assessment answers "is it configured and shared safely, and what do I fix first?" - a different job. And your configuration posture doesn't change every second: it changes when someone changes something, which is exactly what the quarterly re-read is built to catch.
Plan remediation against a baseline that isn't moving under you - close the top items, then re-measure.
A document you own and can hand to an insurer, board or auditor. A live feed is not evidence you can file.
Quarterly drift tracking surfaces what moved since last time, without the always-on noise.
Pricing
Tell us which report you need and book a 30-minute onboarding call - we run the assessment and hand you a self-contained report you own and keep. A one-off engagement, or a quarterly retainer for ongoing assurance. No portal, no subscription, no lock-in.
Free
Free
Oversharing exposure and a Copilot-readiness verdict, across six areas. The free way in - you keep the report whether or not you go further.
Signature
£1,750
The signature deliverable, and the one nothing else on the market produces: a visual map of who can reach which sites, libraries, folders and files - and how they got there, whether through a group, a sharing link or a direct grant. Principals are grouped by how far their reach goes - site-wide, into specific libraries only, or nothing but a single shared file - and libraries holding their own permissions are drawn in their own lane, so per-library compartmentalisation is visible rather than rolled up. Includes per-user reachability, compare-two-users, broken-inheritance carve-outs, and a raw data export your admin team can work from. Included in the Complete engagement below. Report within 5 business days of access.
Live readout with the architect who ran it
Tenants over ~250 SharePoint sites? Book a call for a scoped quote →Reachability
£1,000
A complete map of external sharing and access exposure: every sharing link, every broken-inheritance file, and who can reach what - down to the named recipient. Includes the per-site and per-link breakdown from a read-only crawl. The oversharing Copilot will surface on day one - found first. For tenants up to ~250 SharePoint sites; larger tenants, book a call for a scoped quote. Report within 5 business days of access.
Live readout with the architect who ran it
Tenants over ~250 SharePoint sites? Book a call for a scoped quote →Posture + sharing
£2,200
The sharing deep-dive and the config baseline in one run: every external share down to the named recipient, plus your posture across identity, email, Teams, SharePoint, devices and data protection. It does not include the permission map - if you want to see who can actually reach what, take the Complete engagement. For tenants up to ~250 SharePoint sites; larger tenants, book a call. Report within 5 business days of access.
Live readout with the architect who ran it
Tenants over ~250 SharePoint sites? Book a call for a scoped quote →Complete
£2,700
Everything, in one read-only run: the config baseline, the external-sharing deep-dive down to the named recipient, and the permission map. This is the engagement that answers the whole question - what is configured, what is shared, and who can actually reach it - from a single crawl of your tenant. Most buyers who are assessing risk rather than ticking a box take this one. For tenants up to ~250 SharePoint sites; larger tenants, book a call. Report within 5 business days of access.
Live readout with the architect who ran it
Tenants over ~250 SharePoint sites? Book a call for a scoped quote →Retainer
from £7,500 /yr
Your posture as a tracked record rather than four separate reports. Each quarter we re-run the complete engagement and diff it against your held baseline: what closed, what regressed, what is new, and whether last quarter's fixes actually held. The history is the deliverable. It is what lets you show an insurer, a board or an auditor a direction of travel instead of a snapshot, and it is the one thing a first assessment cannot give you at any price - it only exists once there is a prior run to measure against. Same architect every quarter, and your baseline held between runs so the comparison is real.
A live readout every quarter, same architect
Foundation
£1,500
The config baseline on its own: your posture across identity, email, Teams, SharePoint, devices and data protection, scored against the Glow Cloud M365 Security Framework - honestly, and licence-aware. The included foundation, available standalone; most buyers take it inside the Full Suite. Report within 3 business days of access.
Live readout with the architect who ran it
Buying more than one? We bundle them when we scope, because one read-only crawl feeds all of it - you are never charged twice for the same scan. The Complete engagement is the fully bundled price; any other combination we quote when we scope.
One read-only approval covers most of the assessment - identity, email, storage, Purview, Intune, licensing and more. Two minutes, needs a Global Administrator.
Two further approvals are set up together on your onboarding call:
Skip the Fabric setting and the assessment still runs, with those checks clearly marked "requires consent" in your report, never silently missing and never guessed. Skip the SharePoint account and the map is shallower rather than absent, and we will say so at the readout. Nothing is scored against you for access you chose not to grant. And the price is the price: full coverage costs nothing extra - the only thing gating your report is what you choose to grant.
The fine print, plainly
Engaging us means you agree to our terms & policies.
Sample reports
Melbrooke Ltd is a fictional company generated through the real engine - real, drillable reports in your browser, zero client data. No install, no email needed.
Inside the reports
Clear, interactive reports from one read-only run. The visuals below mirror the Melbrooke Ltd demo: fictional company, real engine.
Melbrooke Ltd · 13 domains · 54 of 166 controls passing
Compliance by domain
Entra, Intune, SharePoint, email, data and auditing, each control marked Pass, Partial, Fail or Manual across the whole Glow Cloud M365 Security Framework, so you see precisely where the gaps are.
Melbrooke Ltd · July 2026
Significant gaps
Multiple high-severity controls are failing. Address the priorities below before enabling Copilot or broad collaboration.
Top priorities
Executive summary
A clear verdict and the High-severity priorities to act on first, so the readout takes minutes, not a wade through a spreadsheet.
Glow Cloud Framework · SPG-AUTH-201 · Account & Authentication
What we found
No all-users MFA Conditional Access policy, and security defaults are off - MFA is not enforced tenant-wide.
Why it matters
Without enforced MFA, a single stolen password is enough to take over an account - the primary path to account takeover and lateral movement.
Recommended action
Enforce MFA for all users via Conditional Access (pilot in report-only first), then disable security defaults.
Evidence · GET /identity/conditionalAccess/policies · GET /policies/authenticationMethodsPolicy
Every finding, in full
Each finding carries its framework control reference, what we found, why it matters, a recommended action and the evidence behind it. See a complete sample report, filterable by platform, domain, type, severity and status.
The sharing deep-dive
Every site ranked by exposure (per-site), then every individual link drilled down to who can reach it, what it exposes and whether it ever expires (per-link), delivered as two separate reports.
Melbrooke Ltd · 40 sites · SharePoint & OneDrive
Melbrooke Ltd · SharePoint & OneDrive
Named to the person, not just the domain: 32 external recipients surfaced across the guest links. Highest risk here - /Finance/Aged Debtors 2026.xlsx, an "Anyone" edit link anyone with the URL can change.
How it works
You grant a read-only, least-privilege app. The assessment app only ever reads, and never writes to your tenant. On a large estate some sites cannot be read that way; where that happens we agree a temporary permission on just those sites with you first, and remove it when the run is done.
We map who can reach what across your SharePoint sites, trace external sharing across SharePoint and OneDrive, and assess the config baseline. Read-only throughout, no agents, no disruption. Most of the run uses the read-only app; the permission map and the OneDrive sharing checks need one SharePoint Administrator sign-in during the scan window.
A self-contained, interactive report: prioritised findings, the sharing deep-dive and the permission map. Yours to keep.
Re-run each quarter and see exactly what improved, control by control.
Assessed against the Glow Cloud M365 Security Framework - our own control set, refined across years of hands-on Microsoft 365 governance work.
Who it's for
Security-conscious and regulated organisations - finance, legal, pharma, professional services - and any team rolling out Microsoft 365 Copilot who needs proof their data is not overshared.
"Built by a Microsoft 365 architect who got tired of audits that stop at a settings screen. The permission map is the report I always wanted to hand a client and could never buy."
Read-only, least-privilege
We never change your environment.
Microsoft-verified publisher
Verified on the consent screen.
£1M professional indemnity
Insured, boutique, accountable.
A named architect, not a portal
The same person runs it, presents it, and stands behind it.
Point-in-time assessment; not a certification or accredited audit; not legal advice. Assessments can be aligned to recognised industry best practice on request.
Questions, answered
You grant a read-only, least-privilege app, and we never write to your tenant. Access is revocable at any time, and every read shows in your own audit log. Most of the assessment runs app-only with nobody signed in. Some stages are the exception: reading each site’s own permission list, and certain tenant-level SharePoint settings, needs a signed-in administrator rather than an app. You create a dedicated SharePoint Administrator account for the engagement and disable it when we hand over; a full run signs into it at up to three points, and we do the signing in, so nobody of yours has to be available overnight. Without it the map still renders, but it shows access rolled up to the site and misses the library-level detail that makes it worth having.
Nowhere you have to log into. The assessment produces a single, self-contained report you own and keep, and nothing about your tenant sits in a portal you have to sign in to. The working data behind it stays on our own secured machine. We sweep delivered copies on a regular cycle, and we delete everything for a client on request, in writing, at any time. Retainer clients keep prior runs by design, because the quarter-over-quarter drift is computed from them.
The reachability map - who can reach which file, and exactly how - a link-by-link external-sharing deep-dive down to the recipient, and a config baseline across Entra, email, Teams, SharePoint, devices and data protection. All scored against the Glow Cloud M365 Security Framework, licence-aware and honest.
Free scanners and native scoring grade your configuration - that is the floor, and it is useful. We start above it: who can actually reach your data, what is over-shared, and what to fix first - interpreted by a named architect who is accountable for the answer. A config score cannot tell you who can reach what, or stand behind the finding.
Yes. We surface the oversharing and broad access Copilot would expose to staff on day one, so you can fix it before switching Copilot on.
No. It is a point-in-time assessment, not a certification or accredited audit, and not legal advice. Assessments can be aligned to recognised industry best practice on request.
No. Every paid engagement includes a live readout with the architect who ran it - we walk your team through the findings, what they mean for your estate specifically, and what to do first. The report is yours to keep and is written to be read without us, but the readout is where most of the value lands: the questions that matter are almost always about your data, not about the method. Retainer clients get one every quarter.
The Complete engagement - config baseline, sharing deep-dive and permission map in one run - is £2,700, and is what most buyers take. Individually: the Permission (RBAC) Map is £1,750, the Sharing & Permission Deep-Dive is £1,000, the Full Suite (baseline and deep-dive, no map) is £2,200, and the config baseline on its own is £1,500. The quarterly retainer starts at £7,500/yr and includes four complete engagements, the drift comparison between them, and a readout each quarter. The Copilot-readiness health-check is free.
Your report lands within 3 business days of access for the Assessment, and within 5 business days for the Deep-Dive, Full Suite and RBAC Map.
The fixed prices cover a tenant of up to around 250 SharePoint sites - typically a few hundred users, though headcount is only half of it. The effort, and the size of the reports, scale with the number of sites, and a small team can easily have thousands. Above that the work is scoped individually, and we will always confirm the price before anything starts. Tell us roughly how many sites you have, or just book a call.
The assessment still runs, and anything that needed a consent you chose not to grant is marked “requires consent” in your report rather than being silently missing, guessed at, or scored against you. One approval works differently and we would rather say so: if you decline the SharePoint Administrator sign-in, the permission map still renders, but it shows access rolled up to the site instead of down to the library. We will tell you at the readout if that happened.
Yes - it is a fixed-scope engagement: a full refund if we cannot gain read-only access within 5 business days. Once the assessment run begins it is non-refundable.
Ready to see who can reach what?
Tell us your tenant and we will arrange a read-only access window. No sales call required, and no obligation.
Request your assessment
No cost to ask. No sales call required.
Prefer email? hello@glowcloud.uk
We use your details only to respond. See our privacy & cookies policy.