SharePoint maze
Broken inheritance and unique permissions hide who can open a library. PowerShell theatre does not help a readout room.
A permissions and oversharing map for SharePoint, OneDrive, Teams, and Exchange Online, so IM, ICT, and security can answer exposure questions before Copilot or the next audit amplifies them.
Admin consent once. Pick the workloads that matter. Run a scoped scan. Leave with an offline report pack for the readout room, without installing anything into your SharePoint farm.
Self-serve trial is the demo estate · Fixed-fee Access Evaluation · Live tenant when Entra is ready
The problem
Sites, personal drives, Teams membership, and mailboxes each hide who can open what. Inheritance, groups, guests, anyone-links, calendar delegates, and folder permissions stack until nobody can answer a simple question. Copilot then searches everything a user can already reach.
Broken inheritance and unique permissions hide who can open a library. PowerShell theatre does not help a readout room.
Guest owners, shared channels, and personal Anyone links sit outside a SharePoint-only review. Copilot still reaches them.
Calendar delegates and Inbox folder permissions grant quiet access. Oversharing that sat quiet for years becomes an answer in chat.
Outcomes
Not another platform to learn. A workshop week that leaves IM, ICT, and security with the same map across the workloads you enable.
Critical Anyone links, High guests and delegates, Medium unique-permission density, ranked with location and who-has-access evidence, filterable by workload.
HTML, CSV, and ZIP you can forward to privacy, audit, or the executive without granting another admin console.
Deep Library Audit, Mailbox Access Evaluation, Remediation Sprint, or Quarterly Re-scan, only where the evidence says it is needed.
Workloads
One product, four collectors. Toggle workloads after connect. Leave with a single evidence pack and workload filters on Review.
Sites, libraries, Anyone / org / specific links, and unique permissions. Prefer least-privilege connect so you do not hand over the keys to the whole tenant by default.
Personal drives by owner, without pasting cryptic my.sharepoint URLs. Same link and guest classifiers as SharePoint.
Team and channel membership, private and shared channel sites, guest and template-drift findings. Not a Teams admin or app-governance console.
Calendar delegates plus well-known folder permissions (Inbox, Tasks, Contacts). Mailbox-only packages when that is the job.
How it works
Your ICT admin grants consent to the Trustholm app. ShareSight reads sharing and permissions from our hosted control plane. Nothing installed in your farm.
Admin consent once. Prefer narrow SharePoint access when it still answers the question. Document OneDrive, Teams, and Exchange scopes honestly.
Toggle SharePoint, OneDrive, Teams, and Exchange. Shortlist sites, people, teams, and mailboxes with depth and sampling you agree in the workshop.
Risk-ranked findings, who/where boards, permissions matrix views, and honest coverage notes. Then HTML, CSV, and ZIP for the readout.
Propose remediations with human approval, save snapshots, and track drift on a retainer when you are ready.
Capabilities
Built for the access question competitors market as oversharing governance, scoped across workloads, evidence-ranked, and honest about depth.
Anyone / anonymous links, organisation-wide links, and specific-people sharing on sites and personal drives that open records beyond intent.
Guest users, external identities, Everyone-style principals, Teams guests, and Exchange calendar/folder delegates ranked by severity.
Site/library × principal views, broken inheritance density, nested group paths (bounded), and well-known mailbox folder permissions.
Every finding points back to a site, team, personal drive, or mailbox location and principal so the readout stays factual, filterable by workload.
Depth, sampling, permission gaps, and per-workload blind spots listed in the pack. We do not claim continuous estate-complete crawls by default.
Propose revoke and harden actions across workloads; execute only with human approval and an audited change log.
What you see
Severity language your security team recognises, packaged for people who will never live in the SharePoint, Teams, OneDrive, or Exchange admin centres.
Anyone links and passwordless anonymous sharing
Guests, external users, delegates, shared-channel external, Everyone-style principals
Unique permission density, folder access drift, excessive team owners, orphaned principals
Honest notes on depth, sampling, and blind spots per workload
Compare
Honest fit. We compete on the access map and Access Evaluation engagement, not on becoming ShareGate Migrate or a full continuous Protect platform.
| Need | ShareSight | ShareGate Protect / SysKit | Microsoft SAM | Consulting DIY |
|---|---|---|---|---|
| Answer this workshop week | Best fit Access Evaluation + pack | Licence + onboard first | Admin reports if Copilot/SAM ready | Possible, uneven packs |
| SharePoint + OneDrive + Teams + Exchange in one pack | Core M365 Access Evaluation | Platform breadth (licence-led) | SharePoint-focused admin reports | Separate scripts per workload |
| Offline HTML/CSV/ZIP for IM/privacy | Core Core deliverable | Exports / product UI | Admin centre exports | Ad hoc |
| Continuous tenant crawl + owner reviews | Scheduled re-scan / retainer | Best fit Best fit | DAG + site access reviews | Project-based |
| Least-privilege connect | Preferred Sites.Selected preferred | Broad SaaS consent models | Native admin roles | Often full-control scripts |
| AU gov / records packaging | Best fit Primary GTM | Global SaaS voice | Native Microsoft | Firm-dependent |
| Content migration | Migrate (sibling product) | ShareGate Migrate (separate) | Not the job | Separate SoW |
ShareGate Protect wins when you need continuous estate crawl and day-2 owner workflows as the default. ShareSight wins when you need a trustworthy Access Evaluation this workshop week. Deep pages: ShareGate, SysKit Point, AvePoint Insights.
Built for
One access map that each function can take into their own conversation.
Know whether records libraries, personal drives, Teams, and mailboxes are overshared, and forward the HTML pack without teaching four admin centres.
Find unique-permission sprawl, Teams guests, OneDrive links, and calendar delegates without PowerShell theatre or full-control consent by default.
Anonymous links, org-wide sharing, external principals, and folder access ranked with evidence for audit and incident playbooks.
Trust
Competitor pages lead with SOC badges. We lead with what is actually built, and what is not yet claimed.
Engagements
Fixed-fee workshop: connect, pick workloads, scoped scan, report pack, and readout. Typical delivery within one workshop week once consent exists. Payment default: 50% kickoff / 50% report.
Use ShareSight before records land, during hypercare, or as a standalone estate health review for agencies already on Microsoft 365. Migrate moves content; ShareSight proves who can see it, on sites, personal drives, Teams, and mailboxes.
Explore MigrateBook an Access Evaluation with Trustholm, or try the synthetic demo estate in minutes. No credit card, no farm install.
Those platforms are continuous Microsoft 365 governance products: tenant crawls, permissions matrices, day-2 remediation. ShareSight is the fastest path to a trustworthy answer for a scoped estate: connect, pick SharePoint / OneDrive / Teams / Exchange workloads, scan, review, and leave with an offline HTML/CSV/ZIP pack.
Start with a fixed-fee Access Evaluation; expand to deep audits and retainers when you need ongoing drift. Read the ShareGate compare page for Protect versus Migrate disambiguation.
For permissions and oversharing visibility, yes that is the SEO and buying conversation we own. We are not a ShareGate Migrate alternative (that is Trustholm Migrate). We are not a full Protect replacement if your requirement is continuous estate crawl on day one. We win when you need Access Evaluation speed, an offline pack, least-privilege connect, and honest coverage.
Native Data Access Governance reports are a strong baseline when Copilot is licensed. Use them first for admin-centre visibility. ShareSight is for when IM, privacy, or security need a forwardable evidence pack across SharePoint, OneDrive, Teams, and Exchange, a workshop readout with honest coverage notes, not another admin console export.
Yes. After connect, toggle SharePoint sites, OneDrive by person, Teams membership and channel sites, and Exchange calendars/folders. One offline pack with workload filters on Review. Mailbox Access Evaluation is the Exchange-only package; M365 Access Evaluation covers the multi-workload workshop.
Not for the main path. ShareSight is hosted by Trustholm. Your ICT admin grants consent; we read sharing and permissions from our control plane.
Access Evaluation uses scoped sites, OneDrive people, teams, and/or mailboxes with depth and sampling you agree in workshop. Coverage notes list what was walked, what was sampled, and blind spots per workload. Deep Library Audit is the paid full unique-permission walk on named high-risk libraries. We do not pretend every first scan is estate-complete.
Remediation Sprint proposes changes and executes only with human approval and an audited change log. We do not silently strip permissions in the background.
Scan artefacts live in the Trustholm control plane for the engagement retention window (default 90 days unless the statement of work says otherwise). See the company trust hub for broader Trustholm posture.
Migrate moves and validates content from TRIM / Content Manager into SharePoint. ShareSight proves who can see what across sites, personal drives, Teams, and mailboxes, before records land, during hypercare, or as a standalone estate health review. They share branding and consulting motion; they are separate engagements.