The first question of every incident, audit and AI rollout

Who has access to what?

In most organizations the honest answer is: nobody knows. Not IT, not security, not Microsoft’s own admin centers. 1Security exists so the answer is always: here - down to the file, the person, the app, the device, and the AI agent. Live, not last quarter’s export.

  • …and what did they do with it?
  • …and should that AI see it?
  • …and since when?
  • …and who else?

The ordeal

Try answering it today.

Say the question lands on your desk this afternoon - from an auditor, an incident bridge, or a board member who just read about a breach. Here is the honest procedure: open three admin centers, dust off the PowerShell folder, export permissions to CSV, cross-reference group memberships by hand, screenshot the sharing panes one by one.

A week later you present the answer. It was stale before the meeting started - access changed a thousand times while you were compiling it.

None of this is your fault, and none of it is a skills problem. You didn’t choose this career to screenshot permission panes.

The reason

Why the question is structurally unanswerable.

Access in Microsoft 365 hides in seven places at once - and no native surface joins them into one answer. This isn’t a missing feature. It’s a missing category.

  1. 01

    Direct grants

    The explicit permission on the file or folder - the only layer most access reviews ever look at, and by volume the smallest.

  2. 02

    Sharing links

    “Anyone with the link” created in one click, alive for years. A 500-seat tenant typically carries over a thousand of them.

  3. 03

    Group memberships

    Access through a team someone was added to in 2021, for a project that shipped in 2022. The grant outlived its reason.

  4. 04

    Site roles

    SharePoint sites run their own role system - owners, members, visitors - administered separately from everything else.

  5. 05

    Application permissions

    OAuth apps consented once, holding tenant-wide read scopes forever. Nobody remembers the consent screen.

  6. 06

    Agent knowledge sources

    Copilot and custom AI agents reach whatever their knowledge sources reach - an access path that didn’t exist two years ago.

  7. 07

    Inheritance

    Permission flows down site → library → folder → file, silently overridden and silently restored. The layer that makes the other six multiply.

The living map

One graph, from the whole tenant to a single file’s why.

Identity & Access × Data & Content × Apps & AI × Activity - one graph, refreshed live. Zoom out to the whole tenant; zoom in to one file and read exactly why each person, app and agent can touch it: which grant, which link, which group, which inheritance.

Under pressure

The answer, when it matters most.

Three moments when “we’re not sure” stops being an acceptable answer.

  • 10 minutes

    A breach

    The blast radius of a compromised account - every file, site and mailbox it could reach, and what it actually touched. What used to take 12 hours of log stitching now takes ten minutes.

  • Drawn live

    An audit

    NIS2, ISO 27001, SOC 2 - evidence pulled from the living map at the moment the auditor asks, not from a screenshot folder assembled the week before.

  • Before rollout

    A Copilot rollout

    Know exactly what the assistant will be able to see before you switch it on - counted, listed, and trimmed down to what it should see.

Kept current

Answered forever, not once.

  • Live

    A real-time engine

    Every permission change, share and sign-in lands on the map as it happens - the answer you get is the answer right now, not last quarter’s export.

  • 3 years

    A memory

    Who had access last March, and what they did with it - the question forensics actually asks. Three years of attributed activity, without a SIEM contract.

  • Per identity

    A watchful baseline

    Anomaly baselines watch every identity - human, app, agent, device - and open an episode when the answer changes in a way it shouldn’t. The alert line is yours to position.

From answer to action

What the answer reveals, you fix on the same screen.

A finding without a fix is homework. Every excessive permission, stale link and over-scoped app on the map carries its remediation with it - automations with grace periods, review queues, and owner sign-off where it matters.

From “nobody knows” to an answer in under 10 minutes - and first answers the day you connect. Read-only, on the licenses you already own.

Get the answer for your tenant - today.

Connect read-only in the morning. Ask anything by the afternoon.

No thanks - nobody’s asked yet.