1Security

Permission Graph

One interactive map of every identity, resource, and permission in your tenant - so "why does this user have access to this file?" becomes a path you can see, not a project.

Permission Graph

The permission graph answers the question that burns more analyst hours than any other in Microsoft 365: "Why does this person have access to this file?" Native tools can sometimes tell you that someone has access. The why - the chain of nested groups, site inheritance, and sharing links behind it - is scattered across admin centers and PowerShell output. 1Security draws it as a path you can walk, in either direction, from any starting point.

What You Can Achieve

Trace any access to its source

Start from a file and walk out to every identity that can reach it - or start from a user and walk to everything they can touch. Every hop shows the mechanism: which group, nested how deep, inherited from which site, opened by which link.

Audit by traveling, not exporting

Every entity is a doorway to the next: user → their actions → the files they modified → who else can read those files → whether they hold sensitive data. One continuous investigation instead of five disconnected exports.

Resolve the access nobody granted deliberately

Nested group membership and SharePoint inheritance create reach that no admin ever approved as such. The graph resolves indirect access completely, so effective permissions - not declared ones - are what you audit.

Zoom from tenant to a single edge

See permission creep at the bird's-eye level, then drill until you're looking at one specific grant connecting one identity to one resource - and remove it if it shouldn't exist.

One Map, Every Relationship

The graph connects the two halves of your tenant that Microsoft keeps in separate tools:

  • Identities - users, groups, third-party apps, and AI agents.
  • Resources - sites, files, and emails.

The edges between them are the permissions and activity that actually matter: membership, direct grants, link access, inheritance, and actions taken. Because indirect paths are resolved - including the hard ones, like multi-level group nesting and per-site SharePoint permission inheritance - the graph is a single source of truth for who has access to what at any moment.

Where the Graph Works for You

The graph isn't a page you visit; it's the backbone the platform runs on, and every screen is one of its views:

  • The Files screen answers "who has access to our files - and why?" with the graph's resolved paths behind every count.
  • The Groups screen shows effective membership - nesting resolved - and the blast radius each group unlocks.
  • The Sites screen separates direct from indirect access, so you see through which doors people enter each site.
  • The Apps and Agents screens quantify how far third-party software and AI reach along the same edges.
  • The Activity Logs attribute every action to the actor, resource, app, device, and location - the graph in motion.
  • Trends evaluate conditions over the graph continuously, turning any pattern you can describe into an alert.

Investigative Patterns

The why-chain audit: pick a high-risk detection on the Sensitive Info screen, open the files that carry it, and walk each access path to its origin. Every path ends in one of three places - a deliberate grant, a forgotten link, or an inheritance nobody considered. The second and third are your findings, and you can revoke them where you stand.

On this page