SharePoint governance tool
Dozens of your sites are open to outsiders. Half of them are abandoned.
Sharing settings say what is allowed. Governance needs what has already happened: which sites have external users, anyone links, SharePoint-only guests, and which of those sites nobody inside has opened in a year. 1Security ranks every site and OneDrive by exposure and abandonment, crosses it with the sensitive data inside, and stages the fix - sharing settings, external access expiry, ownership, Copilot search - behind a 72-hour review window.
- 300+sensitive data types detected per site, OCR included
- 72 hdefault review window before any automated change to a site
- ~10 minfor a new site or a new sharing link to show up in the ranking
The gap
Settings say what may be shared. Exposure is what has been shared.
Sharing policy is a tenant setting. Actual sharing is thousands of links, guests and grants created over years - and adding them up per site is the work.
A site's real exposure is a sum nobody computes by hand: the anyone links created since the site was set up, the organization-wide links nobody remembers, the external users still attached, and the SharePoint-only guests who never became directory objects and so slip past a directory-based guest review. Add the apps that can read every library and the nested groups that quietly extend the member list.
Meanwhile the tenant keeps growing. Every Team leaves a site, every private and shared channel another, every person a OneDrive. Most tenants hold several times more sites than IT believes, and in a typical one more than half of all files sit in sites nobody has opened in a year - many of them still shared outside. Governance by policy document does not reach those sites, because nobody knows they exist.
1Security computes exposure per site - direct and indirect, human and app, internal and external - crosses it with the sensitive data stored there and with the abandonment signals, and keeps the picture about ten minutes behind reality. Then it turns the worst rows into staged actions.
What you get
Exposure, lifecycle and sensitivity - one row per site.
Every column the governance conversation needs on the Sites screen, with a drawer that drills to the file level.
Exposure classes, counted separately
Shared with anyone via anonymous links, shared with the whole organization, external users, SharePoint-only guests, apps with access - each its own count per site, each count clickable to the list behind it.
Direct vs indirect members
Not just how many can enter, but through which door: direct membership, group chains, inherited site roles. The distinction that decides whether removing one grant actually closes anything.
Link governance across every site
Links without passwords, links past expiration, disabled links kept visible, filterable by scope (anyone, organization, specific people) and type (view, edit, review) - the whole link inventory, not the last 30 days of it.
Abandonment signals
No activity in a year, no owners, no members - with "external users still attached" highlighted, because a site nobody inside visits but someone outside can still enter is the finding that matters most.
Sensitivity and Copilot per site
Purview labels, 1Security's own 300+ detection types (OCR of scans and screenshots included), and whether Copilot is enabled - the exact inputs of a pre-AI cleanup list.
The email trail
How many times each file left by mail - uploaded or linked - and when it last did. A download is not the only way data leaves a site, and it is the one most reviews skip.
In practice
The external exposure sweep.
The pass most teams run in their first week - because the first list it produces is usually the one manual audits missed for years.
- 01
Rank sites by exposure
Sort Sites by external users, then by anyone links. The top of the list is your perimeter: the places where the tenant boundary is already open. In a mid-size tenant that is typically 50 to 300 sites with at least one external door.
- 02
Find the abandoned doors
Filter to no activity in the last year with external users still attached. Usually 20 to 200 sites - short, uncomfortable, and immediately actionable.
- 03
Cross with sensitive data
Public + sensitive + permanent: files behind anyone links, carrying sensitive data, with no expiration. That is your genuine already-exposed list, in minutes, with detection types and counts to cite.
- 04
Stage the fix
Tighten sharing capability, expire external access, assign owners, block Copilot org-wide search - staged as per-site proposals behind a 72-hour window, then executed through Microsoft's own APIs and logged in Actions.
From found to fixed
Governance that ends in a changed setting.
Site-level actions are part of the product, not an exported to-do list for someone else.
The action catalog covers what site governance actually adjusts: sharing capability, default link type and scope, anonymous-link expiry, external user expiration, allowed and blocked sharing domains, site privacy, owners and members - and blocking a site from Copilot's org-wide search before AI reads what it should not.
Every automated action stages a per-site proposal behind a grace window - 72 hours by default, configurable from instant to manual-only approval. Owners can be pulled into the review, rejecting a proposal snoozes it, and every executed change lands in Actions with who approved it and when. 1Security changes tenants through Microsoft's own APIs: no shadow permission model, and every change is visible and reversible in the Microsoft admin centers.
The difference
The joins that turn a site list into a governance list.
Each of these is a join across data that normally lives in different places - computed for you, per site, and kept about ten minutes behind reality.
- SharePoint-only guests: external identities with site access, counted per site even though they are not directory objects
- Anyone and organization-wide links crossed with the sensitive data behind them
- Links without passwords and links past expiration, across every site at once
- Sites with no activity in a year that still have external users attached
- Personal OneDrives governed like sites - same columns, same filters, same actions
- Copilot-enabled sites ranked by sensitive data concentration
- How many times each file left by email, next to its sharing state
- Direct vs indirect access per site, with the group chain that produced it
Deployment
Read-only consent. Same-day ranking.
One read-only connection maps every site and OneDrive; nothing is installed on endpoints and nothing is forwarded. Site actions live in a separately consented write module and stage behind review windows by default. Standard Microsoft licensing from Business Basic up - Purview label sync is optional, not required. Each customer tenant runs in its own dedicated database.
- Same dayfrom consent to a ranked site list
- 0agents deployed, nothing forwarded
- Business Basiclicense floor - no E5 required
Use cases
Three conversations this changes.
The pre-Copilot cleanup: before enabling AI, the list of Copilot-enabled sites holding sensitive data - sorted by detections - is the honest scope of what needs fixing first, and blocking org-wide search on the worst offenders is one staged action away.
The external collaboration review: instead of debating policy in the abstract, start from the sites already open to outsiders, who those outsiders are and what they can reach - then expire what should never have persisted.
The storage and sprawl conversation: abandoned sites with size, owners and last activity attached. In a typical tenant 30-50% of storage sits in sites with no activity in a year. Deleting is a decision; now it is at least an informed one.
Microsoft 365 Inventory Tool
The full tenant count the site list belongs to - sites, OneDrives, guests, apps, agents, devices.
See the inventory →Office 365 Access Management
The permission graph behind every site's member list - groups, links and inheritance resolved.
See access management →Copilot Security Tool
What AI can read across the sites you govern, counted before the rollout.
See Copilot security →
FAQ
Common questions.
Does this replace SharePoint sharing policies?
No. It aims them. Sharing capability, link defaults and expiry stay where they are; 1Security shows where they need tightening per site - measured against actual exposure and sensitive data - and stages the changes through Microsoft's own APIs, behind a review window.
Are personal OneDrives covered?
Yes, with the same exposure classes, link governance, sensitivity columns and filters as any SharePoint site. Personal vs SharePoint site is itself a filter, and site actions apply to OneDrives too.
What are SharePoint-only guests?
External identities invited directly into a site that never became Entra directory objects. They hold real access but are easy to miss in a directory-based review - which is exactly why they accumulate. 1Security counts them per site as their own exposure class.
Do I need Purview or E5 for the sensitivity columns?
No. 1Security's own engine detects 300+ sensitive data types, including OCR of scanned documents and screenshots, on standard licensing. Where Purview labels exist they sync in as a second signal alongside.
Can it change site settings automatically?
Only if you enable the separately consented write module - and even then actions stage as per-site proposals behind a grace window, 72 hours by default, with approve, reject and manual-only options. Every executed change is recorded in Actions.
Start from what is already exposed.
One read-only consent and the ranked site list is ready the same day - exposure, abandonment and sensitivity per site, with the fix one review away.
Or keep governing SharePoint from a policy document nobody has measured.