The first question of every incident, audit and AI rollout

Who has access to what?

In most organizations the honest answer is: nobody knows. Not IT, not security, not the last quarterly export. 1Security exists so the answer is always: here - down to the file, the person, the app, the device, and the AI agent. Live, not last quarter's export.

  • …and what did they do with it?
  • …and should that AI see it?
  • …and since when?
  • …and who else?

The ordeal

Try answering it today.

Say the question lands on your desk this afternoon - from an auditor, an incident bridge, or a board member who just read about a breach. Here is the honest procedure: pull permissions from several places, export them to CSV, cross-reference group memberships by hand, screenshot the sharing panes one by one.

A week later you present the answer. It was stale before the meeting started - access changed a thousand times while you were compiling it.

None of this is your fault, and none of it is a skills problem. You didn't choose this career to screenshot permission panes.

The reason

Why the question is so hard to answer.

Access in Microsoft 365 hides in seven places at once - and joining them into one answer is a category of its own. That category is what 1Security is.

  1. 01

    Direct grants

    The explicit permission on the file or folder - the only layer most access reviews ever look at, and by volume the smallest.

  2. 02

    Sharing links

    "Anyone with the link" created in one click, alive for years. A 500-seat tenant typically carries over a thousand of them.

  3. 03

    Group memberships

    Access through a team someone was added to in 2021, for a project that shipped in 2022. The grant outlived its reason.

  4. 04

    Site roles

    SharePoint sites run their own role system - owners, members, visitors - administered separately from everything else.

  5. 05

    Application permissions

    OAuth apps consented once, holding tenant-wide read scopes forever. Nobody remembers the consent screen.

  6. 06

    Agent knowledge sources

    Copilot and custom AI agents reach whatever their knowledge sources reach - an access path that didn't exist two years ago.

  7. 07

    Inheritance

    Permission flows down site → library → folder → file, silently overridden and silently restored. The layer that makes the other six multiply.

The living map

One graph, from the whole tenant to a single file's why.

Identity & Access × Data & Content × Apps & AI × Activity - one graph, refreshed live. Zoom out to the whole tenant; zoom in to one file and read exactly why each person, app and agent can touch it: which grant, which link, which group, which inheritance.

Under pressure

The answer, when it matters most.

Three moments when "we're not sure" stops being an acceptable answer.

  • 10 minutes

    A breach

    The blast radius of a compromised account - every file, site and mailbox it could reach, and what it actually touched. What used to take 12 hours of log stitching now takes ten minutes.

  • Drawn live

    An audit

    NIS2, ISO 27001, SOC 2 - evidence pulled from the living map at the moment the auditor asks, not from a screenshot folder assembled the week before.

  • Before rollout

    A Copilot rollout

    Know exactly what the assistant will be able to see before you switch it on - counted, listed, and trimmed down to what it should see.

Kept current

Answered forever, not once.

  • Live

    A real-time engine

    Every permission change, share and sign-in lands on the map as it happens - the answer you get is the answer right now, not last quarter's export.

  • 3 years

    A memory

    Who had access last March, and what they did with it - the question forensics actually asks. Three years of attributed activity, on standard licenses.

  • Per identity

    A watchful baseline

    Anomaly baselines watch every identity - human, app, agent, device - and open an episode when the answer changes in a way it shouldn't. The alert line is yours to position.

From answer to action

What the answer reveals, you fix on the same screen.

A finding without a fix is homework. Every excessive permission, stale link and over-scoped app on the map carries its remediation with it - automations with grace periods, review queues, and owner sign-off where it matters.

From "nobody knows" to an answer in under 10 minutes - and first answers the day you connect. Read-only, on the licenses you already own.

Get the answer for your tenant - today.

Connect read-only in the morning. Ask anything by the afternoon.

No thanks - nobody's asked yet.