Each permission row keeps the content item, principal, access level, and location together. Review all four before deciding whether access is appropriate.
To check who actually opened a document, see See who viewed files in SharePoint. Permission assignments show who can access content; SharePoint Viewers and Microsoft Purview Audit show viewing activity.
Read a permission row
| Column | What it shows |
|---|---|
| Item | The site, document library, folder, file, or list that was evaluated. Select a linked item to load that scope. |
| Shared with | A person, guest, SharePoint group, Microsoft 365 group or Team, security group, distribution list, or sharing link. |
| Access level | The assigned SharePoint role and icons for resulting capabilities. |
| Location | The SharePoint path where the entry applies. Select it to open that location. |
For SharePoint groups, Protect can show member pictures and names for the first visible members plus a count for the remainder. Group membership, not the permission row itself, controls which people receive that group access.
Interpret capability icons
Protect translates a returned access level into practical capabilities where possible:
| Capability | Meaning |
|---|---|
| View | Open or read content. |
| Download | Download a copy. |
| Upload | Add content. |
| Edit | Change existing content or properties. |
| Approve | Participate in supported approval actions. |
| Share | Create or manage sharing. |
| Delete | Delete supported content. |
Capability icons help compare custom roles, but the SharePoint permission-level definition remains authoritative. Select Access levels to open the current site's native role definitions.
Identify principal types
Use Shared with filters to separate:
- Internal person and Guest direct assignments.
- SharePoint group assignments managed at the site.
- Microsoft 365 group or Team assignments that can affect other group-connected resources.
- Security group and Distribution list entries managed outside the permission row.
- People in your organization with the link, People you choose, and Anyone with the link sharing entries.
Anyone links can work without sign-in and normally warrant the most deliberate review. Organization links require an authenticated person in the tenant. Specific-people links are restricted to their named recipients.
Distinguish inherited and custom access
Inherited access comes from a parent scope. Custom access means the item has its own permission boundary.
- In Access source, select Items with inherited access or Items with custom access.
- For an inherited row, use the parent-source link to inspect where the assignment originates.
- For a custom item, review every entry required at that boundary.
- Don't remove an inherited row at a child location when the actual decision belongs at the parent.
Load nested entries
- Start with the current shallow scope.
- Narrow to the site, library, or folder that needs review.
- In Load, select Load nested sharing entries.
- Wait until detailed loading completes.
- Filter by item type, principal type, access level, location, or source.
- Clear the checkbox to return to shallow results.
Run a focused external-access review
- Select Guest, People you choose, and Anyone with the link under Shared with.
- Select the high-impact access levels relevant to your organization.
- Select Items with custom access.
- Use search to locate a known person, project, or path when needed.
- Review the principal, capability icons, permission source, and location.
- Export the loaded permission data or send an approved remediation decision to the site owner.
