Skip to content
DocumentationContact
Protect

Export and import permission workbooks

Read Protect's permission matrix, export review evidence, and validate additive SharePoint-group assignments before import.

Protect exports permissions as a matrix workbook. Protect Pro can read that structure back to add validated SharePoint-group assignments. Import doesn't synchronize or remove access.

Understand the workbook

The exported workbook contains a worksheet named permissions:

Area Meaning
First column SharePoint content path
Columns B and later One principal per column
Principal header Principal name and type
Assignment cell One SharePoint access-level name or multiple comma-separated names
Yellow path cell Item has custom access
White path cell Item inherits access

Assignment cells include an Excel dropdown based on role names in a hidden validation worksheet. Use those listed values to avoid spelling drift.

Export permission data

  1. Open the site or location in Protect.
  2. Enable Load nested sharing entries if child content belongs in the review.
  3. Wait for loading to finish.
  4. Apply the filters needed for on-screen analysis.
  5. Select Export to Excel.
  6. Open the workbook and confirm the expected paths, principals, and roles.
  7. Save an unchanged source copy in the approved evidence location.

Filters help reviewers analyze the screen, but always verify workbook scope before treating the file as evidence.

Prepare an import workbook

Start from a current Protect export from the target site.

  1. Keep the first path column and principal headers unchanged.
  2. Keep only group principal columns that the target site can resolve by exact SharePoint group title.
  3. In each applicable path row, enter one role name or comma-separated role names from the cell dropdown.
  4. Leave a cell blank when no new group assignment should be added for that path.
  5. Don't add individual email addresses, guests, sharing-link principals, or system groups.
  6. Save the workbook as a supported Excel file.

Import ignores sharing-link principals, the Limited Access System Group, principals containing an email-address marker, and paths that don't have the expected site-relative structure.

Validate an import

  1. In Protect, open the target site.
  2. Select Import from Excel.
  3. Choose the prepared workbook.
  4. Wait while Protect checks unique paths across the site.
  5. Review every preview row across Path, Member, Role, Type, and Status.
  6. Correct the workbook if a row shows Path not found, Member not found, Role not found, or a missing value.
  7. Repeat import until every row shows Ready.

Protect validates paths with the signed-in user's site access, group titles against loaded SharePoint groups, and role names against the site's existing access levels.

Grant imported access

  1. Confirm that the preview contains only intended additive assignments.
  2. Select Grant access.
  3. Wait for the save to complete.
  4. Select Refresh in the permission explorer.
  5. Filter to the imported groups and paths.
  6. Verify the new entries in Protect and SharePoint.

The Grant access button remains disabled while path checks run or any row is invalid.

Maintain review evidence

  • Retain the unchanged export and the approved import separately.
  • Record the reviewer, approver, business purpose, date, and change reference.
  • Split unrelated changes into separate workbooks.
  • Pilot a large change with representative paths first.
  • Re-export after the change when your audit process requires proof of resulting state.
Was this page helpful?