Skip to content
Security

Microsoft 365 remains the security boundary.

Protect works with SharePoint’s permission model instead of creating a separate data store or a second source of truth.

Security principles

Secure by design.

Existing access applies

People see the workspaces and permission information available to their signed-in Microsoft 365 identity.

SharePoint stays the source

Protect reads and writes permission information through SharePoint in the current user’s context.

No external permission store

The SharePoint app does not copy permission data into a Protect-managed external database.

Changes are deliberate

Permission, metadata, file-property, rename, and approval actions are initiated by licensed users, not silently applied in the background.

Security questions

Straight answers for a technical review.

Does Protect replace SharePoint permissions?

No. SharePoint remains the system of record. Protect makes its permission model easier to inspect and update deliberately.

Does everyone see the same workspaces?

No. Workspace discovery and results depend on what the signed-in user can access. Some tenants can return partial discovery results.

Is permission data sent to external storage?

No. The SharePoint app does not transfer permission data into external storage managed by Protect.

Can Protect change access automatically?

Pro actions are user initiated. Protect does not silently remediate permissions in the background.