Launching autumn 2026

TRACER365 · Microsoft 365 sharing and permissions auditing

See exactly who can access what across your Microsoft 365 sharing

— with the noise removed. TRACER365 audits external SharePoint and OneDrive sharing: every anonymous link, guest grant, and inherited exposure, de-duplicated down to the findings that actually need a decision.

External sharing — findingsIllustrative sample dataSEVERITYFINDINGLOCATIONHIGH"Anyone" link — no sign-in requiredFinance / Q3-forecast.xlsxHIGHInherited guest accessHR / Policies (folder)↳ 142 duplicate child findings collapsed under this oneMEDDirect grant to guestProjects / Fusion-brief.docxMED"Everyone except external users" grantIntranet / Handbook.pdfLOWUnredeemed guest invitationSales / Pricelist-2026.xlsx2,412 raw findings → 217 after cascade de-duplication● Read-only — nothing changed in the tenantScan finished 14 minutes ago
Illustrative sample data — not a screenshot, not a customer tenant.

The noise problem

The 200 findings that matter — not the 50,000 you'd wade through

Share one folder with a guest and every file beneath it inherits that access. Native reports and raw permission dumps list every row — the same exposure repeated hundreds of times, until nobody reviews any of it.

TRACER365 collapses inherited duplicates under the single grant that caused them — we call it cascade de-duplication. In our testing, roughly 91% of raw findings collapsed as duplicates, leaving a severity-ranked list a human can actually work through.

How inherited guest access works →

Without de-duplication

One guest grant on an HR folder = hundreds of identical "external access" rows, one per file. Multiply by every share in the tenant.

With TRACER365

One finding: the grant itself, with the affected items collapsed beneath it. Review the cause once — not every symptom.

Built for the audit you actually need

  • External sharing, audited

    Anonymous links, guest grants, inherited guest access, and pending invitations — across SharePoint Online and every OneDrive, in one scan.
  • 100% read-only

    The audit uses read-only Azure app-registration scopes your own security team can verify. Nothing changes in your tenant.
  • Your data stays yours

    TRACER365 runs locally, in your environment. Audit data never leaves it — a real data-residency advantage over SaaS scanners for EU organisations.
  • No extra Microsoft licences

    No Microsoft 365 Copilot licence. No SharePoint Advanced Management add-on. It works with what you already have.

How it works

Three steps to a defensible answer

  1. 01 — Connect, read-only

    Register the app in your own tenant with read-only scopes. You (or your security team) can inspect exactly what it is allowed to see — and that it can change nothing.

  2. 02 — Scan with live status

    Watch the scan in real time: which sites and drives are in progress, what has been covered, and what could not be scanned — reported honestly, never skipped silently.

  3. 03 — Review what matters

    Work a severity-ranked, de-duplicated findings list. Schedule email reports, follow trends scan over scan, and give non-IT stakeholders a viewer role.

Compliance

Evidence for the access-control question GDPR already asks you

GDPR Article 32 expects you to control — and be able to show — who can access personal data. TRACER365 produces exactly that evidence for your Microsoft 365 sharing: who can access what, especially externally, on a schedule, delivered to a reviewer.

External sharing & GDPR

Know what your tenant is sharing before someone else does

Free 30-day trial at launch — no registration. Until then, get notified the day the installer ships.