Launching autumn 2026
TRACER365 · Microsoft 365 sharing and permissions auditing
See exactly who can access what across your Microsoft 365 sharing
— with the noise removed. TRACER365 audits external SharePoint and OneDrive sharing: every anonymous link, guest grant, and inherited exposure, de-duplicated down to the findings that actually need a decision.
The noise problem
The 200 findings that matter — not the 50,000 you'd wade through
Share one folder with a guest and every file beneath it inherits that access. Native reports and raw permission dumps list every row — the same exposure repeated hundreds of times, until nobody reviews any of it.
TRACER365 collapses inherited duplicates under the single grant that caused them — we call it cascade de-duplication. In our testing, roughly 91% of raw findings collapsed as duplicates, leaving a severity-ranked list a human can actually work through.
Without de-duplication
With TRACER365
Built for the audit you actually need
External sharing, audited
Anonymous links, guest grants, inherited guest access, and pending invitations — across SharePoint Online and every OneDrive, in one scan.100% read-only
The audit uses read-only Azure app-registration scopes your own security team can verify. Nothing changes in your tenant.Your data stays yours
TRACER365 runs locally, in your environment. Audit data never leaves it — a real data-residency advantage over SaaS scanners for EU organisations.No extra Microsoft licences
No Microsoft 365 Copilot licence. No SharePoint Advanced Management add-on. It works with what you already have.
How it works
Three steps to a defensible answer
01 — Connect, read-only
Register the app in your own tenant with read-only scopes. You (or your security team) can inspect exactly what it is allowed to see — and that it can change nothing.
02 — Scan with live status
Watch the scan in real time: which sites and drives are in progress, what has been covered, and what could not be scanned — reported honestly, never skipped silently.
03 — Review what matters
Work a severity-ranked, de-duplicated findings list. Schedule email reports, follow trends scan over scan, and give non-IT stakeholders a viewer role.
Compliance
Evidence for the access-control question GDPR already asks you
GDPR Article 32 expects you to control — and be able to show — who can access personal data. TRACER365 produces exactly that evidence for your Microsoft 365 sharing: who can access what, especially externally, on a schedule, delivered to a reviewer.
Know what your tenant is sharing before someone else does
Free 30-day trial at launch — no registration. Until then, get notified the day the installer ships.