Documentation

How TRACER365 works

The parts worth reading before you install anything: the auth model, the permissions it requests — and refuses — and what a scan actually does.

The basics

What you're installing

TRACER365 runs as a background Windows service on a machine you control, and serves its management interface over HTTPS as a web console listening on a TCP port on the host; how that port is reached is determined by your own network configuration, and it needs no inbound path from the internet. There is no SaaS backend — the app talks directly to Microsoft's APIs from your environment, and everything it finds is stored locally.

At a high level, you'll need:

  • a Windows machine to install on — Windows Server 2019 or later, or Windows 11 (a laptop is fine — consultants run it that way);
  • permission to create an app registration in the Microsoft Entra tenant you're auditing, and an admin who can grant consent to its read-only permissions;
  • outbound access to Microsoft Graph and SharePoint Online endpoints.

The full prerequisites — host, network, tenant access and licence scope — are on the requirements page. The step-by-step install guide — screenshots, the certificate helper script — ships with the product at launch.

No agents, no tenant footprint

Nothing is deployed into your tenant except an app registration you create and control. Uninstalling is deleting the app and the app registration.

Per-installation licence

One licence covers one installation and up to two Microsoft 365 tenants. Consultants and MSPs run one installation per client — see partner pricing.

Trial: 30 days, no registration

The full product, capped at 100 findings rows. On expiry it drops to a read-only view of what it found. Trial terms

Security model

Read-only, certificate-based, verifiable

TRACER365 authenticates to Microsoft Graph and the SharePoint API using certificate-based, app-only authentication — the modern Microsoft-recommended pattern. App-only means there is no signed-in user and no delegated permissions at all: the app can never do anything on a user's behalf.

The certificate is yours: generated on your own machine (a helper script ships with the product), uploaded by your admin to your app registration. Storrex never holds, escrows, or can recover it — each installation is a fully isolated credential unit, and no credential spans customers.

Because the app registration lives in your tenant, your security team can open it at any time and verify the permission list below — and that nothing on it can write.

One posture decision worth knowing: Microsoft offers a faster sharing-change feed, but gates it behind tenant-wide full control permission. TRACER365 declined it. In the product's own words to security reviewers: we'd rather accept a bounded delay on one optimisation than ask for write access to your tenant.

Application permissions requested (all read-only)

PermissionUsed for
Files.Read.AllRead files and their permissions for the sharing analysis
Sites.Read.AllEnumerate SharePoint sites and read site-level metadata
User.Read.AllResolve who a finding points at (display names, sign-in names)
Group.Read.AllEnumerate Microsoft 365 groups and map sites to their backing group
Sites.Read.All (SharePoint API)Read site permission groups so routine site groups can be filtered as noise

Deliberately not requested: Sites.FullControl.All, any *.ReadWrite.* permission, and any Mail, Calendar, or Contacts permission. The definitive permission list is restated in the launch install guide.

The full security & trust page goes further — credentials at rest, the operator roles, the audit trail, framework alignment, and an explicit list of what the product deliberately doesn't do.

Scanning

How a scan works

  1. 01 — Enumerate

    Every SharePoint site and every OneDrive in the tenant — including the sites behind Teams channels. Anything that can't be enumerated (a OneDrive under retention lock, say) is listed with its reason, never skipped silently.

  2. 02 — Analyse, read-only

    Permissions and sharing links on every item are read and classified into nine severity-ranked finding types — external exposure first, from anonymous "Anyone" links to inherited guest access.

  3. 03 — De-duplicate

    Inherited duplicates collapse under the grant that caused them — in our testing, roughly 91% of raw findings collapsed as duplicates. You watch progress live the whole way.

  4. 04 — Repeat on schedule

    Scheduled scans keep the answer current: expanded sharing re-flags for review, reduced sharing doesn't nag, and scan-over-scan history feeds the trend view and email reports.

The full capability tour — what's detected, what's out of scope, and the honesty section — is on the product page.

Common questions

Does it change anything in my tenant?
No. TRACER365 is 100% read-only: every permission it requests is a read permission, there are no delegated permissions at all, and the app registration lives in your tenant where your security team can verify all of it. It observes and reports; it never remediates.
What Microsoft licence do I need?
None beyond what you already have. TRACER365 needs no Microsoft 365 Copilot licence and no SharePoint Advanced Management add-on — see the licence-wall guide for the comparison with Microsoft's native reports.
Where does my audit data live?
On the machine you install TRACER365 on. It runs there as a background Windows service that serves a web console over HTTPS on a TCP port; findings are stored locally and never reach Storrex. There is no vendor cloud in the design.
When can I install it?
At launch, autumn 2026 — with a 30-day free trial, no registration. Leave your email on the trial page and you'll get the installer the day it ships.

This documentation is deliberately partial. It expands as we approach launch (autumn 2026) — install guide, certificate setup, scanning model reference, and troubleshooting land here as they're finalised. Questions in the meantime: support.

Ready to see it on your own tenant?

30-day free trial at launch, no registration — get notified the day the installer ships.