Product
The external sharing audit, end to end
TRACER365 runs as a background Windows service on a machine you control, serving a web console from that host. It scans your Microsoft 365 tenant read-only, finds every external exposure across SharePoint and OneDrive, and collapses the duplicates so the review is actually doable.
Coverage
What it scans
One scan covers every SharePoint Online site — team sites, communication sites, Microsoft 365 group sites — and every OneDrive in the tenant, not one user at a time.
Teams files are covered where they physically live: standard-channel files in the parent team's SharePoint site, private- and shared-channel files in their own channel sites, and chat attachments in the sender's OneDrive.
Because Loop components, OneNote notebooks, Stream videos, and Whiteboard files are stored in SharePoint and OneDrive, their file-level sharing is audited the same way.
Nine finding types, ranked by severity
| Finding type | Severity | What it means |
|---|---|---|
| Anonymous ("Anyone") link | HIGH | A link that grants access with no sign-in at all — to a file in SharePoint or any OneDrive. |
| Inherited guest access | HIGH | A guest can reach an item because a parent folder or site was shared — the item itself shows no share. |
| Direct grant to a guest | MEDIUM | An external (B2B guest) account granted permission directly on a file or folder. |
| Specific-people external link | MEDIUM | A sharing link scoped to named recipients that include external people — every recipient tracked individually. |
| "Everyone except external users" grant | MEDIUM | An item opened to the entire organisation via the built-in EEEU group — a specific internal over-exposure condition. |
| Group with access | Varies | An item shared with a Microsoft 365 or SharePoint group at item level; routine site groups are filtered as noise. |
| Organisation-wide link | LOW | An "anyone in the organisation" link — internal, but on a personal OneDrive it publishes a user's content tenant-wide. |
| Unredeemed guest invitation | LOW | A pending external invitation that has not been accepted yet — tracked from invitation to acceptance. |
| Broken permission inheritance | INFO | An item whose permissions diverge from its parent — a governance flag that makes access hard to reason about. |
Cascade de-duplication
The noise, removed
The reason sharing audits fail is volume. A single guest grant on a folder repeats on every file beneath it; a raw report shows thousands of rows that are all the same decision.
TRACER365 folds inherited duplicates under the grant that caused them and filters structural noise — routine site groups, Microsoft's own system sites — with every filter decision documented. In our testing, roughly 91% of raw findings collapsed as duplicates.
What's left is the honest working set: the exposures that each need one human decision.
Scan transparency
You always know what the scan is doing
Live progress
Real-time status while the scan runs: what's in progress, what's done, how fresh the data is. No spinner of unknown meaning.Honest coverage
Anything that could not be scanned — like a OneDrive locked by a Microsoft 365 retention hold — is listed explicitly with the reason, never skipped silently.Change-aware findings
When sharing on a known finding expands, it is re-flagged for review. When it shrinks, your earlier sign-off stands — the product doesn't nag about good news.
Trust by design
Read-only, local, verifiable
Read-only scopes
The Azure app registration uses read-only permissions. Your security team can open it and verify: no write access, anywhere.Runs in your environment
A background Windows service on a machine you control, with a web console served from that same host and no inbound path from the internet required. Findings are stored locally; audit data never leaves your environment.Nothing to certify away
There is no vendor cloud holding your tenant data — because none of it ever reaches us.
The full auth model — certificate-based, app-only, and the exact read-only permission list — is in the documentation. What the host and your tenant have to provide before any of it runs is on the requirements page.
Beyond IT
Built to be reviewed, not just run
Viewer role
Give a department head or compliance owner read-only access to the findings that concern them — no admin console required.Scheduled email reports
Reports arrive on a schedule, to the person who has to act on them. The review cadence becomes routine instead of a yearly scramble.Historical trending
Scan-over-scan history shows whether exposure is shrinking or growing — point-in-time and change-over-time evidence for an auditor.
Stated plainly
What TRACER365 does not do
We tell you what we detect and what we don't — silent gaps defeat the point of an audit tool.
- It is not a full internal-access map. TRACER365 leads on external exposure. Specific internal conditions are detected and named — organisation-wide links, "Everyone except external users" grants, broken inheritance — but it does not claim to show every internal permission.
- Exchange is out of scope. Mailbox auto-forward rules, calendar sharing, and shared-mailbox delegations are not audited — review those in the Exchange admin center.
- Forms, Planner task data, and Viva Engage networks live in different storage and are not audited. File attachments that land in SharePoint or OneDrive are.
- SharePoint list-item permissions (Microsoft Lists) are a separate audit surface we have not yet verified — document libraries are fully covered; we won't claim lists until it's tested.
- It changes nothing. TRACER365 is deliberately read-only: it is the precise discovery step before remediation, not the remediation.
See your own tenant's real exposure
30-day free trial at launch, no registration — or get notified the day the installer ships.