Product

The external sharing audit, end to end

TRACER365 runs as a background Windows service on a machine you control, serving a web console from that host. It scans your Microsoft 365 tenant read-only, finds every external exposure across SharePoint and OneDrive, and collapses the duplicates so the review is actually doable.

Coverage

What it scans

One scan covers every SharePoint Online site — team sites, communication sites, Microsoft 365 group sites — and every OneDrive in the tenant, not one user at a time.

Teams files are covered where they physically live: standard-channel files in the parent team's SharePoint site, private- and shared-channel files in their own channel sites, and chat attachments in the sender's OneDrive.

Because Loop components, OneNote notebooks, Stream videos, and Whiteboard files are stored in SharePoint and OneDrive, their file-level sharing is audited the same way.

Known edges, stated plainly: channel-membership access inside Teams channels and group permissions specific to channel sites are not audited in v1; Teams-chat attachments appear as OneDrive findings without a "shared via chat" label yet.

Nine finding types, ranked by severity

Every detection lands as one of nine finding types with a severity, so triage starts at the top. The full list is below — and we publish what we don't detect too.
Finding typeSeverityWhat it means
Anonymous ("Anyone") linkHIGHA link that grants access with no sign-in at all — to a file in SharePoint or any OneDrive.
Inherited guest accessHIGHA guest can reach an item because a parent folder or site was shared — the item itself shows no share.
Direct grant to a guestMEDIUMAn external (B2B guest) account granted permission directly on a file or folder.
Specific-people external linkMEDIUMA sharing link scoped to named recipients that include external people — every recipient tracked individually.
"Everyone except external users" grantMEDIUMAn item opened to the entire organisation via the built-in EEEU group — a specific internal over-exposure condition.
Group with accessVariesAn item shared with a Microsoft 365 or SharePoint group at item level; routine site groups are filtered as noise.
Organisation-wide linkLOWAn "anyone in the organisation" link — internal, but on a personal OneDrive it publishes a user's content tenant-wide.
Unredeemed guest invitationLOWA pending external invitation that has not been accepted yet — tracked from invitation to acceptance.
Broken permission inheritanceINFOAn item whose permissions diverge from its parent — a governance flag that makes access hard to reason about.

Cascade de-duplication

The noise, removed

The reason sharing audits fail is volume. A single guest grant on a folder repeats on every file beneath it; a raw report shows thousands of rows that are all the same decision.

TRACER365 folds inherited duplicates under the grant that caused them and filters structural noise — routine site groups, Microsoft's own system sites — with every filter decision documented. In our testing, roughly 91% of raw findings collapsed as duplicates.

What's left is the honest working set: the exposures that each need one human decision.

External sharing — findingsIllustrative sample dataSEVERITYFINDINGLOCATIONHIGH"Anyone" link — no sign-in requiredFinance / Q3-forecast.xlsxHIGHInherited guest accessHR / Policies (folder)↳ 142 duplicate child findings collapsed under this oneMEDDirect grant to guestProjects / Fusion-brief.docxMED"Everyone except external users" grantIntranet / Handbook.pdfLOWUnredeemed guest invitationSales / Pricelist-2026.xlsx2,412 raw findings → 217 after cascade de-duplication● Read-only — nothing changed in the tenantScan finished 14 minutes ago
Illustrative sample data — not a screenshot, not a customer tenant.

Scan transparency

You always know what the scan is doing

  • Live progress

    Real-time status while the scan runs: what's in progress, what's done, how fresh the data is. No spinner of unknown meaning.
  • Honest coverage

    Anything that could not be scanned — like a OneDrive locked by a Microsoft 365 retention hold — is listed explicitly with the reason, never skipped silently.
  • Change-aware findings

    When sharing on a known finding expands, it is re-flagged for review. When it shrinks, your earlier sign-off stands — the product doesn't nag about good news.

Trust by design

Read-only, local, verifiable

  • Read-only scopes

    The Azure app registration uses read-only permissions. Your security team can open it and verify: no write access, anywhere.
  • Runs in your environment

    A background Windows service on a machine you control, with a web console served from that same host and no inbound path from the internet required. Findings are stored locally; audit data never leaves your environment.
  • Nothing to certify away

    There is no vendor cloud holding your tenant data — because none of it ever reaches us.

The full auth model — certificate-based, app-only, and the exact read-only permission list — is in the documentation. What the host and your tenant have to provide before any of it runs is on the requirements page.

Beyond IT

Built to be reviewed, not just run

  • Viewer role

    Give a department head or compliance owner read-only access to the findings that concern them — no admin console required.
  • Scheduled email reports

    Reports arrive on a schedule, to the person who has to act on them. The review cadence becomes routine instead of a yearly scramble.
  • Historical trending

    Scan-over-scan history shows whether exposure is shrinking or growing — point-in-time and change-over-time evidence for an auditor.

Stated plainly

What TRACER365 does not do

We tell you what we detect and what we don't — silent gaps defeat the point of an audit tool.

  • It is not a full internal-access map. TRACER365 leads on external exposure. Specific internal conditions are detected and named — organisation-wide links, "Everyone except external users" grants, broken inheritance — but it does not claim to show every internal permission.
  • Exchange is out of scope. Mailbox auto-forward rules, calendar sharing, and shared-mailbox delegations are not audited — review those in the Exchange admin center.
  • Forms, Planner task data, and Viva Engage networks live in different storage and are not audited. File attachments that land in SharePoint or OneDrive are.
  • SharePoint list-item permissions (Microsoft Lists) are a separate audit surface we have not yet verified — document libraries are fully covered; we won't claim lists until it's tested.
  • It changes nothing. TRACER365 is deliberately read-only: it is the precise discovery step before remediation, not the remediation.

See your own tenant's real exposure

30-day free trial at launch, no registration — or get notified the day the installer ships.