Historical SharePoint Access Intelligence

Know who had access, when, and why.

SharePoint shows permissions as they are now. Auditors, legal holds and incident reviews ask what they were then. Access Witness records the history of SharePoint Online permissions and reconstructs the answer for any moment: who could reach what, at which level, and through which groups.

Installed on your own servers. Your SharePoint permission history stays in your own database; we never receive it.

The Access Witness Permission Structure page in historical mode: the graph from FY2026 Budget.xlsx through SharePoint groups and nested Entra ID groups to seven users, with the inspector open on Alex Turner.
The Permission Structure page with “View state at:” set to Feb 14, 2026, 09:00 UTC. Everyone who could reach FY2026 Budget.xlsx in the Payroll folder at that moment, and why the external guest Alex Turner had Read. Sample Contoso Finance data.
Where it runs
On your Windows Server, with your SQL Server database. Installed by your own administrator.
What stays with you
Every permission, membership, sharing link and audit record it collects stays in your database. None of it reaches us.
What reaches us
A license check once a day and, if you turn on automatic updates, an update check. Never a name, a permission or a file.

SharePoint can tell you who has access now. What about six months ago?

Microsoft 365 administration tools show the present. When an auditor arrives, an insider is investigated or a file leaks, the questions are about the past, and SharePoint cannot answer them.

  • Why does this user have access?

    A user appears in the permissions, but not by name. The access could come from a Microsoft 365 group, a nested Entra ID security group, a sharing link, or a folder three levels down that stopped inheriting.

  • Who gave this contractor access?

    Contractors and guests arrive through groups and links. Naming the person who made the change, and the time, is the difference between a finding and an explanation.

  • Could this user reach Finance last March?

    Standard SharePoint reports evaluate today. Memberships, role assignments and sharing links removed since then are gone from the answer.

  • Was the access direct or inherited?

    An effective-permission label hides the path. Direct assignments and unique permissions have to be visible as such, because that is where exceptions and drift live.

Record, reconstruct, report.

Three steps, in that order. The middle one is the product.

  1. Step 1

    Record

    It reads permissions, group memberships and the audit log on the schedule you set.

  2. Step 2

    Reconstruct

    It keeps a continuous record of who had what, and every change in between, not just occasional snapshots.

  3. Step 3

    Report

    The Dashboard answers for any moment, shows the route that gave the access, and exports the evidence.

Follow the access path.

Instead of piecing together permission tables and group membership pages, follow the chain from a resource to the person holding access: resource, SharePoint group, Entra ID or Microsoft 365 group, user. Every path is kept, even when several collapse to the same level, and every connector says what kind of relationship it is.

Inspector panel for Alex Turner, B2B guest: what they can do here (Read, through a group), why they have it, and how the access reaches them: Payroll, Finance Visitors, Finance Contractors, Alex Turner.
Figure 1. The inspector for Alex Turner: Read on FY2026 Budget.xlsx, set on the Payroll folder, reaching him through Finance Visitors and the Finance Contractors security group, with the date each link has been in place. Sample Contoso Finance data.

Go back to any point in time.

Choose a date and time and Permission Structure and Access Map answer for that instant: the permission structure, group memberships, sharing links and effective access, with the confidence of the answer stated up front. Access History takes a date of its own.

  • One “View state at” selector sets Permission Structure and Access Map to the same past moment.
  • Every answer says how sure it is (Verified snapshot, Reconstructed, Partial, Unknown) and from what date the record begins.
  • Access History and the Access Map’s What changed tab show what was gained, lost or changed between two moments.
  • History starts with the first full scan. Nothing earlier is guessed.
The What changed list: 7 changes, 3 gave more access and 4 took it away. Adele Vance removed a sharing link on Feb 16, 2026 and Megan Bowen removed John Smith from Finance Visitors on Feb 15, both Less access, above the moment picked, Feb 14, 2026, 9:00 AM, when John Smith had Read (Reconstructed).
The What changed list in Access History for John Smith on FY2026 Budget.xlsx: each change in the period, newest first, with who made it and the access before and after, and the moment you picked placed among them. He had Read then. Sample Contoso Finance data.

Don't just show the permission. Explain it.

An effective-permission label is not evidence. It works out access step by step and shows the route, where each permission was set, and the evidence behind every step.

Access History: what could John Smith do to FY2026 Budget.xlsx as of Feb 14, 2026, 09:00 UTC. The answer: Read, reconstructed, with the path Payroll, Finance Visitors, John Smith.
The answer for John Smith on FY2026 Budget.xlsx as of Feb 14, 2026: Read, through Finance Visitors, the strongest of two routes, with each step of the path and the date it has been in place. Sample Contoso Finance data.

Turn permission changes into an investigation timeline.

Every change is attributed to an actor and a UTC timestamp, with the state before and after and the original audit record. Filter by who made it, whose access changed, where and when.

Investigations results table with the columns When, What happened, Kind of change, Before → after and Effect: a site archived in August 2026, then permission, sharing-link and group-membership changes from December 2025 to April 2026, each marked More access or Less access.
Figure 2. The Investigations page: the changes Access Witness recorded, newest first, each saying who did what to whom and where, the kind of change, the access before and after, and whether it gave more or less access. Sample Contoso Finance data.

Your permissions. Your infrastructure. Your data.

Private Edition runs on a Windows Server you control and stores everything in your own SQL Server database. Only the license and update checks reach us.

Customer Microsoft 365 tenant

SharePoint Online, Entra ID

Microsoft
Sites and permissionsRead
Groups and membershipsRead
Audit logRead

Your network

Permission data stays here

Your Windows Server

On-premises or in your Azure subscription

DashboardYour team's view, in the browser
Recording serviceKeeps the history up to date
Sign-inYour Microsoft Entra ID

Your SQL database

SQL Server 2019 or later

Permission historyYours
Every recorded changeYours

No inbound connections

Nothing on the internet reaches in

Public endpointNone required
Dashboard accessYour network or VPN

Access Witness licensing

License and update checks

Vendor
License key, installation, tenant IDSent
Product version, licensed-user countSent
Permissions, names, filesNever
Audit recordsNever
Nothing on the internet needs to reach your servers. They connect out to Microsoft 365, to read, and to our licensing service, to check the license once a day and offer updates. There is no offline mode.
Figure 3. What talks to what. Access Witness reads from Microsoft 365 and writes only to your database. It contacts us for the license and for updates, nothing else.
  • Your own database

    Permission history, memberships and every recorded change stay in your own SQL Server database.
  • Credentials stay on your server

    The credentials it reads Microsoft 365 with are created on your server and never leave it. We never hold them.
  • Outbound only

    Nothing on the internet needs to reach your servers. They connect out to Microsoft 365 and to our licensing service. What we receive is listed on the security page.

Built for large tenants, and honest about the first scan.

The first full scan of a very large tenant can take days, not hours. After that the record keeps up as Microsoft 365 reports changes, and the Sites page shows which sites are recorded and why any are not.

The Sites page: a notice that 2 of 6 sites are recorded, with the reason for each of the others, filter chips for every state, and the first sites listed with their state.
The Sites page: every site in your tenant and whether its permissions are recorded. A site that is not says why (not scanned yet, failed, excluded, archived or locked) and what to do. Sample data.

Built for the teams accountable for Microsoft 365 security.

Whether you are defending against data exposure or answering a statutory audit, the product gives you evidence you can explain.

  • Security investigations

    Determine exactly who could reach confidential documents at the time of an incident, and how.

    Investigations

  • Audit and compliance

    Produce a historical access answer with its path, confidence and evidence trail for auditors.

    Access History

  • Permission troubleshooting

    Resolve unexpected access with a deterministic explanation instead of trial and error in the admin center.

    Permission Structure

  • External guest reviews

    See every external identity, the group or link that admits it, and when that path appeared.

    Guest access guide

Take control of SharePoint access history

Stop reconstructing SharePoint permissions manually.

See how Access Witness records SharePoint permissions as they change and answers who had access on any past date, on a server you control.

Private deployment. Customer-controlled SQL database. Outbound-only connectivity.