Access Map

What can they reach?

Permission Structure starts from a document and works back to the people. Access Map starts from a person or a group and works forward: every site, library, folder and file they can reach, how each one reaches them, and what they held on a given date. Read it before a leaver's last day, during an incident, or when a guest account has been in the tenant longer than anyone remembers.
Starting pointTenant: Contoso Industries
John Smith
Member user
Sites reached
1 site, 3 objects
Through
2 groups, 1 nested, 1 sharing link
Strongest level
Edit

The picture

A tree, not a web

A person with access to forty sites through a dozen groups would be a tangle if every line were drawn. Access Map draws one tree: the person on the left, their groups and sharing links next, nested groups after that, and one card per site on the right. Every line runs to the right, a group that fans out too widely starts folded, and access that everyone in the tenant has is set apart so it does not hide what is specific to this person.

The Access Map page at a past date: John Smith on the left, the Finance Team and Finance Visitors groups and a sharing link in the next column, the nested Finance Members group after that, and the Finance site card on the right showing three objects reached and Edit as the strongest level.
The Access Map for John Smith as of Feb 14, 2026, 09:00 UTC: through the Finance Team group and its nested Finance Members group he reaches the Finance site with Edit; Finance Visitors gives him Read on the Payroll folder; a sharing link names him on one file. Three days later the link and the Visitors membership are gone, and the same page says so. Sample Contoso Finance data.

The list

The answer an auditor keeps

The picture explains; the list is the record. One row per object, grouped by site, strongest level first, with the route that grants it, when that route appeared, and the confidence of the answer. Export it as CSV or JSON with the date it was taken for.

The Access Map list: rows for the Finance root web, the Payroll folder and FY2026 Budget.xlsx, each with its level, the route through Finance Team and Finance Members, Finance Visitors, or a sharing link, the date since, and a confidence badge.
The same answer as a table, for the same moment: site, object, level, the groups or link the route passes through, when it has been in place, and the confidence of the reconstruction. Sample Contoso Finance data.

Two moments

What changed between two dates

The What changed tab sets two moments side by side for the same person or group: what they gained, what they lost, where the level changed and what stayed the same, with the route before and after. Both moments stay in the page address, so the comparison can be sent to a colleague, and the changes export as CSV.

The What changed tab: 0 gained, 2 lost, 0 changed and 1 unchanged, marked Reconstructed, above a table of the two lost objects, Payroll with Read through Finance Visitors and FY2026 Budget.xlsx with Read through a specific people link, both not reached on Feb 17, 2026.
What changed for John Smith between Feb 14, 2026, 09:00 UTC and Feb 17, 2026: the Payroll folder, which Finance Visitors gave him, and FY2026 Budget.xlsx, which a sharing link gave him, are both lost; his access to the Finance site itself is unchanged. Sample Contoso Finance data.

Where it is used

The questions that start from a name

Site-first views answer one object at a time. These questions need the whole reach of one identity at once.

  • Leavers and movers

    Before a last day or a team change: every site and library the person can still reach, and which group membership or link to remove to close each one.
  • Guest accounts

    Start from an external identity and see exactly what it reaches, including access that arrives only through a sharing link or a nested group.
  • Incident scope

    Set the date to the moment of an incident and read what the account could reach then, with the confidence of the reconstruction stated on every row.
  • Reviews with evidence

    Export the list for the review record, filter it to Full Control only, to direct grants, or to sharing links, and leave out what every user in the tenant has.

What you can rely on

Rules the map follows

Access Map and Permission Structure work out access the same way from opposite ends, so the two views always agree.

  • Groups inside groups are followed

    Every group the person belongs to, and every group those belong to, including the tenant-wide Everyone groups where they apply.

  • Every route is kept

    An object reached three ways lists all three routes, so you know every route to close, not just the first one found.

  • The strongest level wins the card

    A site card shows the highest level held on anything inside it; opening the card shows each object with its own level.

  • The date is honoured

    Set a past date and the map shows that day's access, never today's.

  • Nothing is guessed

    A date before recording began returns nothing, with the date recording began, rather than a guess.

Access Map

See what one account can reach in your tenant.

See it on sample data in a demo, then on your own tenant during a 60-day evaluation. It only reads: it never changes permissions, sharing or content.

Never changes permissions, sharing or content. Runs on your servers.