Investigations
Who changed access?
Event timeline
Every change, attributed
Inheritance breaks, role assignment changes, group membership changes and sharing-link events are brought together in one timeline with the actor, the UTC timestamp and the state before and after.

Workflow
From a question to exportable evidence
Scope the investigation
Start from a resource, an identity, an actor or a time window. Changes are listed newest first, one per row, and each opens with the before and after, the actor and the original audit record.Attribute the actor
Each event names the administrator, owner or user who made the change, as recorded by the Microsoft 365 audit log.See the blast radius
The person or group whose access changed, and the resource it changed on, are listed for every change.Export evidence
Export the event list as CSV, or the answer with its access paths, before/after state and confidence as a JSON evidence file.
Worked example
The Payroll privilege increase
On Jan 20, 2026 the Finance Visitors group on the Payroll folder was changed from Read to Edit; on Jan 28 it was changed back. For eight days every member of Finance Visitors, including the external guest Alex Turner via the Finance Contractors group, could edit payroll files.
What changed
Finance Visitors' permission on the Payroll folder: raised from Read to Edit, then set back to Read.
Who and when
Jordan Ellis, Global Administrator, at 2026-01-20 15:05:41 UTC and 2026-01-28 10:00:00 UTC.
Who was affected
Finance Visitors members: Finance Contractors (Entra ID group) including Alex Turner and, via nesting, External Auditors and Elena Vance.
A current-state permission report taken today shows Finance Visitors with Read and nothing unusual. The investigation timeline is the only place the eight-day window exists.
Investigations
Turn permission changes into an investigation timeline.
See how Access Witness records SharePoint permissions as they change and answers who had access on any past date, on a server you control.
Private deployment. Customer-controlled SQL database. Outbound-only connectivity.