Permission Visualiser
The Permission Visualiser is a free tool that shows who can actually reach a SharePoint site, and by which group, link or inherited permission. It deploys into your own Microsoft 365 in under 30 minutes and answers the question most tenants cannot: who can see this?
- Deploys in under 30 min
- Runs in your own tenant
The job it does
Shows who can actually reach a site, and by which group, link or inherited permission.
What this does for your AI
Copilot answers from what a user can reach. This is that map.
Where it leads
Where you want the full picture rather than one slice of it, this is the Governance & Cleanup engagement.
Deploys in under 30 min into your own Microsoft 365 tenant, on the licences you already hold. Nothing leaves your environment and there is nothing to buy.
How to read what it finds: Who can reach a site →
Common questions
01. What does the Permission Visualiser read, and what does it change?
It reads and reports. It does not remove a member, break inheritance or delete a sharing link. What to change is your call, once you can see the shape of it.
02. Why does it disagree with the site’s own permissions page?
Because it follows the whole chain — nested groups, inherited permissions and sharing links — rather than the direct assignments the site page lists. The gap between the two is usually the finding.
03. What permissions does the Permission Visualiser need?
Read access across the sites it maps, which in practice means a global reader plus SharePoint administrator. Read-only is the whole point, so nothing it does requires write access.
04. Why does this matter for Copilot?
Copilot answers from whatever the person asking can reach. A site open wider than anyone realised becomes a source it will quote from, so this map is the shape of what it can say and to whom.
05. Is the Permission Visualiser a trial for something paid?
No, and there is no paid version of the visualiser. Where the access needs fixing rather than mapping, that is a Governance & Cleanup engagement.