Service 02
SharePoint Governance, Permissions & Cleanup
TechRam rebuilds your SharePoint permission model so access is granted by group rather than by one-off link, brings external sharing under a policy your people can follow, and consolidates the sites that sprawled. It's for organisations where nobody can answer who can reach what, and shared links outlive the projects that created them.
- 4–8 weeks
Who it's for
Organisations where nobody can answer who can reach a site, and external links outlive the projects that created them.
What we do
- Permission model rebuilt so access is granted by group, not by one-off link
- External sharing brought under a policy, with the existing links reviewed and revoked
- Site sprawl consolidated, with owners named against what stays
- Lifecycle rules so this doesn't have to be done again next year
How it works
Step 1
Read the current state against your tenant
Step 2
Agree the policy your people can actually follow
Step 3
Remediate in waves, starting with what is externally reachable
Step 4
Hand over the policy, the owners and the review cycle
The problem it answers
Ask who can reach a site and the honest answer is usually that nobody knows. Access was granted by link, the link was forwarded, and the person who created it has left.
External sharing is the same story one step further out. Links created for a project that finished two years ago are still live, and there’s no list of them because nobody was keeping one.
What changes
Access is granted by group rather than by one-off link, so the question “who can reach this” has an answer you can read off a screen. External sharing sits under a policy, with the existing links reviewed and the dead ones revoked. Sites that sprawled get consolidated, with an owner named against everything that stays.
Related reading
How do you find out who can actually access a SharePoint site?
Read it → — Who can reach a SharePoint site
Start here for free
Permission Visualiser
Deploys in under 30 min
Deploy it in your own tenant → — Permission VisualiserWhat this does for your AI
An agent inherits whatever the permission model allows. Fixing the model is what stops it answering from somewhere it shouldn't.
Common questions
01. How is a governance cleanup different from what our MSP already does?
An MSP grants access when a ticket asks for it. This changes how access is granted at all, so those tickets stop being one-off exceptions nobody can audit later.
02. Do we need a Baseline first?
Usually, and not because we insist. Remediating permissions you haven't read means guessing at the order, and the wrong order is what breaks something somebody was using.
03. Can we clean up one department rather than the whole organisation?
Usually yes, and it's often the better way in. One department that works is a more persuasive business case internally than a plan covering all of them, and it gives us a real cost to scope the rest against.
04. What does a SharePoint governance cleanup cost?
Fixed scope, quoted in writing before work starts, and the number doesn't move because the work turned out harder than we expected. We don't publish a range, because the scope is what sets it and a range without a scope is a guess you would have to unlearn.
05. Do we need to buy anything new for a governance cleanup?
Almost never. We start with what is already in your Microsoft 365 licensing, and we don't resell licences or earn a margin on them. Where something genuinely isn't covered we'll say so before you commit, not after.
06. What happens when the cleanup is finished?
You own it: the systems, the documentation, and the ability to maintain them without us. Run & Improve exists if you would rather we kept it current, and it's monthly with no lock-in.