Service 01

The SharePoint Audit

The SharePoint Audit is TechRam's two-to-three-week, read-only review of your Microsoft 365. It answers three questions in your own numbers: what Copilot can see that it shouldn't, what SharePoint isn't doing for you, and whether your records would survive an audit. It opens no files and changes nothing.

  • 2–3 weeks
Victor Khalil taking notes while someone talks through how their SharePoint is used
  • Timeframe

    Two to three weeks

  • Access

    Read-only

    We never open a file or change a setting.

  • Billing

    At the readout

    Nothing material to fix, no invoice.

Who it's for

Organisations of 50–500 staff on Microsoft 365 whose SharePoint grew without a plan. There are usually two of you in the room: the IT lead or MSP, and the operations, quality or GM sponsor who has to answer for the records.

What we do

  • A one-page scorecard
  • A findings report for the board, and one for the team
  • A mock-up of your new SharePoint front door
  • An Opportunities Register of about ten next steps, each with the licence you already hold and the subscription it retires
  • A fixed-price proposal for the fix, every line traced to a number in your tenant

How it works

  1. Step 1

    You accept the proposal, and a named officer authorises a read-only scan

  2. Step 2

    Your Global Admin or MSP grants read-only access, with the full permission list and the script source in their hands first

  3. Step 3

    The scan runs, alongside a short questionnaire and two or three interviews

  4. Step 4

    Readout in the final week. Access is revoked that day and the data deleted

What a SharePoint audit checks: three questions

What can Copilot see that it shouldn’t? Copilot answers from whatever a person can already open, so this part is a SharePoint permissions audit — anonymous links, “Everyone” grants, the OneDrives of people who left years ago. Nobody has counted them, so nobody can say what a prompt will surface.

What is SharePoint not doing for you? Spreadsheets behaving like systems, and subscriptions doing what Business Premium already includes. Each one is a cost you carry for something you already own.

Would your records survive an audit? We take a record from three months ago, an incident report say, and trace it from first entry to last. Either the trail holds or it doesn’t, and you find out from us rather than from the auditor.

Without the audit, and with it

Without

  • Anonymous links nobody has counted
  • Spreadsheets behaving like systems
  • A record you couldn't trace
  • A fix scoped on opinion

With

  • Every link listed, with who made it
  • Each one named, with the licence that replaces it
  • One traced from first entry to last, three months back
  • A proposal traced to your numbers

What the pilot found

The pilot audit, an 85-seat organisation on Microsoft 365, found 508 anonymous links across 55 OneDrives, 500 of them with edit rights, against one in SharePoint. Of 179 GB of SharePoint storage, 111 GB was old versions of files. Both numbers were in the tenant all along. Nobody had read them.

Access and data

We never open a file or change a setting. Before anything runs, your IT lead or MSP gets the full list of permissions the scan needs and the source of the script, so they can read what it does. A named officer authorises the scan; your Global Admin grants read-only access and revokes it on the last day. The data is deleted at the end of the audit.

Is this a fit?

Yes, if

  • 50–500 staff on Microsoft 365
  • SharePoint grew without a plan
  • Your policies, incident reports and board papers live in SharePoint or on a file server

Not yet, if

  • Most of your records live in specialist apps
  • You want a helpdesk
  • You need one file moved

One question before you book

Where do your policies, incident reports and board papers live today? If the answer is SharePoint or a file server, the audit fits. If it’s mostly specialist apps, we’ll tell you honestly whether it does. The useful conversation there is usually what you’re paying in subscriptions, not SharePoint. Either way, that is what the 30-minute Discovery Call is for.

Book a Discovery Call

Related reading

Start here for free

External Sharing Risk Scanner

Deploys in under 30 min

Deploy it in your own tenant → — External Sharing Risk Scanner

What this does for your AI

Copilot answers from whatever a person can already open. The audit is where you find out what that is.

Common questions

01. What counts as "material", and what if you always find something?

Material, in The SharePoint Audit, means a finding you'd act on: an anonymous edit link to a file that should be internal, a record you can't trace back three months, a subscription doing what your Business Premium licence already includes. The threshold goes in the proposal, in writing, before the scan runs. If the readout clears it, you're invoiced. If it doesn't, you aren't. We expect to find something. The pilot found 508 anonymous links in an 85-seat tenant. So the real question is whether it's worth fixing, and that's the number you'll see.

02. How is The SharePoint Audit different from what our MSP does?

Your MSP keeps the tenant running. The SharePoint Audit reads what is in it and tells you what to fix first, which is a different job. Your IT lead or MSP gets the full permission list and the script source before anything runs, and revokes the access on the last day. We hand the findings to whoever does the work, and that's often them.

03. Is our SharePoint ready for Copilot?

Most SharePoint tenants aren't ready for Copilot yet, and it's quicker to check than to guess. Copilot only shows people what they can already open, so the question is The SharePoint Audit's first one: what can Copilot see that it shouldn't? Anonymous links, "Everyone" grants, the OneDrives of people who have left. The audit reads all of it, changes nothing, and tells you what to close first.

04. Do we need to buy anything?

You almost never need to buy anything for The SharePoint Audit or what follows it. The Opportunities Register names the licence you already hold against each next step, and the subscription it retires. We don't resell licences or earn a margin on them. Where something genuinely isn't covered we'll say so before you commit, not after.

05. What does The SharePoint Audit cost?

The SharePoint Audit is a fixed price, set in writing before work starts, and it doesn't move because the work turned out harder than expected. We invoice at the readout, not up front. If we find nothing material to fix, there's no invoice. If you go ahead with the first fix within 60 days, the audit fee is credited in full against it. We don't publish a range, because a range without a scope is a guess you'd have to unlearn.

06. What happens after the readout?

After the readout you own everything we hand over: the scorecard, both reports, the front-door mock-up and the Opportunities Register. The proposal prices the first fix: Foundations, which is permissions and structure, plus one app built after it. You can take it to anyone, including your MSP. Most take it to us, and the credit is why.

Tell us what isn’t working.

We’ll look at what you already pay for and tell you honestly whether we can help. No new software. No new subscriptions.

Book a Discovery Call