Permissions & Transparency
All of Controlio's access is read-only. No agent is installed, nothing is written to your environment, and your content is never reached.
Permissions taken
| Surface | Type | Purpose |
|---|---|---|
| Microsoft Graph | Read-only application permissions | Reading Entra, Intune, Defender and similar configuration |
| Microsoft Graph | Limited delegated read | Sign-in and basic user and directory read |
| Exchange Online | Global Reader (read-only) | Reading Exchange, Teams and Purview configuration |
Permissions not taken
Broad permissions such as Sites.FullControl are never requested. The content of a mailbox, file or message is never reached. No write or change permission is taken.
Global Reader and the Exchange commands are limited to reads (Get-*). Controlio reads configuration; it cannot change it.
Privacy
Data is kept to a minimum. Full user or mail lists are not stored, only counts. Identity is kept masked when needed, and a stable object identifier (GUID) is used when identity has to be stored.
Verification
The full list of permissions and the audit level are published on the transparency page. A customer can verify it in their own Microsoft portal.