Permissions & Transparency
All of Controlio's access is read-only. No agent is installed, nothing is written to your environment, and your content is never reached.
Permissions taken
| Surface | Type | Purpose |
|---|---|---|
| Microsoft Graph | Read-only application permissions | Reading Entra, Intune, Defender and similar configuration |
| Microsoft Graph | Limited delegated read | Sign-in and basic user and directory read |
| Exchange Online | Global Reader (read-only) | Reading Exchange, Teams and Purview configuration |
Permissions not taken
Broad permissions such as Sites.FullControl are never requested. The content of a mailbox, file or message is never reached. No write or change permission is taken.
Global Reader and the Exchange commands are limited to reads (Get-*). Controlio reads configuration; it cannot change it.
Privacy
Data is kept to a minimum. Full user or mail lists are not stored, only counts. Identity is kept only as far as a finding requires it, and a stable object identifier (GUID) is used when identity has to be stored, because mail addresses and names change over time.
Verification
The full list of permissions and the audit level are published on the transparency page. A customer can verify it in their own Microsoft portal.