Skip to main content

Permissions & Transparency

All of Controlio's access is read-only. No agent is installed, nothing is written to your environment, and your content is never reached.

Permissions taken

SurfaceTypePurpose
Microsoft GraphRead-only application permissionsReading Entra, Intune, Defender and similar configuration
Microsoft GraphLimited delegated readSign-in and basic user and directory read
Exchange OnlineGlobal Reader (read-only)Reading Exchange, Teams and Purview configuration

Permissions not taken

Broad permissions such as Sites.FullControl are never requested. The content of a mailbox, file or message is never reached. No write or change permission is taken.

Read-only assurance

Global Reader and the Exchange commands are limited to reads (Get-*). Controlio reads configuration; it cannot change it.

Privacy

Data is kept to a minimum. Full user or mail lists are not stored, only counts. Identity is kept masked when needed, and a stable object identifier (GUID) is used when identity has to be stored.

Verification

The full list of permissions and the audit level are published on the transparency page. A customer can verify it in their own Microsoft portal.