Skip to main content

Permissions & Transparency

All of Controlio's access is read-only. No agent is installed, nothing is written to your environment, and your content is never reached.

Permissions taken

SurfaceTypePurpose
Microsoft GraphRead-only application permissionsReading Entra, Intune, Defender and similar configuration
Microsoft GraphLimited delegated readSign-in and basic user and directory read
Exchange OnlineGlobal Reader (read-only)Reading Exchange, Teams and Purview configuration

Permissions not taken

Broad permissions such as Sites.FullControl are never requested. The content of a mailbox, file or message is never reached. No write or change permission is taken.

Read-only assurance

Global Reader and the Exchange commands are limited to reads (Get-*). Controlio reads configuration; it cannot change it.

Privacy

Data is kept to a minimum. Full user or mail lists are not stored, only counts. Identity is kept only as far as a finding requires it, and a stable object identifier (GUID) is used when identity has to be stored, because mail addresses and names change over time.

Verification

The full list of permissions and the audit level are published on the transparency page. A customer can verify it in their own Microsoft portal.