Data access governance

See your Copilot blast radius. Then shrink it.

ShareCare answers the question every Microsoft 365 customer suddenly has to answer: what is shared with the outside world — or over-shared internally so Copilot can reach it — and who can fix it?

In one line: see what is exposed across every tenant you manage, and safely fix it.

Why it matters now

Copilot can summarise, surface and cite anything a user can technically reach. Sharing links created years ago, "Everyone" groups and inherited permissions that never mattered now decide what an AI assistant will hand to the wrong person. Security teams are being asked — often for the first time — to prove the blast radius before the rollout, and keep it shrinking afterwards.

Underneath that, the classic problems have not gone anywhere: anonymous link sprawl, stale guest access, and mailbox forwarding rules used for exfiltration. Native tooling reports these thinly, one workload at a time, one tenant at a time.

What it does

  • Crawls seven planes of the estate app-only — SharePoint, OneDrive, Teams, Entra app consents, Exchange forwarding, Power Platform and Power BI. No agent, no user disruption.
  • Finds internal over-exposure — organisation-wide sharing links and whole-company groups such as "Everyone except external users". These are exactly the patterns that make Copilot surface data far more broadly than anyone intended.
  • Scores real risk as sensitivity × exposure × blast radius rather than a flat checklist, and keeps an identity-level score so one toxic guest surfaces across every share they touch.
  • Detects the dangerous specifics — anonymous edit links, dormant external guests measured by actual sign-in activity, over-permissioned OAuth applications, and mail forwarding to domains nobody owns.
  • Remediates durably — simulate, then execute after an optional grace window, with undo and retry. App-only permission revoke on OneDrive, plus downgrade and resource-level revoke-all.
  • Recertifies with the owner, not just the admin — and the owner's decision actually executes rather than landing in a report.
  • Benchmarks the fleet — rank and compare oversharing exposure across every managed tenant.

What it does not do yet

Some planes are read-only today: Exchange forwarding rules, SharePoint site roles, Power Platform and delegated-admin relationships are detected but not revoked app-only. When ShareCare cannot safely act, it tells you the precise reason instead of guessing or silently skipping.

OneDrive permission revoke and sharing-link revoke are live today. Beyond Microsoft 365, Box public links and external collaborations are covered with app-only revoke, and Slack Connect externally-shared channels are read-only pending the admin APIs that would let us act.

Inside ShareCare

What’s in the product

The screens you will actually work in.

What a finding actually looks like

Not a CSV of everything. A scored item, the reasons behind the score, the root cause, and the action — with the alternative to remediating stated next to it.

A finding on OneDrive: medium severity, edit access granted directly to an
                      outlook.com address with no expiry, risk score 45 out of 100, a score breakdown
                      reading edit access +25, no expiry +10 and freemail domain +10, the root cause,
                      and buttons to remediate, accept the risk, or revoke all sharing.

No number you cannot take apart

A score you have to trust is a score you will argue with. Every one on this screen opens into the reasons that produced it, and every reason names something you can change.

  1. The arithmetic, in the open. Edit access +25, no expiry +10, freemail domain +10. Change any one of those and the score moves — you can see in advance by how much.
  2. A cause, then a fix. Not “this file is risky” but who was granted what, directly on which resource, and the one action that ends it.
  3. Accepting the risk is a real answer. Some sharing is the business working. Accept it and it stops nagging — but it stays on the record, with your name on the decision.

See it on your own tenant

Scan detail: seven technologies in scope, SharePoint, Teams, Entra, Exchange, Power
                    Apps and Power Automate complete, OneDrive still scanning, Power BI marked not
                    licensed, Box and Slack marked not connected.
A scan that admits what it could not see. Every plane reports for itself, and two of them report that they were never read.
  1. Not licensed. The plane exists in your tenant but nothing here can reach it. It is excluded from the score rather than counted as clean.
  2. Not connected. Same again for anything outside Microsoft 365. A silent pass on a plane nobody scanned is the failure mode we refuse to ship.

Capability and what you get from it

CapabilityWhat it means for you
Cross-workload sharing and permission crawlOne picture of exposure instead of seven separate workload reports
Org-wide link and "Everyone" group detectionA direct answer to "what can Copilot reach?"
Sensitivity × exposure risk modelPrioritise the shares that actually matter, not the loudest ones
Durable remediation with grace window and undoFix safely in production, and reverse a mistake
Owner-delegated recertificationPush the decision to the person who owns the data
Fleet benchmarkingRank clients by exposure and drive the remediation conversation

Objections, answered straight

"Copilot has its own controls."

Restricted search and tenant-wide switches blunt the symptom for everyone. ShareCare finds and fixes the specific over-shared items, and does it across every client you manage.

"Will scanning disrupt users?"

The crawl is app-only and read-first. Remediation is simulate-then-execute with a grace window and undo, and it only runs on the tier you bought.

"We only need this once, before Copilot."

Sharing sprawl regenerates continuously — new links, new guests, new apps. And the continuous version is what becomes compliance evidence.

"Can it fix Exchange forwarding rules?"

It detects them. App-only revoke for that plane needs Exchange PowerShell and is on the roadmap. We would rather say that than imply coverage we do not have.

Start with a Copilot-readiness assessment

A real crawl of your worst tenants, a scored exposure report, and a remediation plan — whether or not you buy anything afterwards.