Skip to content
Connector permissions

What you are granting, and why

When you connect a Microsoft 365 or Google Workspace tenant to one of the diagnostic tools, this page lists every permission requested, why it is requested, what is stored, what is never stored, and how to remove access. It is generated from the code that makes the request, so it cannot drift from what we actually ask for.

The short version

  • The diagnostics read and never write. Every Microsoft Graph permission requested by a scan is a Microsoft read permission (the name ends in .Read.All or .Read.Directory).
  • HELMGATE is the exception, and it is what HELMGATE is for. It is a separate application you consent to separately, and it holds 4 permissions that change your tenant. Nothing under any of them runs until a second named person approves that specific action. The full list is below.
  • You are the controller. For the directory data these tools read, you are the data controller and ITSailor acts as your data processor. The processing runs on your instruction, which you give by connecting your tenant.
  • Identities are digested before logging. Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs. The report shown to your administrator still carries real identities, because it is your own tenant and you need them to act.
  • You can revoke at any time. Your administrator removes the grant directly with Microsoft or Google, without us, and all further reads stop at once.
Read the data-handling terms in the Privacy Policy

SaaS Auditor

Microsoft Graph

Reads directory, licence, and security posture to find dormant accounts, wasted licences, Shadow IT, and standing admin risk.

A Microsoft 365 tenant administrator approves the connection. Nothing below can change your tenant.

SaaS Auditor Microsoft Graph permissions: scope, purpose, read-only, what is stored, what is never stored
PermissionWhy it is requestedAccessWhat is storedNever stored
User.Read.AllRead the user roster and account status, so the audit can count active, disabled, and stale accounts.Read-onlyCounts and posture flags for the report shown to your administrator.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
AuditLog.Read.AllRead sign-in activity (last sign-in dates), so dormant and unused accounts can be found.Read-onlyCounts and posture flags for the report shown to your administrator.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
Organization.Read.AllRead tenant and licence inventory, so assigned licences can be matched to active use.Read-onlyLicence counts and utilisation figures for the report.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
Directory.Read.AllRead service principals and OAuth grants for Shadow IT and third-party app discovery.Read-onlyCounts and posture flags for the report shown to your administrator.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
Application.Read.AllRead the registered and enterprise application detail behind those grants.Read-onlyCounts and posture flags for the report shown to your administrator.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
SecurityEvents.Read.AllRead Microsoft Secure Score and security findings for posture context.Read-onlySecure Score figures and finding counts for the report.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
Policy.Read.AllRead Conditional Access policy posture.Read-onlyPolicy posture flags for the report.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
RoleManagement.Read.DirectoryRead the directory role roster to find standing, non-PIM administrator assignments.Read-onlyThe count of standing privileged assignments for the report.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
IdentityRiskEvent.Read.AllRead Entra identity-risk detections (risky sign-ins), where the tenant licence exposes them.Read-onlyRisk-detection counts for the report.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
Reports.Read.AllRead per-service usage reports to measure feature-level adoption.Read-onlyAggregate adoption figures for the report.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
offline_accessLet the connector refresh its own access token, so you can enrol in continuous monitoring without signing in again.Read-onlyYour sign-in refresh token, held server-side and encrypted, for up to 30 minutes so you can enrol in continuous monitoring (Tenant Monitor) without signing in again. On enrol it moves to encrypted long-term storage; otherwise it expires and is deleted.The token is never written in plaintext and never reaches your browser. This permission carries no directory read access.

How long it is kept

Your report is held server-side for up to ten minutes so the page can load it, then it expires. When you start a scan, your sign-in refresh token is also held server-side, encrypted, for up to thirty minutes so you can enrol in continuous monitoring without signing in again, then it is deleted. If you enrol in continuous monitoring (Tenant Monitor), the encrypted refresh token and the aggregate posture move to long-term storage so the scan can repeat on schedule; if you never enrol, nothing is kept.

How to revoke

A tenant administrator can remove the grant at any time in the Microsoft Entra admin center, under Enterprise applications, by deleting the ITSailor application. Revoking access stops all further reads at once.

Back to SaaS Auditor

SaaS Auditor

Google Workspace Admin SDK

Reads the Workspace directory and per-user security state for the same dormant-account, licence, and Shadow IT audit.

A Google Workspace super administrator approves the connection. 1 of the 3 permissions below grants more than a read, marked Broader than read in the table, and each one says what it can do beyond reading.

SaaS Auditor Google Workspace Admin SDK permissions: scope, purpose, read-only, what is stored, what is never stored
PermissionWhy it is requestedAccessWhat is storedNever stored
https://www.googleapis.com/auth/admin.directory.user.readonlyRead the user list and per-user status, last login, and administrator flag.Read-onlyCounts and posture flags for the report shown to your administrator.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
https://www.googleapis.com/auth/admin.directory.domain.readonlyRead domain and customer account information.Read-onlyDomain and account figures for the report.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
https://www.googleapis.com/auth/admin.directory.user.securityRead per-user third-party OAuth token grants (for Shadow IT discovery) and two-step verification state.Google publishes no read-only variant of this scope. It covers every operation on application-specific passwords, OAuth tokens and verification codes, which includes revoking them. We use it to read only: token grants for Shadow IT discovery, and two-step verification state. Your administrator can confirm the scope and revoke it at any time, and the scan is the only thing that would stop working.Broader than readShadow IT grant counts and MFA-coverage figures for the report.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.

How long it is kept

Your report is held server-side for up to ten minutes so the page can load it, then it expires. No sign-in token is stored: the one-off Google scan keeps nothing beyond that window. Use of Google Workspace data follows the Google API Services User Data Policy, including the Limited Use requirements.

How to revoke

A Workspace super administrator can remove the grant at admin.google.com under Security, API controls, App access control, or a user can remove it at myaccount.google.com under Security. Revoking access stops all further reads at once.

Back to SaaS Auditor

Offboarding Risk Scan

Microsoft Graph

Reads leaver-relevant evidence (disabled users, sign-in activity, OAuth grants, roles, devices, drives, sharing) to build an offboarding evidence pack. No remediation permission is requested.

A Microsoft 365 tenant administrator approves the connection. Nothing below can change your tenant.

Offboarding Risk Scan Microsoft Graph permissions: scope, purpose, read-only, what is stored, what is never stored
PermissionWhy it is requestedAccessWhat is storedNever stored
User.Read.AllRead the user list and account status to find disabled or lingering leaver accounts.Read-onlyCounts and posture flags for the report shown to your administrator.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
AuditLog.Read.AllRead sign-in activity to show whether a departed account is still being used.Read-onlyCounts and posture flags for the report shown to your administrator.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
Directory.Read.AllRead service principals and OAuth grants a leaver may still hold.Read-onlyCounts and posture flags for the report shown to your administrator.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
Application.Read.AllRead the application detail behind those grants.Read-onlyCounts and posture flags for the report shown to your administrator.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
Organization.Read.AllRead tenant and licence context for the evidence pack.Read-onlyLicence and tenant figures for the report.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
Policy.Read.AllRead the Conditional Access posture that governs leaver access.Read-onlyPolicy posture flags for the report.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
RoleManagement.Read.DirectoryRead directory role assignments to catch privileged roles left on a leaver.Read-onlyThe count of privileged assignments for the report.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
DeviceManagementManagedDevices.Read.AllRead the Intune managed-device inventory to confirm a leaver has no device left active.Read-onlyManaged-device counts for the report.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
SecurityEvents.Read.AllRead security alerts relevant to the offboarding evidence pack.Read-onlySecurity-alert counts for the report.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
Files.Read.AllRead OneDrive and SharePoint drive presence for leavers: drive type and quota, to flag data left behind.Read-onlyDrive presence and quota state per flagged account, for the report.The contents of documents are not read; only drive type and quota state are summarised, and raw identities are digested before logging.
SharePointTenantSettings.Read.AllRead the tenant external-sharing posture.Read-onlyExternal-sharing posture flags for the report.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.

How long it is kept

The scan result is held in a short-lived server session for ten minutes to render your report and evidence pack, then it expires. Nothing is retained long-term.

How to revoke

A tenant administrator can remove the grant at any time in the Microsoft Entra admin center, under Enterprise applications, by deleting the ITSailor application. Revoking access stops all further reads at once.

Back to Offboarding Risk Scan

Microsoft 365 Security Scorecard

Microsoft Graph

Reads Conditional Access, Security Defaults, admin roles, PIM, app-consent policy, Intune enrolment, and SharePoint sharing to verify posture against the ITS-M365 baseline.

A Microsoft 365 tenant administrator approves the connection. Nothing below can change your tenant.

Microsoft 365 Security Scorecard Microsoft Graph permissions: scope, purpose, read-only, what is stored, what is never stored
PermissionWhy it is requestedAccessWhat is storedNever stored
User.Read.AllRead the user roster to size the tenant and check per-user posture.Read-onlyAggregate scorecard metrics for the drift trend.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
Directory.Read.AllRead directory objects for app-consent and service-principal posture.Read-onlyAggregate scorecard metrics for the drift trend.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
Policy.Read.AllRead Conditional Access and the authorization (app-consent) policy.Read-onlyPolicy posture flags, as aggregate scorecard metrics.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
RoleManagement.Read.DirectoryRead role assignments and PIM eligibility to check the standing Global Administrator count.Read-onlyThe count of standing Global Administrators, as an aggregate metric.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
AuditLog.Read.AllRead sign-in activity for MFA and legacy-authentication signals.Read-onlyAggregate scorecard metrics for the drift trend.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
SecurityEvents.Read.AllRead Microsoft Secure Score as advisory context.Read-onlySecure Score figures, as advisory context in the report.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
DeviceManagementManagedDevices.Read.AllRead Intune enrolment to verify device-management coverage.Read-onlyEnrolment coverage figures, as aggregate metrics.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
SharePointTenantSettings.Read.AllRead the external-sharing posture.Read-onlyExternal-sharing posture flags, as aggregate metrics.Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained.
offline_accessReserved so a scheduled re-scan could refresh its own access token without a fresh sign-in. Scheduled re-scans are not enabled for the scorecard yet.Read-onlyNothing today. The scorecard scan does not retain your sign-in token; this permission is held in reserve for scheduled re-scans, which are not enabled yet.No directory data. This permission carries no read access, only the ability to refresh an access token.

How long it is kept

The live scan produces aggregate scorecard metrics (percentage, band, gap counts, per-control verdicts) kept for up to 180 days for the drift trend, keyed to an opaque random token in your browser, not your email. No identities are stored.

How to revoke

A tenant administrator can remove the grant at any time in the Microsoft Entra admin center, under Enterprise applications, by deleting the ITSailor application. Revoking access stops all further reads at once.

Back to Microsoft 365 Security Scorecard

HELMGATE

Microsoft Graph

The only ITSailor connection that can change your tenant. It ends sign-in sessions, blocks sign-in, removes standard group memberships and changes licences, each one only after a second named person approves that specific action.

A Microsoft 365 tenant administrator, on a separate application from every scan above approves the connection. 4 of the 5 permissions below grant more than a read, marked Broader than read in the table, and each one says what it can do beyond reading.

HELMGATE Microsoft Graph permissions: scope, purpose, read-only, what is stored, what is never stored
PermissionWhy it is requestedAccessWhat is storedNever stored
User.RevokeSessions.AllEnd a named user’s active sign-in sessions, so a compromised or departing account stops being usable immediately.This permission revokes sign-in sessions and does nothing else: it cannot read or edit a user record, and Microsoft publishes no wider application permission for the call. Nothing under this permission runs without a second named person approving the specific action first. The engine refuses when the approver is the requester, and refuses outright against any account you list as protected.Broader than readThe action, the target identifier, the approver and the timestamp.The engine records the action, who requested it, who approved it, the target identifier and the timestamp, in a hash-chained evidence chain. It does not copy mailbox content, files, or directory records into ITSailor systems.
User.Read.AllRead the account being acted on, and confirm the connector can reach your directory at all. Microsoft requires it alongside the block-sign-in permission below.Read-onlyThe target identifier and the action outcome.The engine records the action, who requested it, who approved it, the target identifier and the timestamp, in a hash-chained evidence chain. It does not copy mailbox content, files, or directory records into ITSailor systems.
User.EnableDisableAccount.AllBlock sign-in on a named account, and unblock it again to reverse the action.This permission sets one property, accountEnabled, and nothing else on the user object. Microsoft names it plus User.Read.All as the least privileged combination; the alternative, User.ReadWrite.All, would additionally permit editing every name, sign-in name and identity in your tenant. Nothing under this permission runs without a second named person approving the specific action first. The engine refuses when the approver is the requester, and refuses outright against any account you list as protected.Broader than readThe action, the target identifier, the approver and the timestamp.The engine records the action, who requested it, who approved it, the target identifier and the timestamp, in a hash-chained evidence chain. It does not copy mailbox content, files, or directory records into ITSailor systems.
GroupMember.ReadWrite.AllRemove a named user from a named standard group during offboarding, because group membership is how access survives a disabled account.This permission can add and remove members on any group in the tenant, which is wider than the one thing the engine does with it: remove one named user from one named group. It cannot remove a member from a role-assignable group, which needs a role-management permission ITSailor does not hold and will not request. Nothing under this permission runs without a second named person approving the specific action first. The engine refuses when the approver is the requester, and refuses outright against any account you list as protected.Broader than readThe action, both identifiers, the approver and the timestamp.The engine records the action, who requested it, who approved it, the target identifier and the timestamp, in a hash-chained evidence chain. It does not copy mailbox content, files, or directory records into ITSailor systems.
LicenseAssignment.ReadWrite.AllAdd or remove one named licence SKU on a named user, so a departure stops being billed and a joiner can be licensed.This permission can change licence assignments on any user in the tenant. The engine changes one named SKU per approved action and refuses a call that names none. Removing a licence can make the service data behind it inaccessible on Microsoft’s own retention schedule, which is Microsoft’s behaviour and not something ITSailor can reverse. Nothing under this permission runs without a second named person approving the specific action first. The engine refuses when the approver is the requester, and refuses outright against any account you list as protected.Broader than readThe action, the target identifier, the SKU, the approver and the timestamp.The engine records the action, who requested it, who approved it, the target identifier and the timestamp, in a hash-chained evidence chain. It does not copy mailbox content, files, or directory records into ITSailor systems.

How long it is kept

Every request, policy decision, approval and execution is written to a hash-chained evidence chain held for the life of your engagement, so an auditor can be shown what happened and check it themselves. The chain records identifiers, decisions and timestamps; it does not hold mailbox content, files or directory records.

How to revoke

A tenant administrator can remove the grant at any time in the Microsoft Entra admin center, under Enterprise applications, by deleting the HELMGATE application. Revoking it stops every action at once: the engine cannot obtain a token, the connector reports itself unavailable, and nothing executes. This is rehearsed as a scheduled drill during a pilot, with you watching.

Back to HELMGATE

The paid Offboarding Evidence connector

The Offboarding Evidence subscription requests two permissions the free scan above does not: offline_access and MailboxSettings.Read. Both are still read permissions; neither can change your tenant.

The free scan above is one browser session and finishes well inside the hour a Microsoft Graph access token stays valid, so it never needs to renew one. The paid subscription reruns once a day with nobody at the console, and a token that has expired cannot renew itself: offline_access is what lets the connector refresh its own access token instead of asking your administrator to reconnect before every run.

MailboxSettings.Read is not requested by the free scan at all, which is why its own evidence pack states that mailbox forwarding and redirect rules can only be checked once this permission is granted. The paid connector requests it so a leaver's mailbox rules are read directly rather than left as a gap in the evidence.

Recipients

Every party that receives personal data from ITSailor, condensed from the Privacy Policy. Most are sub-processors, acting on documented instruction. Some are not, and their rows open by saying so. The policy is the authoritative source and is updated first when this list changes.

Recipients: party, role and purpose, and jurisdiction
ProcessorPurposeJurisdiction
Stripe Payments Europe Ltd.Our processor for executing payments, subscription charges and refunds on our instruction. Independent controller for fraud prevention, financial and security risk, AML and KYC obligations, and developing its own productsIreland (EEA). Processing: Ireland, inside the EEA, with routing to Stripe group entities outside the EEA. Transfers: Standard Contractual Clauses (EU) 2021/914 for any routing outside the EEA; Stripe also self-certifies under the EU-US Data Privacy Framework.
Resend, Inc.Transactional email deliveryUnited States. Processing: United States, outside the EEA. Transfers: EU-US Data Privacy Framework, with the Standard Contractual Clauses (EU) 2021/914 in place regardless.
Upstash, Inc.Managed storage for newsletter and rate-limit stateUnited States. Processing: United States, outside the EEA. Transfers: Data processing addendum and the Standard Contractual Clauses (EU) 2021/914. No framework listing is claimed.
Hetzner Online GmbHProduction server hosting and backupsGermany (EEA). Processing: Falkenstein, Germany, inside the EEA. Transfers: None needed. The processing does not leave the EEA.
Cloudflare, Inc.DNS, CDN, and Zero Trust TunnelUnited States. Processing: A global edge network outside the EEA; EU traffic is served from EU edge nodes. Transfers: EU-US Data Privacy Framework, with the Standard Contractual Clauses (EU) 2021/914 in place regardless.
Vercel, Inc.Frontend hosting and edge logsUnited States. Processing: Serverless functions execute in Frankfurt, Germany (fra1), inside the EEA. Static assets and request logs are served from a global edge network outside the EEA. Transfers: EU-US Data Privacy Framework, with the Standard Contractual Clauses (EU) 2021/914 in place regardless.
Plausible Insights OÜCookie-free website and conversion analyticsEstonia (EEA). Processing: Inside the EEA. Transfers: None needed. The processing does not leave the EEA.
GitHub, Inc.Private repository hosting and tool authenticationUnited States. Processing: United States, outside the EEA. Transfers: EU-US Data Privacy Framework, self-certified under the Microsoft umbrella, with the Standard Contractual Clauses (EU) 2021/914 in place regardless.
Anthropic (Claude API)SaaS Auditor briefs from aggregate figures, contract-document extraction, internal Ops Log draftingNot verified. This row names the service rather than a contracting entity; ask us and we will tell you which entity we contract with. Processing: Outside the EEA. Transfers: Standard Contractual Clauses (EU) 2021/914 alone. No framework listing is claimed, because none has been verified.
OpenAI (API)Free-tool diagnostic report and the Tenant Monitor reportNot verified. This row names the service rather than a contracting entity; ask us and we will tell you which entity we contract with. Processing: Outside the EEA. Transfers: Standard Contractual Clauses (EU) 2021/914 alone. No framework listing is claimed, because none has been verified.
Cal.comScheduling for discovery calls, demos and paid workshop sessionsNot verified. This row names the service rather than a contracting entity; ask us and we will tell you which entity we contract with. Processing: Outside the EEA. Transfers: Standard Contractual Clauses (EU) 2021/914 alone. No framework listing is claimed, because none has been verified.
DocRaptorRendering purchased eBook PDFs, which carry the buyer email in the licence lineNot verified. This row names the service rather than a contracting entity; ask us and we will tell you which entity we contract with. Processing: Outside the EEA. Transfers: Standard Contractual Clauses (EU) 2021/914 alone. No framework listing is claimed, because none has been verified.
Google LLC (reCAPTCHA)Not our sub-processor. The reCAPTCHA script loads into your browser on our contact and scan-request forms, so your browser sends device, network and interaction data to Google directly. We are a controller for that collection and transmission (CJEU C-40/17 Fashion ID); Google determines what it does with the data afterwardsUnited States. Processing: Outside the EEA. The data goes from your browser to Google and does not pass through our systems. Transfers: No transfer instrument of ours covers this path, and we claim none. Whether one is required is with counsel.
Microsoft Ireland Operations LimitedNot our sub-processor. Licensor and platform operator for Microsoft 365 bought through us via Pax8. Microsoft processes your tenant content as YOUR processor under its Data Protection Addendum, on your instructions and not oursIreland (EEA). Processing: Your own tenant, under the agreement you hold with Microsoft. The contracting entity is inside the EEA. Transfers: Not ours to state. Microsoft processes tenant content on your instruction under its Data Protection Addendum with you, so your agreement governs that transfer and not ours.
Pax8 Inc.Not our sub-processor. Wholesale supplier and provisioning rail for Microsoft licensing. Pax8 receives your order data as an independent controller in its own right to fulfil the wholesale order; your tenant data does not reach itNetherlands (EEA), for the EU wholesale operation. Processing: Netherlands, inside the EEA. Transfers: Not ours to state. Pax8 receives the order data as an independent controller, so its own position governs that processing.
Read the full sub-processor disclosure

Azure, and why it is not in the table above

SEAWALL Azure requests no Microsoft Graph permissions. Not a narrow set: none. Access to an Azure subscription does not come from a consented API permission at all, it comes from an RBAC role assignment you make yourself in your own portal and can delete in one click, without telling us.

The role is the built-in Reader, which grants */read and nothing else.

We deliberately do not ask for Cost Management Reader, despite the name suggesting it is the read-only one for cost. Its action list contains the wildcard Microsoft.Support/*, which permits support-ticket creation. Reading a permission by its name rather than by its action list is a mistake this practice has made once before and does not intend to repeat.

Sufficiency was settled by running every read path the collector needs as a principal holding Reader and nothing else, on 2026-08-15: budgets, Advisor, policy assignments, resources, Resource Graph and Cost Management all answered. SEAWALL never writes to your Azure, in any tier.

Documents

A Data Processing Agreement (DPA) covering this processing is available on request during scoping. The controller-to-processor terms follow the requirements of GDPR Article 28.