What you are granting, and why
When you connect a Microsoft 365 or Google Workspace tenant to one of the diagnostic tools, this page lists every permission requested, why it is requested, what is stored, what is never stored, and how to remove access. It is generated from the code that makes the request, so it cannot drift from what we actually ask for.
The short version
- The diagnostics read and never write. Every Microsoft Graph permission requested by a scan is a Microsoft read permission (the name ends in
.Read.Allor.Read.Directory). - HELMGATE is the exception, and it is what HELMGATE is for. It is a separate application you consent to separately, and it holds 4 permissions that change your tenant. Nothing under any of them runs until a second named person approves that specific action. The full list is below.
- You are the controller. For the directory data these tools read, you are the data controller and ITSailor acts as your data processor. The processing runs on your instruction, which you give by connecting your tenant.
- Identities are digested before logging. Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs. The report shown to your administrator still carries real identities, because it is your own tenant and you need them to act.
- You can revoke at any time. Your administrator removes the grant directly with Microsoft or Google, without us, and all further reads stop at once.
SaaS Auditor
Microsoft GraphReads directory, licence, and security posture to find dormant accounts, wasted licences, Shadow IT, and standing admin risk.
A Microsoft 365 tenant administrator approves the connection. Nothing below can change your tenant.
| Permission | Why it is requested | Access | What is stored | Never stored |
|---|---|---|---|---|
User.Read.All | Read the user roster and account status, so the audit can count active, disabled, and stale accounts. | Read-only | Counts and posture flags for the report shown to your administrator. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
AuditLog.Read.All | Read sign-in activity (last sign-in dates), so dormant and unused accounts can be found. | Read-only | Counts and posture flags for the report shown to your administrator. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
Organization.Read.All | Read tenant and licence inventory, so assigned licences can be matched to active use. | Read-only | Licence counts and utilisation figures for the report. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
Directory.Read.All | Read service principals and OAuth grants for Shadow IT and third-party app discovery. | Read-only | Counts and posture flags for the report shown to your administrator. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
Application.Read.All | Read the registered and enterprise application detail behind those grants. | Read-only | Counts and posture flags for the report shown to your administrator. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
SecurityEvents.Read.All | Read Microsoft Secure Score and security findings for posture context. | Read-only | Secure Score figures and finding counts for the report. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
Policy.Read.All | Read Conditional Access policy posture. | Read-only | Policy posture flags for the report. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
RoleManagement.Read.Directory | Read the directory role roster to find standing, non-PIM administrator assignments. | Read-only | The count of standing privileged assignments for the report. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
IdentityRiskEvent.Read.All | Read Entra identity-risk detections (risky sign-ins), where the tenant licence exposes them. | Read-only | Risk-detection counts for the report. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
Reports.Read.All | Read per-service usage reports to measure feature-level adoption. | Read-only | Aggregate adoption figures for the report. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
offline_access | Let the connector refresh its own access token, so you can enrol in continuous monitoring without signing in again. | Read-only | Your sign-in refresh token, held server-side and encrypted, for up to 30 minutes so you can enrol in continuous monitoring (Tenant Monitor) without signing in again. On enrol it moves to encrypted long-term storage; otherwise it expires and is deleted. | The token is never written in plaintext and never reaches your browser. This permission carries no directory read access. |
How long it is kept
Your report is held server-side for up to ten minutes so the page can load it, then it expires. When you start a scan, your sign-in refresh token is also held server-side, encrypted, for up to thirty minutes so you can enrol in continuous monitoring without signing in again, then it is deleted. If you enrol in continuous monitoring (Tenant Monitor), the encrypted refresh token and the aggregate posture move to long-term storage so the scan can repeat on schedule; if you never enrol, nothing is kept.
How to revoke
A tenant administrator can remove the grant at any time in the Microsoft Entra admin center, under Enterprise applications, by deleting the ITSailor application. Revoking access stops all further reads at once.
SaaS Auditor
Google Workspace Admin SDKReads the Workspace directory and per-user security state for the same dormant-account, licence, and Shadow IT audit.
A Google Workspace super administrator approves the connection. 1 of the 3 permissions below grants more than a read, marked Broader than read in the table, and each one says what it can do beyond reading.
| Permission | Why it is requested | Access | What is stored | Never stored |
|---|---|---|---|---|
https://www.googleapis.com/auth/admin.directory.user.readonly | Read the user list and per-user status, last login, and administrator flag. | Read-only | Counts and posture flags for the report shown to your administrator. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
https://www.googleapis.com/auth/admin.directory.domain.readonly | Read domain and customer account information. | Read-only | Domain and account figures for the report. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
https://www.googleapis.com/auth/admin.directory.user.security | Read per-user third-party OAuth token grants (for Shadow IT discovery) and two-step verification state.Google publishes no read-only variant of this scope. It covers every operation on application-specific passwords, OAuth tokens and verification codes, which includes revoking them. We use it to read only: token grants for Shadow IT discovery, and two-step verification state. Your administrator can confirm the scope and revoke it at any time, and the scan is the only thing that would stop working. | Broader than read | Shadow IT grant counts and MFA-coverage figures for the report. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
How long it is kept
Your report is held server-side for up to ten minutes so the page can load it, then it expires. No sign-in token is stored: the one-off Google scan keeps nothing beyond that window. Use of Google Workspace data follows the Google API Services User Data Policy, including the Limited Use requirements.
How to revoke
A Workspace super administrator can remove the grant at admin.google.com under Security, API controls, App access control, or a user can remove it at myaccount.google.com under Security. Revoking access stops all further reads at once.
Offboarding Risk Scan
Microsoft GraphReads leaver-relevant evidence (disabled users, sign-in activity, OAuth grants, roles, devices, drives, sharing) to build an offboarding evidence pack. No remediation permission is requested.
A Microsoft 365 tenant administrator approves the connection. Nothing below can change your tenant.
| Permission | Why it is requested | Access | What is stored | Never stored |
|---|---|---|---|---|
User.Read.All | Read the user list and account status to find disabled or lingering leaver accounts. | Read-only | Counts and posture flags for the report shown to your administrator. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
AuditLog.Read.All | Read sign-in activity to show whether a departed account is still being used. | Read-only | Counts and posture flags for the report shown to your administrator. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
Directory.Read.All | Read service principals and OAuth grants a leaver may still hold. | Read-only | Counts and posture flags for the report shown to your administrator. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
Application.Read.All | Read the application detail behind those grants. | Read-only | Counts and posture flags for the report shown to your administrator. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
Organization.Read.All | Read tenant and licence context for the evidence pack. | Read-only | Licence and tenant figures for the report. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
Policy.Read.All | Read the Conditional Access posture that governs leaver access. | Read-only | Policy posture flags for the report. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
RoleManagement.Read.Directory | Read directory role assignments to catch privileged roles left on a leaver. | Read-only | The count of privileged assignments for the report. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
DeviceManagementManagedDevices.Read.All | Read the Intune managed-device inventory to confirm a leaver has no device left active. | Read-only | Managed-device counts for the report. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
SecurityEvents.Read.All | Read security alerts relevant to the offboarding evidence pack. | Read-only | Security-alert counts for the report. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
Files.Read.All | Read OneDrive and SharePoint drive presence for leavers: drive type and quota, to flag data left behind. | Read-only | Drive presence and quota state per flagged account, for the report. | The contents of documents are not read; only drive type and quota state are summarised, and raw identities are digested before logging. |
SharePointTenantSettings.Read.All | Read the tenant external-sharing posture. | Read-only | External-sharing posture flags for the report. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
How long it is kept
The scan result is held in a short-lived server session for ten minutes to render your report and evidence pack, then it expires. Nothing is retained long-term.
How to revoke
A tenant administrator can remove the grant at any time in the Microsoft Entra admin center, under Enterprise applications, by deleting the ITSailor application. Revoking access stops all further reads at once.
Microsoft 365 Security Scorecard
Microsoft GraphReads Conditional Access, Security Defaults, admin roles, PIM, app-consent policy, Intune enrolment, and SharePoint sharing to verify posture against the ITS-M365 baseline.
A Microsoft 365 tenant administrator approves the connection. Nothing below can change your tenant.
| Permission | Why it is requested | Access | What is stored | Never stored |
|---|---|---|---|---|
User.Read.All | Read the user roster to size the tenant and check per-user posture. | Read-only | Aggregate scorecard metrics for the drift trend. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
Directory.Read.All | Read directory objects for app-consent and service-principal posture. | Read-only | Aggregate scorecard metrics for the drift trend. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
Policy.Read.All | Read Conditional Access and the authorization (app-consent) policy. | Read-only | Policy posture flags, as aggregate scorecard metrics. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
RoleManagement.Read.Directory | Read role assignments and PIM eligibility to check the standing Global Administrator count. | Read-only | The count of standing Global Administrators, as an aggregate metric. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
AuditLog.Read.All | Read sign-in activity for MFA and legacy-authentication signals. | Read-only | Aggregate scorecard metrics for the drift trend. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
SecurityEvents.Read.All | Read Microsoft Secure Score as advisory context. | Read-only | Secure Score figures, as advisory context in the report. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
DeviceManagementManagedDevices.Read.All | Read Intune enrolment to verify device-management coverage. | Read-only | Enrolment coverage figures, as aggregate metrics. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
SharePointTenantSettings.Read.All | Read the external-sharing posture. | Read-only | External-sharing posture flags, as aggregate metrics. | Raw names, email addresses, and user principal names are replaced with a one-way digest before anything is written to our logs; the raw values are not retained. |
offline_access | Reserved so a scheduled re-scan could refresh its own access token without a fresh sign-in. Scheduled re-scans are not enabled for the scorecard yet. | Read-only | Nothing today. The scorecard scan does not retain your sign-in token; this permission is held in reserve for scheduled re-scans, which are not enabled yet. | No directory data. This permission carries no read access, only the ability to refresh an access token. |
How long it is kept
The live scan produces aggregate scorecard metrics (percentage, band, gap counts, per-control verdicts) kept for up to 180 days for the drift trend, keyed to an opaque random token in your browser, not your email. No identities are stored.
How to revoke
A tenant administrator can remove the grant at any time in the Microsoft Entra admin center, under Enterprise applications, by deleting the ITSailor application. Revoking access stops all further reads at once.
HELMGATE
Microsoft GraphThe only ITSailor connection that can change your tenant. It ends sign-in sessions, blocks sign-in, removes standard group memberships and changes licences, each one only after a second named person approves that specific action.
A Microsoft 365 tenant administrator, on a separate application from every scan above approves the connection. 4 of the 5 permissions below grant more than a read, marked Broader than read in the table, and each one says what it can do beyond reading.
| Permission | Why it is requested | Access | What is stored | Never stored |
|---|---|---|---|---|
User.RevokeSessions.All | End a named user’s active sign-in sessions, so a compromised or departing account stops being usable immediately.This permission revokes sign-in sessions and does nothing else: it cannot read or edit a user record, and Microsoft publishes no wider application permission for the call. Nothing under this permission runs without a second named person approving the specific action first. The engine refuses when the approver is the requester, and refuses outright against any account you list as protected. | Broader than read | The action, the target identifier, the approver and the timestamp. | The engine records the action, who requested it, who approved it, the target identifier and the timestamp, in a hash-chained evidence chain. It does not copy mailbox content, files, or directory records into ITSailor systems. |
User.Read.All | Read the account being acted on, and confirm the connector can reach your directory at all. Microsoft requires it alongside the block-sign-in permission below. | Read-only | The target identifier and the action outcome. | The engine records the action, who requested it, who approved it, the target identifier and the timestamp, in a hash-chained evidence chain. It does not copy mailbox content, files, or directory records into ITSailor systems. |
User.EnableDisableAccount.All | Block sign-in on a named account, and unblock it again to reverse the action.This permission sets one property, accountEnabled, and nothing else on the user object. Microsoft names it plus User.Read.All as the least privileged combination; the alternative, User.ReadWrite.All, would additionally permit editing every name, sign-in name and identity in your tenant. Nothing under this permission runs without a second named person approving the specific action first. The engine refuses when the approver is the requester, and refuses outright against any account you list as protected. | Broader than read | The action, the target identifier, the approver and the timestamp. | The engine records the action, who requested it, who approved it, the target identifier and the timestamp, in a hash-chained evidence chain. It does not copy mailbox content, files, or directory records into ITSailor systems. |
GroupMember.ReadWrite.All | Remove a named user from a named standard group during offboarding, because group membership is how access survives a disabled account.This permission can add and remove members on any group in the tenant, which is wider than the one thing the engine does with it: remove one named user from one named group. It cannot remove a member from a role-assignable group, which needs a role-management permission ITSailor does not hold and will not request. Nothing under this permission runs without a second named person approving the specific action first. The engine refuses when the approver is the requester, and refuses outright against any account you list as protected. | Broader than read | The action, both identifiers, the approver and the timestamp. | The engine records the action, who requested it, who approved it, the target identifier and the timestamp, in a hash-chained evidence chain. It does not copy mailbox content, files, or directory records into ITSailor systems. |
LicenseAssignment.ReadWrite.All | Add or remove one named licence SKU on a named user, so a departure stops being billed and a joiner can be licensed.This permission can change licence assignments on any user in the tenant. The engine changes one named SKU per approved action and refuses a call that names none. Removing a licence can make the service data behind it inaccessible on Microsoft’s own retention schedule, which is Microsoft’s behaviour and not something ITSailor can reverse. Nothing under this permission runs without a second named person approving the specific action first. The engine refuses when the approver is the requester, and refuses outright against any account you list as protected. | Broader than read | The action, the target identifier, the SKU, the approver and the timestamp. | The engine records the action, who requested it, who approved it, the target identifier and the timestamp, in a hash-chained evidence chain. It does not copy mailbox content, files, or directory records into ITSailor systems. |
How long it is kept
Every request, policy decision, approval and execution is written to a hash-chained evidence chain held for the life of your engagement, so an auditor can be shown what happened and check it themselves. The chain records identifiers, decisions and timestamps; it does not hold mailbox content, files or directory records.
How to revoke
A tenant administrator can remove the grant at any time in the Microsoft Entra admin center, under Enterprise applications, by deleting the HELMGATE application. Revoking it stops every action at once: the engine cannot obtain a token, the connector reports itself unavailable, and nothing executes. This is rehearsed as a scheduled drill during a pilot, with you watching.
The paid Offboarding Evidence connector
The Offboarding Evidence subscription requests two permissions the free scan above does not: offline_access and MailboxSettings.Read. Both are still read permissions; neither can change your tenant.
The free scan above is one browser session and finishes well inside the hour a Microsoft Graph access token stays valid, so it never needs to renew one. The paid subscription reruns once a day with nobody at the console, and a token that has expired cannot renew itself: offline_access is what lets the connector refresh its own access token instead of asking your administrator to reconnect before every run.
MailboxSettings.Read is not requested by the free scan at all, which is why its own evidence pack states that mailbox forwarding and redirect rules can only be checked once this permission is granted. The paid connector requests it so a leaver's mailbox rules are read directly rather than left as a gap in the evidence.
Recipients
Every party that receives personal data from ITSailor, condensed from the Privacy Policy. Most are sub-processors, acting on documented instruction. Some are not, and their rows open by saying so. The policy is the authoritative source and is updated first when this list changes.
| Processor | Purpose | Jurisdiction |
|---|---|---|
| Stripe Payments Europe Ltd. | Our processor for executing payments, subscription charges and refunds on our instruction. Independent controller for fraud prevention, financial and security risk, AML and KYC obligations, and developing its own products | Ireland (EEA). Processing: Ireland, inside the EEA, with routing to Stripe group entities outside the EEA. Transfers: Standard Contractual Clauses (EU) 2021/914 for any routing outside the EEA; Stripe also self-certifies under the EU-US Data Privacy Framework. |
| Resend, Inc. | Transactional email delivery | United States. Processing: United States, outside the EEA. Transfers: EU-US Data Privacy Framework, with the Standard Contractual Clauses (EU) 2021/914 in place regardless. |
| Upstash, Inc. | Managed storage for newsletter and rate-limit state | United States. Processing: United States, outside the EEA. Transfers: Data processing addendum and the Standard Contractual Clauses (EU) 2021/914. No framework listing is claimed. |
| Hetzner Online GmbH | Production server hosting and backups | Germany (EEA). Processing: Falkenstein, Germany, inside the EEA. Transfers: None needed. The processing does not leave the EEA. |
| Cloudflare, Inc. | DNS, CDN, and Zero Trust Tunnel | United States. Processing: A global edge network outside the EEA; EU traffic is served from EU edge nodes. Transfers: EU-US Data Privacy Framework, with the Standard Contractual Clauses (EU) 2021/914 in place regardless. |
| Vercel, Inc. | Frontend hosting and edge logs | United States. Processing: Serverless functions execute in Frankfurt, Germany (fra1), inside the EEA. Static assets and request logs are served from a global edge network outside the EEA. Transfers: EU-US Data Privacy Framework, with the Standard Contractual Clauses (EU) 2021/914 in place regardless. |
| Plausible Insights OÜ | Cookie-free website and conversion analytics | Estonia (EEA). Processing: Inside the EEA. Transfers: None needed. The processing does not leave the EEA. |
| GitHub, Inc. | Private repository hosting and tool authentication | United States. Processing: United States, outside the EEA. Transfers: EU-US Data Privacy Framework, self-certified under the Microsoft umbrella, with the Standard Contractual Clauses (EU) 2021/914 in place regardless. |
| Anthropic (Claude API) | SaaS Auditor briefs from aggregate figures, contract-document extraction, internal Ops Log drafting | Not verified. This row names the service rather than a contracting entity; ask us and we will tell you which entity we contract with. Processing: Outside the EEA. Transfers: Standard Contractual Clauses (EU) 2021/914 alone. No framework listing is claimed, because none has been verified. |
| OpenAI (API) | Free-tool diagnostic report and the Tenant Monitor report | Not verified. This row names the service rather than a contracting entity; ask us and we will tell you which entity we contract with. Processing: Outside the EEA. Transfers: Standard Contractual Clauses (EU) 2021/914 alone. No framework listing is claimed, because none has been verified. |
| Cal.com | Scheduling for discovery calls, demos and paid workshop sessions | Not verified. This row names the service rather than a contracting entity; ask us and we will tell you which entity we contract with. Processing: Outside the EEA. Transfers: Standard Contractual Clauses (EU) 2021/914 alone. No framework listing is claimed, because none has been verified. |
| DocRaptor | Rendering purchased eBook PDFs, which carry the buyer email in the licence line | Not verified. This row names the service rather than a contracting entity; ask us and we will tell you which entity we contract with. Processing: Outside the EEA. Transfers: Standard Contractual Clauses (EU) 2021/914 alone. No framework listing is claimed, because none has been verified. |
| Google LLC (reCAPTCHA) | Not our sub-processor. The reCAPTCHA script loads into your browser on our contact and scan-request forms, so your browser sends device, network and interaction data to Google directly. We are a controller for that collection and transmission (CJEU C-40/17 Fashion ID); Google determines what it does with the data afterwards | United States. Processing: Outside the EEA. The data goes from your browser to Google and does not pass through our systems. Transfers: No transfer instrument of ours covers this path, and we claim none. Whether one is required is with counsel. |
| Microsoft Ireland Operations Limited | Not our sub-processor. Licensor and platform operator for Microsoft 365 bought through us via Pax8. Microsoft processes your tenant content as YOUR processor under its Data Protection Addendum, on your instructions and not ours | Ireland (EEA). Processing: Your own tenant, under the agreement you hold with Microsoft. The contracting entity is inside the EEA. Transfers: Not ours to state. Microsoft processes tenant content on your instruction under its Data Protection Addendum with you, so your agreement governs that transfer and not ours. |
| Pax8 Inc. | Not our sub-processor. Wholesale supplier and provisioning rail for Microsoft licensing. Pax8 receives your order data as an independent controller in its own right to fulfil the wholesale order; your tenant data does not reach it | Netherlands (EEA), for the EU wholesale operation. Processing: Netherlands, inside the EEA. Transfers: Not ours to state. Pax8 receives the order data as an independent controller, so its own position governs that processing. |
Azure, and why it is not in the table above
SEAWALL Azure requests no Microsoft Graph permissions. Not a narrow set: none. Access to an Azure subscription does not come from a consented API permission at all, it comes from an RBAC role assignment you make yourself in your own portal and can delete in one click, without telling us.
The role is the built-in Reader, which grants */read and nothing else.
We deliberately do not ask for Cost Management Reader, despite the name suggesting it is the read-only one for cost. Its action list contains the wildcard Microsoft.Support/*, which permits support-ticket creation. Reading a permission by its name rather than by its action list is a mistake this practice has made once before and does not intend to repeat.
Sufficiency was settled by running every read path the collector needs as a principal holding Reader and nothing else, on 2026-08-15: budgets, Advisor, policy assignments, resources, Resource Graph and Cost Management all answered. SEAWALL never writes to your Azure, in any tier.
Documents
A Data Processing Agreement (DPA) covering this processing is available on request during scoping. The controller-to-processor terms follow the requirements of GDPR Article 28.