You have a report showing guest permissions on a SharePoint site. Your audit search returns no matching sharing event. Check what each source covers and when it was collected before drawing a conclusion about access.
For a SharePoint permissions audit, write down the question first. Do you need to establish reported access at a particular time, investigate how someone shared a resource, or document whether access still has a business reason? Each question needs different evidence. Combining the answers takes care, especially when the dates do not line up.
Choose evidence for the question
| Evidence | Question answered | Evidence and time scope | Limits and next verification |
|---|---|---|---|
| Permission snapshot | What permission state did this report capture? | A dated view of reported permissions within the report's coverage. | Check lag, exclusions and export scope. Verify the relevant access before making a current-state decision. |
| Sharing-event history | What sharing activity was recorded? | Events returned for the chosen search period and criteria. | Read the event type and context. A past event does not establish that access persists today. |
| Human review record | What did the reviewer decide, and why? | Your record of the evidence considered and decision made at the review time. | A decision is not proof that someone executed a change. Record unresolved questions and the next check. |
A SharePoint Online permissions audit can use all three. Keep their conclusions separate in the review record so another person can follow how you reached the decision.
Check the report's prerequisites and coverage
Microsoft's site-permissions snapshot requires SharePoint Advanced Management (SAM). Confirm an eligible Microsoft 365 or Office 365 base subscription and the applicable SAM entitlement. Microsoft's prerequisites describe qualifying Copilot access and SAM add-on routes. The administrator also needs an appropriate role, such as SharePoint Administrator or SharePoint Advanced Management Administrator. Owning a Microsoft 365 subscription alone does not establish availability. Check the current SAM prerequisites for your tenant.
The snapshot can lag behind changes. Record its stated reporting date, generation details and your collection time separately. Microsoft excludes archived sites and sites locked with NoAccess. The portal's ranked site view is a subset; the downloadable CSV covers a wider set of sites within the report's limits. Its guest-permission count is not a named guest list. Use the snapshot documentation to interpret the fields before treating an omitted site or a summary total as a conclusion.
Read the sharing event before interpreting it
Microsoft distinguishes several actions in its sharing audit guidance:
SharingInvitationCreatedrecords an invitation that does not yet grant access.SharingInvitationAcceptedrecords acceptance and access being assigned through that invitation flow.- Sharing with someone who already has a guest account can assign permissions immediately and produce
AddedToGroupandSharingSetevents. Do not assume every guest must accept a new invitation. AnonymousLinkCreatedrecords creation of an Anyone link.AnonymousLinkUsedrecords its use. Creating a link does not demonstrate that somebody opened the resource.SecureLinkCreatedrecords a specific-people link.AddedToSecureLinkidentifies a person added to it; those records should not be treated as evidence of use.
Use the event name to identify the recorded action. Read the resource, actor, target and time in context, then verify current permissions separately.
Treat missing events as an open question
Before relying on a search, confirm audit ingestion is enabled and the search has completed. Search requires the Audit Logs or View-Only Audit Logs role. Event availability can lag, and Microsoft does not guarantee a fixed ingestion time. Check the UTC date range, exact activities and other filters against the question. Follow Microsoft's audit search guidance.
Also check the administrator's visibility. Administrative-unit assignments can restrict what the reviewer can search. A search made with restricted visibility cannot establish an organization-wide absence of activity.
Keep three time limits distinct: the period requested by a search, how long its completed search job remains available, and retention of the underlying audit events. The first two are search mechanics; event retention depends on applicable licensing and policies. See audit search and the Audit overview. SharePoint content retention concerns retaining or deleting content, so it should not be used as a promise about available sharing history.
When no matching event appears, record that result and its limits. Do not convert it into "no access" or invent an explanation for the gap.
A synthetic review of Site A
This example is synthetic. Site A, Guest A and Reviewer A are invented labels; the record below is an illustrative working record, not a Microsoft report or universal control requirement.
At T1, a snapshot reports guest permissions on Site A. Reviewer A collects it later, at T2, alongside a completed sharing-event search covering Window B, a different period. That search has no matching result. Guest A is a person the reviewer has been asked to investigate, but the snapshot's aggregate count does not identify them.
The supported conclusion is limited: the snapshot reported guest permissions at T1; this search has not established their historical origin. Guest A's current access and the reason for any continuing access still need verification.
| Review field | Illustrative entry |
|---|---|
| Scope | Site A within Organization A; Guest A is the person under review. |
| Question | What guest access needs explanation, and can Guest A currently access the relevant resource? |
| Source reference | Snapshot A and completed sharing search B, retained with their settings. |
| Report or event period | Snapshot point T1; event search Window B. These periods differ. |
| Collection time | T2 for both evidence items; source dates retained separately. |
| Known gaps | Historical origin unestablished; aggregate count does not identify Guest A; current access unverified. |
| Reviewer | Reviewer A. |
| Decision and status | Open, pending current verification and a business-owner decision. No removal recorded. |
| Rationale | The available evidence does not support closing the question or attributing access to Guest A. |
| Next check | Verify Guest A's current access through an authorized review, check search coverage, and ask the responsible owner to decide any required action. |
If the next check confirms access, add the evidence and decision. If it leaves a gap, keep that gap visible. Do not label a proposed action as completed remediation.
Direct-team and MSP reviews have different owners
For an Australian IT or security team reviewing its own organization, start with the site and the business question that prompted the review. Ask the responsible business owner why access is needed. Set a follow-up date that fits your organization's policy and the unresolved issue. This example does not prescribe an Australian legal requirement or review frequency.
For an MSP or adviser, keep one client scope and approval owner per record. Agree who supplies evidence, who evaluates it and who can authorize action. A completed review for Client A says nothing about Client B's access. If a client's source is unavailable, name that gap in its report without holding up an independent, adequately evidenced client review.
Where GovernSafe fits
GovernSafe's Microsoft 365 governance guide describes supported tenant data, client-scoped analytics, findings and recommendations with evidence for human review. Coverage depends on the configured connector, data and workflow. Discuss the evidence your team needs and verify that the supported workflow fits that scope. This is not a promise of exhaustive SharePoint permissions coverage or automatic revocation.
Source notes
Sources checked on 8 September 2026. Documentation can change; recheck the relevant source before conducting a review. These sources explain Microsoft behavior and GovernSafe's public scope. The synthetic example reports no customer assessment or tenant action.
- Microsoft site-permissions snapshot report, updated 16 July 2026.
- SharePoint Advanced Management prerequisites, updated 18 August 2026.
- Use sharing auditing in the audit log, updated 24 June 2026.
- Search the audit log, updated 19 June 2026.
- Administrative units in Microsoft Purview, updated 4 June 2026.
- Microsoft Purview auditing solutions, updated 18 May 2026.
- Microsoft Purview retention policies and labels, updated 22 July 2026.
- GovernSafe Microsoft 365 governance guide, accessed 8 September 2026.



