Find every overshared file before Copilot does.
TrueNorth Exposure Scan is a read-only check of SharePoint, OneDrive and Teams. In about ten minutes it finds public links, company-wide shares, stale guests and excess admins, then hands you a scored report with the fix for each one.
Copilot doesn't create new access. It reveals the access you already gave away.
Copilot answers from anything a user can open. Years of "share with anyone" links, company-wide folders and forgotten guests turn into answers anyone can get by asking.
- 01Links nobody remembers"Anyone" links need no sign-in. When one gets forwarded, the file is effectively public.
- 02Org-wide by defaultBudgets, HR files and acquisition notes shared with "everyone" become searchable through Copilot.
- 03Guests who never leftFormer vendors and MSPs often keep access, and sometimes admin rights, long after the contract ends.
Connect, scan, fix. No agents, no change requests.
Admin approves read-only access
A Global Admin reviews four read-only Microsoft Graph permissions and clicks Accept. That's the whole install.
The scan maps your exposure
Every site, library and shared item is checked for link type, scope and expiry, along with guests, admin roles and tenant sharing settings.
You get a scored fix list
An A–F grade, a Copilot readiness verdict, and plain-language fixes ranked by risk. Export to PDF or CSV.
Nine checks that matter most before Copilot.
Sensitive files on public links
Payroll, SSN, contract, tax and legal file names exposed through Anyone links.
Guests holding admin roles
Outside identities that can administer your tenant.
All "Anyone" links
Every unauthenticated link across SharePoint, OneDrive and Teams.
Tenant-level sharing
Whether your organization allows Anyone links at all.
Too many Global Admins
Microsoft recommends fewer than five. Most small businesses have more than that.
Links that never expire
Public links that stay live long after the project ends.
Org-wide sharing
Content every employee and Copilot can reach.
Direct external shares
Files shared with outside email addresses.
Stale guests
Guest accounts with no sign-in for 90+ days.
It can look. It can't touch.
The scanner is built so that the worst case is a list of file names. It has no write permissions, never downloads documents, and blocks every write call in code.
- Metadata only: names, paths, link scopes, and who has access
- Encrypted in transit and at rest, hosted in U.S. Azure regions
- Scan data deleted automatically after 90 days
- Revoke anytime by deleting the app in Microsoft Entra
| Sites.Read.All | Read site and file sharing metadata |
| Directory.Read.All | Read guests, admin roles and licences |
| AuditLog.Read.All | Read guest last sign-in dates |
| SharePointTenantSettings.Read.All | Read tenant sharing policy |
0 WRITE PERMISSIONS · 0 FILE DOWNLOADS
Start with one review. Keep watch for less than an hour of IT time.
Copilot Readiness Review
- Full tenant scan and scored report
- 45-minute findings walkthrough
- Prioritized fix plan
- Rescan after fixes
Monitor
- Monthly automatic rescans
- Alerts on new public links and guests
- Score trend over time
- Up to 300 users
MSP Partner
- White-label reports under your brand
- Multi-tenant onboarding links
- $2,000 wholesale Readiness Review
- You keep the client relationship
Founding partner offer: the first five MSPs get 50% off monitoring for six months, plus one free client review. Annual plans get two months free. Prices exclude applicable taxes.
What admins ask first.
Can the scanner change anything in our tenant?
No. It requests only read permissions, and the code refuses any write request. Nothing is modified, deleted or re-shared. You make the fixes, or your MSP does.
Do you read our documents?
No. We read sharing metadata, such as a file's name, location, link type and who it is shared with. We never download file contents, email or chat.
We don't use Copilot yet. Is this still useful?
Yes. Public links and stale guests are a data-leak risk with or without AI. Copilot just makes them easier to find.
How do MSPs use it?
You send each client an onboarding link, the client admin approves, and reports come out under your logo. You set the resale price and keep the relationship.
How do we remove access?
Delete the "TrueNorth Exposure Scan" enterprise application in Microsoft Entra ID. Access ends immediately, and we delete your data within 30 days.
Know what Copilot will see, before it sees it.
Book a Readiness Review, or have your MSP request partner access.