Knowledge base / Employee Directory / Security & data
Security
Security is enforced by SharePoint and Microsoft 365, not just by hiding buttons. The app configures SharePoint permissions on its own lists, and trusts only identity information that SharePoint records itself.
Your tenant, your data
All directory data lives in your SharePoint site and moves only through SharePoint and Microsoft Graph. There is no analytics, tracking or vendor cloud. The only other download is Microsoft's Fluent UI icon font, from Microsoft's own content network.
Least privilege
Four delegated Microsoft Graph permissions only. The app always acts as the signed-in person and can never exceed their own rights.
Permissions the app sets up
Apply security creates the Directory Admins and Directory HR groups and a "Directory Contributor" permission level (contribute without delete), and gives each list exactly the access it needs.
Item-level security
Where a list holds personal entries, SharePoint lets people change only their own. Change requests, favourites and read status are visible only to their owner (and HR where relevant).
Hidden and out of search
All directory lists are hidden from Site contents. Lists with private or operational data are excluded from SharePoint search.
Tamper-resistant by design
Profile ownership, the kudos sender and change request decisions are checked against SharePoint's own "created by" and "modified by" records, never against values the browser sends.
Who can do what with each list
After Apply security:
| List | Holds | Employees | HR | Admins | In search |
|---|---|---|---|---|---|
| ED_Settings | Configuration, access lists, licence | Read | Read | Edit | Yes |
| ED_Employees | People records from the sync | Read | Edit | Edit | Yes |
| ED_Departments | Department details | Read | Read | Edit | Yes |
| ED_Photos | Profile photos | Read | Edit | Edit | Yes |
| ED_Profiles | Self-service profile details | Read all · edit own | Edit | Edit | Yes |
| ED_Kudos | Recognition | Read all · edit own | Edit (moderate) | Edit | Yes |
| ED_ChangeRequests | Requests to HR | Read and edit own | Edit all | Edit all | No |
| ED_Favorites | Starred colleagues | Own only | Edit | Edit | No |
| ED_NoticeReads | Which notifications were read | Own only | Edit | Edit | No |
| ED_Notifications | In-app notifications | Read · add · edit own | Edit | Edit | No |
| ED_SyncLog, ED_Activity, ED_ReminderLog | Sync history, audit trail, reminder log | No access | Edit | Edit | No |
"Employees" means Everyone except external users, or the site's Members and Visitors, as chosen when security is applied. Site owners always keep full control. Directory users cannot delete items.
Further protections
- Separation of duties. Nobody can review their own change request, and a self-made "approval" is treated as still pending.
- Field privacy. Fields hidden from a viewer are removed from the data before any screen uses it.
- Safe images. Logos, banners and photos must be image data or HTTPS addresses, and anything that could break out into page code is rejected. SVG logos are shown only as images, never as page markup.
- Safe templates. Placeholder values in emails are HTML-escaped, and the template preview runs in a sandboxed frame.
- Safe links and exports. Links in notifications can only open pages inside the directory. CSV exports neutralise values that spreadsheets could run as formulas.
- Safe sync. Leavers are deactivated, never deleted. Mass deactivations are held back, and a lock prevents two syncs running at once.
- Accountability. Setup, upgrades, security changes, settings changes, profile edits and approvals are written to the audit log. Every sync and every reminder is logged.