brillientaKnowledge base

Knowledge base / Employee Directory / Security & data

Security

3 min read · Employee Directory 1.5.0

Security is enforced by SharePoint and Microsoft 365, not just by hiding buttons. The app configures SharePoint permissions on its own lists, and trusts only identity information that SharePoint records itself.

Your tenant, your data

All directory data lives in your SharePoint site and moves only through SharePoint and Microsoft Graph. There is no analytics, tracking or vendor cloud. The only other download is Microsoft's Fluent UI icon font, from Microsoft's own content network.

Least privilege

Four delegated Microsoft Graph permissions only. The app always acts as the signed-in person and can never exceed their own rights.

Permissions the app sets up

Apply security creates the Directory Admins and Directory HR groups and a "Directory Contributor" permission level (contribute without delete), and gives each list exactly the access it needs.

Item-level security

Where a list holds personal entries, SharePoint lets people change only their own. Change requests, favourites and read status are visible only to their owner (and HR where relevant).

Hidden and out of search

All directory lists are hidden from Site contents. Lists with private or operational data are excluded from SharePoint search.

Tamper-resistant by design

Profile ownership, the kudos sender and change request decisions are checked against SharePoint's own "created by" and "modified by" records, never against values the browser sends.

Who can do what with each list

After Apply security:

ListHoldsEmployeesHRAdminsIn search
ED_SettingsConfiguration, access lists, licenceReadReadEditYes
ED_EmployeesPeople records from the syncReadEditEditYes
ED_DepartmentsDepartment detailsReadReadEditYes
ED_PhotosProfile photosReadEditEditYes
ED_ProfilesSelf-service profile detailsRead all · edit ownEditEditYes
ED_KudosRecognitionRead all · edit ownEdit (moderate)EditYes
ED_ChangeRequestsRequests to HRRead and edit ownEdit allEdit allNo
ED_FavoritesStarred colleaguesOwn onlyEditEditNo
ED_NoticeReadsWhich notifications were readOwn onlyEditEditNo
ED_NotificationsIn-app notificationsRead · add · edit ownEditEditNo
ED_SyncLog, ED_Activity, ED_ReminderLogSync history, audit trail, reminder logNo accessEditEditNo

"Employees" means Everyone except external users, or the site's Members and Visitors, as chosen when security is applied. Site owners always keep full control. Directory users cannot delete items.

Further protections

  • Separation of duties. Nobody can review their own change request, and a self-made "approval" is treated as still pending.
  • Field privacy. Fields hidden from a viewer are removed from the data before any screen uses it.
  • Safe images. Logos, banners and photos must be image data or HTTPS addresses, and anything that could break out into page code is rejected. SVG logos are shown only as images, never as page markup.
  • Safe templates. Placeholder values in emails are HTML-escaped, and the template preview runs in a sandboxed frame.
  • Safe links and exports. Links in notifications can only open pages inside the directory. CSV exports neutralise values that spreadsheets could run as formulas.
  • Safe sync. Leavers are deactivated, never deleted. Mass deactivations are held back, and a lock prevents two syncs running at once.
  • Accountability. Setup, upgrades, security changes, settings changes, profile edits and approvals are written to the audit log. Every sync and every reminder is logged.
Apply security on every directory siteUntil security is applied, the lists inherit the site's permissions, so anyone who can edit the site could change directory settings. Setup applies security by default when a site owner installs. Admin › Schema & security shows whether it has been applied and can re-apply it at any time.
This article is about Brillienta Employee Directory.See the productView plansBook a demo
Still need help?Our team answers product questions by email, and we can walk you through it on a call.
Open in the full guideContact support