Knowledge base / Helpdesk / Security & data
Security
Security is enforced by SharePoint and Microsoft 365, not just by hiding buttons. The app configures SharePoint permissions on its own lists, and requester privacy makes SharePoint itself limit requesters to their own items.
Your tenant, your data
All helpdesk data lives in your SharePoint site and moves only through SharePoint and your Power Automate flows. There is no analytics, tracking or vendor cloud. Exports are created in the browser.
Least privilege
No Microsoft Graph permissions at all. The app always acts as the signed-in person and can never exceed their own rights.
Permissions the app sets up
Apply security creates the Helpdesk Admins and Helpdesk Agents groups and a Helpdesk Requester permission level (contribute without delete), and gives each list exactly the access it needs.
Requester privacy
When switched on, requesters read and edit only their own tickets, public replies, notifications, surveys and archive rows. Internal notes stay with agents. Approvers get the single ticket waiting for them.
Hidden and out of the way
All helpdesk lists are hidden from Site contents and navigation; people work through the helpdesk. Owners can still open lists by URL.
Tamper-resistant by design
Safe HTML cleaning on all formatted text, unguessable 20-character links, validated email queueing (requester rows may only reach their ticket's people), and a full audit trail with SharePoint version history.
Who can do what with each list
After Apply security:
| Lists | Admins | Agents | Requesters |
|---|---|---|---|
| Configuration (settings, statuses, priorities, categories, teams, rules, custom fields, holidays) | Edit | Read | Read |
| Agent content (knowledge base, canned responses, announcements, agents) | Edit | Contribute | Read |
| Ticket data (tickets, replies, history, notifications, surveys, feedback) | Edit | Contribute | Add and edit, no delete |
| Agent-only data (time entries, reminders, saved views, setup log) | Edit | Contribute | No access |
Agents may edit only three Settings rows (the background-work locks), so one agent's browser does the shared work while configuration stays read-only for them.