Knowledge base / Intranet Builder / How it works
How it works
Six SharePoint Framework packages provide the web parts and extensions. A PowerShell provisioning engine creates what each site needs: lists and libraries, pages, navigation, extension registrations, permissions and settings. Administration pages on a restricted site design, configure and check every intranet site.
Administration site
Setup Center, Configuration Manager and Health Dashboard, with provisioning history and approved templates.
Home, department, HR, knowledge sites
39 web parts and 9 extensions reading the site's lists with the reader's own permissions.
Provisioning engine
PowerShell IntranetBuilder module: validates, locks, inspects, plans, applies and verifies. Nine scripts for administrator-run installation; the same engine runs in the Azure worker for automated mode.
Key ideas
- Packages only make components available. Deploying the six packages to the tenant app catalog never creates lists or pages. The provisioning engine creates site resources from the configuration.
- Modules are the unit of installation. Each of the 47 modules names its package and components, its lists (created or mapped), its dependencies, its Graph permissions and its guidance.
core-configis required by every module. - Templates are complete site designs. Five templates (administration, corporate home, department hub, HR portal, knowledge hub) define the site role, modules, pages, navigation and settings defaults.
- Delegated access only. Components always act as the person using them, through SharePoint REST and delegated Microsoft Graph permissions approved in API access.
- Presentation is not authorization. Audience targeting and hidden navigation only change what is shown. SharePoint permissions decide what can be opened.
Microsoft Graph permissions
The packages request only the Graph permissions their modules need. A SharePoint administrator approves them once, in the SharePoint admin center under Advanced › API access.
| Package | Requests | Needed by |
|---|---|---|
| Core | User.Read | Audience targeting of content |
| Extensions | User.Read | Audience targeting of navigation links |
| People | User.Read, User.Read.All | Employee directory, organization chart |
| Integrations | User.Read, Tasks.Read | My tasks (To Do / Planner) |
| Administration | user_impersonation on the Provisioning API | Automated installation only |
Web parts whose permission is not approved show that they are not available yet (IB3001); nothing else is affected.