Knowledge base / Intranet Builder / Security & data
Security
Security is enforced by SharePoint and Microsoft 365, not just by hiding buttons. Provisioning uses either the administrator's own permissions or the worker's managed identity, limited to granted sites.
Your tenant, your data
All intranet data lives in your SharePoint sites and moves only through SharePoint and Microsoft Graph. No certificates, secrets or elevated tokens are stored in bundles, lists or settings.
Least privilege
Delegated permissions for components; the administrator's own permissions (administrator-run) or Sites.Selected (automated) for provisioning. Site creation, app catalog and hubs stay separate from routine site changes.
Server-side authorization
The provisioning API validates token issuer, audience, tenant, scope and role, derives the tenant from the verified token and authorizes every target site. UI checks only improve the experience.
Approved content only
Only validated configurations of approved templates and packages; package files are checked against SHA-256 hashes; never uploaded scripts.
Audit
Job records (requester, executor, operation, outcome), migration records and SharePoint version history of settings. Logs and telemetry leave out personal data and credentials.
Presentation is not authorization
Audience targeting and hidden navigation never protect content; SharePoint permissions do. Approvers receive a custom Intranet Approver level on moderated lists.