Knowledge base / TaskManager / How it works
How it works
TaskManager is a single SharePoint Framework (SPFx) web part. It runs in each user's browser, inside a SharePoint page, always acting as the signed-in person. Task data is read and written only through your site's SharePoint REST API. Scheduled work runs either in an open member page or in the Power Automate flows.
TaskManager web part
Runs in the user's browser on a SharePoint page, as the signed-in user. Covers the full browser window. No web-part properties — every option is in Admin.
SharePoint Online: your task site
Hidden lists with the prefix TM_: tasks, projects, comments, history, members, teams, statuses, reminders, notifications, outbox, directory, devices, logs and settings.
Power Automate flows (generated)
Email & email flow, reminders & digest, daily Graph sync and AI assistant — imported from packages the app builds for you, running on your connections.
Key ideas
- Delegated access only. The app always acts as the person using it. Integrations run in the browser with each person's own access — it can never read or do more than that person could.
- Background work without a server. Reminder planning, automations, risk scores and recurring catch-up run every few minutes in one member's open page (shared lock). The reminder flow covers times when nobody is online.
- Schema as code. The app knows exactly which lists and columns it needs. Setup creates them. After an upgrade, the first visit by a site owner checks them and adds anything missing. Existing data is never removed.
- Live updates. Every open page checks every few seconds which TaskManager lists changed and refreshes only what changed — everyone sees others' edits without reloading.
- Plans decide what runs. Features outside your plan are off whatever the settings say (saved choices are kept for an upgrade), and only as many members as there are seats stay active.
Microsoft Graph permissions
Most of the app works with no Graph permissions at all. Approve these only for the integrations you switch on, in the SharePoint admin center under Advanced > API access. Use Check that it works on each Admin > Integrations page.
| Permission | Used for | If it is not approved |
|---|---|---|
| User.Read.All | Syncing people from Microsoft Entra ID (Sync now and the daily flow) | Directory sync stays off; members are managed by hand |
| Device.Read.All, DeviceManagementManagedDevices.Read.All | Syncing devices from Intune / Entra ID and raising device tasks | Devices page stays off |
| Tasks.ReadWrite | Microsoft Planner two-way sync | Planner connections stay off |
| Team.ReadBasic.All, Channel.ReadBasic.All, ChannelMessage.Send | Posting project updates to Teams channels | Channel posts stay off; sharing links still works |