Knowledge base / TaskManager / Security & data
Security
Apply security (setup, or Admin → System health & access; re-runnable; needs a site owner) creates the groups, a TaskManager Requester permission level (contribute without delete), and breaks inheritance on the lists.
Who can do what with each list
After Apply security:
| Lists | Admins | Managers | Members | Guests |
|---|---|---|---|---|
| Configuration (settings, statuses, holidays…) | Edit | Read | Read | Read |
| Projects, templates, announcements | Edit | Edit | Read | Read |
| Tasks, comments, history, notifications, outbox | Edit | Edit | Add & edit | Own only |
| Time, views, reminders, queue, devices, directory, logs | Edit | Edit | Members only | — |
| Members list | Edit | Read | Own availability | — |
Own only = guests reach only their own items (and only with guest privacy switched on for full item-level enforcement).
Further protections
- Guest privacy. Without it, list permissions are list-level: a guest with REST skills could read other tasks. Switch on guest privacy (Enterprise) when tasks are confidential — SharePoint itself then shows guests only their own items.
- Flow authorisation. The email flow trusts members but lets guests queue mail only about their own tasks to that task's people; every row is claimed once and duplicates rejected.
- Secrets stay in flows. The Graph client secret and Azure OpenAI key are typed when the package is downloaded, live only in the package, and are hidden in run history. The Graph and AI flows use the premium HTTP action.
- Unguessable links, recycle-bin deletes. Task links carry unguessable keys, and deletes go to the recycle bin.
Still need help?Our team answers product questions by email, and we can walk you through it on a call.
Open in the full guideContact support