In most environments we’ve analysed, a significant share of mailbox permissions can’t be explained by anyone currently working there.
Each one is an audit finding. Some are active access to data by people who shouldn’t have it.
Environment analysis runs at the start of every deployment and is entirely read-only. Nothing is modified before you approve it. You get a report covering:
Most customers find this report useful on its own.
You decide what goes. Every change is logged and reversible. Once cleaned, SharedConX maintains the state: a user leaving a security group loses the permission and the Outlook mapping automatically. Orphaned permissions stop accumulating.
The change log records every permission modification with timestamp, trigger, and resulting state. When an auditor asks how access to a given mailbox is controlled, the answer is a group membership list and a complete history.