Permissions nobody can account for

In most environments we’ve analysed, a significant share of mailbox permissions can’t be explained by anyone currently working there.

  • Accounts belonging to people who left teams months ago, never revoked
  • Duplicate entries left over from migrations
  • Permissions pointing to users that no longer exist
  • Nested groups whose effective membership nobody has traced
 

Each one is an audit finding. Some are active access to data by people who shouldn’t have it.

What the analysis shows you

Environment analysis runs at the start of every deployment and is entirely read-only. Nothing is modified before you approve it. You get a report covering:

  • Every existing permission on every shared mailbox
  • Permissions held by disabled or deleted accounts
  • Duplicate and conflicting entries
  • Effective membership of nested groups — the actual answer, not the theoretical one
  • Mailboxes with no valid permissions at all

Most customers find this report useful on its own.

Cleanup, under your control

You decide what goes. Every change is logged and reversible. Once cleaned, SharedConX maintains the state: a user leaving a security group loses the permission and the Outlook mapping automatically. Orphaned permissions stop accumulating.

For audits

The change log records every permission modification with timestamp, trigger, and resulting state. When an auditor asks how access to a given mailbox is controlled, the answer is a group membership list and a complete history.