See who has access to a SharePoint document library.
365Canopy is a Windows desktop permissions audit tool from NVZLAB. Explore a site, its library, folders and optionally files, then follow permission grants through classic SharePoint groups and Microsoft Entra groups to the observed people.
Status: 0.1.0-alpha.8 - development preview. This is observed permission evidence, with explicit coverage gaps, rather than a complete effective-access evaluator.
- Administrator sign-in through Microsoft's interactive authentication; no client secret or certificate.
- Recursive folder inventory and optional file-level permission review, off by default.
- Unique/inherited permission sources, classic SharePoint groups, Entra members/owners and available usernames.
- Separate Audit, Results, Coverage and Report pages; automatic Results navigation on completion.
- Offline HTML permissions tree with expandable groups and people, plus CSV and JSON exports.
- Explicitly saved, named connections encrypted for the current Windows account.
- System, Light and Dark appearance, with Windows high-contrast and animation preferences respected.
Requires Windows x64, an HTTPS commercial SharePoint site collection, and an administrator account with sufficient access to the target content. Admin directory roles alone do not ensure that all target content can be read.
When a GitHub prerelease is available, download its setup executable and matching SHA-256 file. The installer includes .NET and PowerShell. Choose Set up audit dependency once to download pinned PnP.PowerShell directly from PowerShell Gallery after reviewing its component terms. Preview executables are unsigned. See desktop instructions.
- Configure your own single-tenant native public-client registration with localhost redirect.
- Review and grant the delegated permissions described in tenant setup.
- Enter your site URL, tenant GUID, public client GUID and library name in Audit.
- Select the scope and run the administrator audit. Microsoft handles sign-in and MFA.
- Review Results and Coverage before exporting or sharing the report.
Tested consent includes SharePoint AllSites.FullControl, and Graph GroupMember.Read.All, User.Read and User.ReadBasic.All. Full Control is write-capable even though the collector uses read operations. Canopy does not create app registrations or grant consent during audits. The separate development registration helper starts with read scopes and is not a complete production onboarding wizard. Never paste passwords, MFA codes or tokens into this project.
Fields start blank. Named site profiles are stored at %LOCALAPPDATA%/365Canopy/sites.protected,
protected by Windows DPAPI for the current user. They contain connection metadata and options,
not credentials, tokens or audit results. Profiles are loaded explicitly and do not start an audit.
Other processes running as the same Windows account are outside that protection boundary.
Audit evidence remains in application memory until explicit export. Microsoft/browser sign-in state can persist separately. Exports contain tenant identities and permissions: keep them private.
File contents, versions, sharing-link details and policy-aware effective access are outside this preview. Hidden membership, inaccessible resources and service/API omissions can leave gaps. File discovery stops at 40,000 returned items; incomplete collection remains partial or unknown. A missing grant or person does not establish absence of access. See coverage details.
Use Windows, PowerShell 7, the .NET 10 SDK specified by global.json, and Inno Setup 6.
Use an extracted official Windows x64 PowerShell 7.6.6 distribution as the bundled runtime.
# Downloads pinned modules into ignored work/modules; no global installation.
./Setup-Checkpoint.ps1 -DesktopOnly
./Start-365Canopy.ps1 -Check
dotnet run --project tests/Canopy.ReportChecks
./scripts/Build-Desktop.ps1 -PowerShellRuntime 'C:/Tools/PowerShell-7.6.6'Override -Dotnet, -InnoCompiler when necessary. The build has no dependency
on a sibling Lantern checkout. Outputs stay under ignored artifacts/; source publication uses
an explicit allowlist through scripts/Prepare-Publication.ps1.
Security and privacy reporting · Alpha.7 release notes · Third-party notices · MIT license
Development checks include synthetic traversal, token/account binding, membership cycles, unknown inheritance, export escaping and read-operation regression guards. The app has passed live development audits and user testing; clean-machine installation and publisher signing remain outstanding. The dependency review checked 92 identified runtime/module package-version pairs against the official NuGet advisory feed on 2 October 2026 and found no matching known advisories. Nightly package identification and unreported vulnerabilities remain limitations. Historical checkpoint notes describe an earlier, incomplete authentication spike. The current desktop uses the delegated collector.
Inspired by 365Lantern. Broader Microsoft 365 visibility and future integration remain design directions.
The dependency review records vendor-hash verification,
known-advisory checks and component license boundaries. Alpha.8 excludes PnP and its
Microsoft components from the installer; dependency setup obtains them directly from the publisher.
The downloaded module is kept at %LOCALAPPDATA%/365Canopy/modules/PnP.PowerShell/3.4.1
and reused until that folder is removed. Uninstall leaves this download and saved profiles in place.

