Every access ticket has a wide answer that closes it quickly and a narrow answer
that closes it correctly. The wide answer is almost always still there two years
later, and nobody remembers who asked for it.
The rule
Grant the narrowest scope, at the lowest permission level, for the
shortest time, to a group rather than a person, and record why.
Narrowest scope
Somebody who needs one folder should be given that folder, not the library, and
certainly not the site. Scope creep in the grant is how a single request becomes a
permanent exposure.
Lowest level
Read before Edit; Edit before Full Control. In Exchange, Send on Behalf is
usually what someone actually needs when they ask for Send As — it preserves
attribution, which protects both parties.
Shortest time
Cover work, secondments and audits end. Access granted for them rarely does. If the
platform supports an expiring grant or access review, use it. If it does not, put a
review date in the ticket and mean it.
To a group, not a person
Group-based grants survive reorganisations, leavers, and the next person who breaks
permission inheritance. Eleven individual grants do not, and they are invisible when
someone later asks "who can see this?"
Record why
"Requested by the user" is not a justification. "Requested by R. Osei, approved by
the data owner, for the Northgate bid until 2026-09-30" is. When someone reviews
access next year, that sentence is the difference between a confident removal and an
indefinite extension "just in case".
Shortcuts that are worse than the ticket
| Shortcut | What it actually does |
|---|---|
| Granting Everyone except external users | Makes the content org-wide, permanently, invisibly |
| Making the requester a site collection admin | Grants far more than the request, with no expiry |
| Adding a domain to the external collaboration allow list | Opens the tenant to every user at that domain |
| Excluding a user from a Conditional Access policy | Removes a security control to close a ticket |
| Anonymous "anyone with the link" sharing | Puts the content on the open internet if the link leaks |
| Granting Full Access to a mailbox for a one-off | Standing access to somebody's correspondence |
Each of these is a governance change with an owner. If one is genuinely required,
escalate it as a change request with a justification and an expiry — do not make it
yourself to clear a queue.
When you have to say no
Say what you cannot do, why, who decides, and what you have raised on their behalf.
A user with a deadline can work with "it needs the identity team's approval and I've
raised it with the justification, expect an answer today." They cannot work with
"it's with another team."
Related
- SharePoint permission inheritance
- Guest access and external collaboration
- Conditional Access basics