UV Permissions Explorer documentation

Overview

Effective access paths, unique permission scopes and principal search. Unique permissions are a signal, not automatically a risk.

For: Admins answering who has access, and why.

Features

  • Effective access

    Why a principal can open a site or item.

  • Unique scopes

    Inventory, not auto-remediation.

Requirements

  • SharePoint Online (Microsoft 365)
  • Tenant app catalog
  • SPFx 1.18+
  • Node 18 LTS / 22 LTS for custom builds
  • License key from Account → License keys

Installation

  1. After purchase or trial, download the signed uv-permissions-explorer.sppkg package from Account → Files / UV Apps catalog.
  2. Upload the package to the tenant app catalog (SharePoint admin → More features → Apps).
  3. Enable the app for the whole tenant or selected site collections.
  4. If Entra asks for consent, approve only the permissions listed on the product page.
  5. Open a site and add the web part (or open the full-page app). The app checks for a purchased license or an active trial for this tenant.
  6. Sites.Read.All, Group.Read.All. Tenant-wide scan needs a backend job.

How to use

  1. Open the page signed in with a work account from this Microsoft 365 tenant.
  2. The app asks the license server whether this tenant has a purchase or an active trial — no key is required.
  3. If nothing is found, paid features stay locked. Clock, Banner, Quick Links and Profile Card still run in Free mode.
  4. A product key from Account → License keys is only a fallback when silent activation fails.
  5. Search a person or site.
  6. Open the access path before changing anything.

Configuration

  • Scope

Troubleshooting

  • Incomplete path: Graph group expansion failed. Show the failure, do not invent members.

Licensing

The app checks this tenant for a purchased license or an active trial and unlocks automatically. Sign in with a work mailbox on a verified domain of the Microsoft 365 tenant. See the licensing guide.

Microsoft Graph

  • Sites.Read.All (Delegated) — Read SharePoint permission assignments the signed-in admin can already see.
  • Group.Read.All (Delegated) — Resolve Microsoft 365 and Entra group membership where Graph allows it.

Back to product