UV Permissions Explorer documentation
Overview
Effective access paths, unique permission scopes and principal search. Unique permissions are a signal, not automatically a risk.
For: Admins answering who has access, and why.
Features
Effective access
Why a principal can open a site or item.
Unique scopes
Inventory, not auto-remediation.
Requirements
- SharePoint Online (Microsoft 365)
- Tenant app catalog
- SPFx 1.18+
- Node 18 LTS / 22 LTS for custom builds
- License key from Account → License keys
Installation
- After purchase or trial, download the signed uv-permissions-explorer.sppkg package from Account → Files / UV Apps catalog.
- Upload the package to the tenant app catalog (SharePoint admin → More features → Apps).
- Enable the app for the whole tenant or selected site collections.
- If Entra asks for consent, approve only the permissions listed on the product page.
- Open a site and add the web part (or open the full-page app). The app checks for a purchased license or an active trial for this tenant.
- Sites.Read.All, Group.Read.All. Tenant-wide scan needs a backend job.
How to use
- Open the page signed in with a work account from this Microsoft 365 tenant.
- The app asks the license server whether this tenant has a purchase or an active trial — no key is required.
- If nothing is found, paid features stay locked. Clock, Banner, Quick Links and Profile Card still run in Free mode.
- A product key from Account → License keys is only a fallback when silent activation fails.
- Search a person or site.
- Open the access path before changing anything.
Configuration
- Scope
Troubleshooting
- Incomplete path: Graph group expansion failed. Show the failure, do not invent members.
Licensing
The app checks this tenant for a purchased license or an active trial and unlocks automatically. Sign in with a work mailbox on a verified domain of the Microsoft 365 tenant. See the licensing guide.
Microsoft Graph
- Sites.Read.All (Delegated) — Read SharePoint permission assignments the signed-in admin can already see.
- Group.Read.All (Delegated) — Resolve Microsoft 365 and Entra group membership where Graph allows it.