Over time, SharePoint document libraries become messy as staff share links freely and break permissions without realising the long-term impact.
The result is permission sprawl - files with unique permissions, anonymous or external sharing links, and content accessible to people who should no longer have access.
What this feature does
Report mode
- Scan multiple document libraries in a SharePoint site
- Detect all shared links
- Identify unique permissions
- See who content is shared with
- Export a clear, auditable report
Removal mode
- Remove shared links in bulk
- Remove unique permissions
- Restore inherited permissions
- Clear a backlog of stale shares in a single pass
Why this matters
Shared links are often created casually - "just for a minute" - but they frequently remain long after the original need has passed. That creates security risk, audit gaps, and compliance concerns.
ShareMaster makes it easy to see exactly what is shared, who it's shared with, and take action confidently - either by exporting a report or actively cleaning up access.
A sharing link and a unique permission are not the same thing
This trips up most clean-ups, and the video spends time on it because removing the wrong one leaves the access you were trying to close.
A sharing link is a URL with a token in it. Anyone holding that URL gets in on the terms the link was created with: an Anyone link needs no sign-in at all, an Organisation link admits any account in your tenant, and a Specific people link is tied to named recipients. Revoking the link kills that URL for everybody who has it, wherever they saved it.
A unique permission is broken inheritance: the file or folder stopped taking its permissions from the library above it and now carries its own, usually because somebody was granted access directly. Removing it restores inheritance, so the item goes back to being governed by the library rather than by a decision made once and forgotten.
Neither removal touches content. Files stay exactly where they are, and people who still have access through the library keep it. What goes is the extra access that was granted on top.
This is a clean-up, not a guard
Worth being straight about, because plenty of tools in this space imply otherwise. ShareMaster reads your tenant when you run it and stops when the run finishes. It does not sit in the background watching, there is nothing to schedule, and a link somebody creates the following morning will not be caught until you scan again.
Removing a link also does not stop the same file being shared again. Whether people can create Anyone links at all is a tenant and site sharing setting in the SharePoint admin centre, and that is where you change it. The right pairing is usually both: tighten the policy so the problem stops growing, then run this to clear what the old policy already let through.
Scan first, revoke second
Report mode is read-only, and it is the sane way to start: scan a site, export the result, and look at what a filter would actually catch before anything is revoked. The filters in the video exist for that reason. Expired links only, or Anyone links only, turns "we have thousands of shares" into a list somebody can defend in a change request.
How it works
1. Select document libraries
Choose one or multiple document libraries within a SharePoint site to scan.
2. Analyse permissions and links
The app detects shared links, identifies unique permissions, and records who content is shared with and how.
3. Report or remove
Generate a report for review, or remove shared links and unique permissions in bulk to restore inherited access. The run ends there: what it found is a picture of the tenant at the moment it read it.