Your input shapes our product. Suggest a feature now →
  1. Home
  2. Use Cases
  3. HR Confidential Permissions Audit

SharePoint Permission Gaps: What HR Admins Miss

Sector: Professional Services  |  Team size: 380 staff  |  Tools used: Report Master, Shared Links

Three hundred and forty-two files. That was the count Karen pulled from the HR Documents library at Meridian Consulting when she realised something had gone wrong. Salary bands. Performance review templates. Disciplinary records. Resignation letters. Employment contracts. All of it sitting in a SharePoint library that every one of the firm's 380 staff could open, read, and edit.

The discovery happened by accident. Karen, Meridian's HR Manager, was reviewing system access as part of a contractor offboarding process. She had asked the IT team to confirm that the departing contractor had been removed from all SharePoint sites. While checking, the IT administrator noticed the HR Documents library was listed under the firm's main intranet site, and that its permissions column read Inherited from parent.

The intranet site had Site Members configured with Edit access for the entire organisation. The HR library, migrated to that site eighteen months earlier during an office restructure, had never had its permissions configured independently.

How the access problem developed

Meridian's intranet was a modern SharePoint communication site used for company announcements, policy documents, and team directories. All 380 employees were members of the site. When the HR library was consolidated into the intranet during the restructure, the goal had been to simplify the site architecture. The IT team moved the library, updated a few navigation links, and marked the project complete.

Nobody audited the library permissions after the move. The assumption was that the library had been private before the restructure and would remain private. In SharePoint Online, that assumption is not safe: when a library is moved to a different site, it inherits the new site's permissions unless inheritance is explicitly broken.

Over the following eighteen months, staff continued adding sensitive documents to the library. Performance review summaries for the end-of-year cycle. A salary benchmarking spreadsheet. Correspondence with legal counsel over a staff grievance. None of the people adding those documents realised the library was, in effect, open to the entire organisation.

Three former contractors also still held Site Member access because their accounts had not been removed from the intranet's membership group after their engagements ended. Those accounts had external guest access and could access the HR library from outside the organisation.

Mapping the full exposure with Report Master

Once the permissions gap was identified, Karen and the IT team needed to understand the full scope before taking any action. The first question was not how to fix the problem but who currently had access and through which permission path. Manually navigating SharePoint's permissions UI for a 342-file library spread across 22 folders would have taken most of a day.

Instead, the IT administrator used Report Master to export a full permissions matrix for the library to Excel. The report took under two minutes to generate and showed:

  • Every user and group with access to the library
  • The access level for each (Read, Contribute, Edit, or Full Control)
  • Whether each access grant came from direct assignment, group membership, or inheritance
  • The three external guest accounts and the specific intranet membership group through which they had inherited access
"The report took two minutes to run. What it showed would have taken us a week to piece together manually going folder by folder through the permissions panel." Karen, HR Manager, Meridian Consulting

The permissions matrix became the remediation checklist. Karen and the IT administrator worked through it together: deciding which accounts needed to retain access, which groups needed to be removed, and which external accounts needed immediate revocation. Having the data in Excel meant they could sort, filter, and annotate without navigating back and forth through SharePoint's UI.

The IT administrator also used ShareMaster's Shared Links audit to check whether any individual HR documents had been shared externally via anonymous or "Anyone with the link" sharing links. Two files had such links, created by a staff member who had shared them for a recruitment process and never removed the link. Both were revoked. For a walkthrough of the shared link audit process, see the SharePoint shared links audit guide.

Remediation and ongoing governance

They completed the remediation in three hours, from initial discovery to a fully locked-down library. The steps, in order:

  1. Break permission inheritance. The IT administrator navigated to the HR Documents library settings, opened the permissions panel, and broke inheritance from the intranet site. This immediately stopped the library from granting access to anyone through the parent site's membership groups.
  2. Create a dedicated security group. The IT administrator created a new Microsoft 365 security group named HR-Documents-Access in Entra ID. Karen and her two direct reports joined as members, with the group assigned Read access to the library.
  3. Assign admin access separately. The IT administrator received Contribute access to the library directly, scoped only to that library and not the broader site.
  4. Remove all other access. The IT administrator removed the Intranet Members and Intranet Owners groups from the library's permissions and revoked all three external guest accounts from the intranet site's membership.
  5. Re-run the permissions report. The IT administrator exported a second permissions matrix from Report Master immediately after the changes. The report confirmed that only the four intended accounts had access to the library, with no inherited access paths remaining.

Karen saved the second permissions report alongside the first as an audit record. The contrast between the two documents - one showing 380 people with Edit access, the other showing four with appropriate access - became a useful illustration for a broader data governance review the firm undertook in the following quarter.

Karen set a recurring reminder to re-export the permissions matrix quarterly and after any change in HR team membership. The export takes two minutes; reviewing it takes another five. That ten-minute check every three months is the governance control that prevents the same issue from recurring. For a broader look at keeping permissions current across sites, see the SharePoint permissions audit guide.

Try ShareMaster free for 14 days

Frequently Asked Questions

What permission level should an HR SharePoint document library use?

Break inheritance from the parent site immediately. Assign Read access to a dedicated security group containing only the HR staff who need to view documents. Assign Contribute or Edit access only to the person responsible for managing the library. Remove all other SharePoint groups from the library's permissions. Never rely on inherited site member permissions for a library containing salary data, performance reviews, or disciplinary records.

How often should HR teams audit SharePoint document permissions?

At a minimum: after any organisational restructure, after any staff departure from the HR team, and after any SharePoint migration or site reorganisation. Many organisations also run a scheduled quarterly permissions export for sensitive libraries as part of their information governance programme. The export takes a few minutes and provides a timestamped record of access at each review point.