Priya manages SharePoint for a 300-person speciality pharmaceutical company. Here is how she delivered a complete access control audit across fourteen regulated document libraries in two days, with a report the QA director could hand directly to the external auditors.
| Industry | Pharmaceutical (speciality biotech, 300 employees) |
|---|---|
| SharePoint admin team | 2 administrators |
| Challenge | Document access sprawl across 14 regulated libraries with no current auditable record |
| Tools used | Report Master, Explore Master |
| Time to resolution | 2 days (versus an estimated 2 weeks manually) |
| Key outcome | Audit-ready permissions matrix delivered to QA director before external review |
The challenge: documented access control across regulated document stores
Pharmaceutical companies using SharePoint Online for document management operate under GxP obligations that require them to demonstrate, at any point an auditor asks, exactly who has access to which controlled documents. Standard operating procedures, validation protocols, batch records, and quality agreements live in dedicated libraries. Access to those libraries should map directly to job role and departmental responsibility.
In practice, SharePoint permissions drift. A validation engineer gets site member access during a project and retains it after the project closes. A departing vendor representative never gets removed from a library. New libraries accumulate unique permission assignments that nobody documents - and each of these patterns compounds silently over months. Over two to three years, the gap between documented access and actual access widens in ways that are difficult to see without deliberately auditing it.
Priya's company faced this problem on a defined deadline: an external GxP audit was scheduled six weeks out. The QA director needed a full access control report across all regulated document libraries - who had access, at what permission level, whether via direct grant or group membership. The company had never run a permissions audit across all its SharePoint document libraries. Doing it manually, library by library, would take the team two weeks and still leave gaps if any library had unique permissions on individual files.
Two weeks was time the team did not have. The QA director needed the report within four days to allow a review cycle before submitting it as supporting evidence.
The approach: structured audit with Report Master
Priya had used Report Master for storage reports and version counts. She had not previously used the permissions matrix export. The workflow was:
- Connect to the tenant. Report Master connects to SharePoint Online using existing admin credentials. No additional configuration is required for a permissions audit.
- Select the libraries in scope. The fourteen regulated document libraries spanned four site collections. Priya selected all fourteen by site collection and ran the permissions export across all of them in a single job, rather than navigating to each library individually in the SharePoint admin center.
- Export the permissions matrix. The Excel output listed every user, group, and security group with access to each library, their permission level, whether access was direct or group-inherited, and the scope (site, library, or item level). Where unique permissions existed on individual files, those appeared in the report too, separated from the library-level grants.
- Review for anomalies. The report surfaced eight accounts with library access that QA could not map to a current role or active contractor relationship. Those accounts were removed before the audit report was finalised.
- Run the version count report. The QA director also wanted to confirm that version history on critical SOPs was intact. A second Report Master export returned version counts per document. Priya used Explore Master to inspect the version metadata on a sample of flagged documents, confirming that version records showed the expected edit history.
The two exports, combined with the remediation notes for the eight removed accounts, formed the complete audit package. The QA director signed off on it within one working day of receiving it, with enough time remaining for a review cycle before the external audit date.
"We expected this to take two weeks. We had a complete, reviewable permissions record in two days. The auditors asked for the report on day one of the site visit and we handed it over without any scrambling." IT Systems Administrator, pharmaceutical company
The outcome: a repeatable process, not a one-time fix
The audit resolved the immediate compliance gap. The larger gain was a documented process that Priya's team can now run on a quarterly schedule, aligned to the company's access review policy, without requiring two weeks of manual effort each time.
GxP document control requirements do not specify how access control audits must be conducted; they require that the evidence is available and defensible. A permissions matrix exported from a purpose-built audit tool, showing the exact state of access on a specific date, meets that standard. The eight accounts that were removed before the audit were a controlled, documented remediation. Had the same gap been discovered by the auditors rather than by the team, the classification and remediation effort would have been significantly more complex.
For regulated industries, the value of a regular SharePoint permissions audit is not just compliance risk reduction. It is the difference between demonstrating that access control is managed continuously and demonstrating that it gets checked only when an audit is imminent. Auditors are experienced at distinguishing between the two.
For the step-by-step process, see how to audit SharePoint permissions and how to export SharePoint permissions to Excel. Both guides cover the Report Master workflow in detail.
Frequently Asked Questions
Can ShareMaster produce a permissions report suitable for a regulatory audit?
Yes. Report Master exports a full permissions matrix to Excel, showing every user and group with access to a site collection or specific libraries, along with their permission level and whether access was granted directly or via a group. The Excel output can be reviewed, annotated, and submitted as supporting evidence for a regulatory or internal audit.
Does the Report Master permissions export include external users?
Yes. The permissions matrix includes external guest accounts alongside internal users and security groups. For pharmaceutical document control purposes, this captures third-party CRO or vendor access alongside internal team members in a single, unified report.
What SharePoint permission details appear in a Report Master export?
The permissions export includes each principal (user, group, or security group), their permission level, whether they have direct access or group-inherited access, the scope of that access (site, list, or item level), and the account type (internal or external). Version count data for each document can be added from a separate report to complete the document lifecycle picture.