Saario
How it works Vitals we check Copilot The Report Why it matters Pricing
Sign in Get your free checkup
How it works Vitals we check Copilot The Report Why it matters Pricing
Trust

Security & Permissions

Last updated: 3 August 2026  ·  Version 1.0

Contents

  1. How Saario connects
  2. Permissions we request
  3. What Saario can never do
  4. How your data is protected
  5. Data retention
  6. Revoking access
  7. Reporting a security issue
  8. Questions

Saario exists to make Microsoft 365 tenants safer — so we hold ourselves to the standard we audit others against. This page explains exactly how Saario connects to your tenant, which permissions it asks for and why, what it can never do, and how the data it reads is protected.

1. How Saario connects

Saario connects to your Microsoft 365 tenant through the Microsoft Graph API, using a Microsoft Entra ID application registration and Microsoft's standard admin-consent process. There is nothing to install: no agents on devices, no servers in your network, no changes to your infrastructure.

Connection works like this:

  • A Global Administrator signs in through Microsoft's own login page. Saario never sees, receives or stores the administrator's password — authentication happens entirely with Microsoft.
  • Microsoft displays the exact list of permissions Saario is requesting. Nothing is granted until the administrator explicitly approves it.
  • Once consent is granted, Saario appears as an enterprise application in your Microsoft Entra ID, where its access can be reviewed — or removed — at any time.

Every permission Saario requests is read-only. This is not a configuration choice that could drift over time; the application is registered without any write scopes, so Microsoft itself will not permit Saario to change anything in your tenant.

2. Permissions we request

The table below describes the Microsoft Graph application permissions Saario requests and what each one is used for. The authoritative list is always the one Microsoft shows on the consent screen, and the one visible against the Saario enterprise application in your Microsoft Entra ID.

PermissionWhy Saario needs it
Directory.Read.AllRead-only Reads users, groups, licences and admin role assignments — used to check MFA coverage, privileged accounts, stale users and guest access.
Policy.Read.AllRead-only Reads Conditional Access and authentication policies to verify that identity protections auditors expect are actually in place.
AuditLog.Read.AllRead-only Reads sign-in and directory audit logs to spot risky sign-ins, legacy authentication and unusual administrative activity.
Reports.Read.AllRead-only Reads Microsoft 365 usage and activity reports that feed trend data into your Saario Score.
SecurityEvents.Read.AllRead-only Reads security alerts and Microsoft Secure Score signals so findings can be prioritised alongside Microsoft's own telemetry.
DeviceManagementManagedDevices.Read.AllRead-only Reads Intune device inventory and compliance state — used to find unmanaged, non-compliant or out-of-date devices.
DeviceManagementConfiguration.Read.AllRead-only Reads Intune configuration and compliance policies to check device baselines against best practice.
Sites.Read.AllRead-only Reads SharePoint and OneDrive sharing settings and link metadata — used to find anonymous links, expired-owner shares and external exposure. Saario does not open or analyse the contents of your documents.
MailboxSettings.ReadRead-only Reads mailbox settings such as forwarding and inbox rules — a common exfiltration route — without reading any message content.
Organization.Read.AllRead-only Reads tenant profile and licence information so checks are matched to the capabilities your subscription actually includes.

If a future version of Saario ever requires an additional permission, Microsoft will require fresh administrator consent before it takes effect — permissions can never expand silently.

3. What Saario can never do

Read-only by design

Saario holds no write permissions of any kind. It cannot create, modify or delete anything in your tenant — no users, no policies, no mail flow rules, no files, no settings.

  • No message or document contents. Saario reads security-relevant settings and metadata. It does not read the body of emails, the contents of files, or Teams conversations.
  • No credentials. Saario never receives or stores Microsoft passwords, and holds no standing credentials for your users.
  • No changes to your tenant. Recommendations in the Saario Report are for your team to action — Saario itself changes nothing.
  • No data selling. Data read from your tenant is used solely to deliver the service to you, as set out in our Privacy Statement.

4. How your data is protected

  • Encryption in transit. All communication with the Microsoft Graph API and with your browser uses TLS.
  • Encryption at rest. Audit results, scores and reports are encrypted at rest.
  • Data minimisation. Saario stores findings, scores and the metadata needed to explain them — not a copy of your tenant.
  • Access controls. Access to customer data within Saario is restricted to authorised personnel who need it to operate and support the service, and is logged.
  • Secure development. The platform is developed and operated against the same security best practices Saario audits for.

5. Data retention

Audit findings and score history are retained for the life of your subscription so that trends can be reported over time. When a subscription ends, customer data is deleted in accordance with our Privacy Statement and clause 9 of our Terms and Conditions, save where retention is required by law.

6. Revoking access

You stay in control at all times. A Global Administrator can remove Saario's access to your tenant in minutes, without contacting us:

  • Open Microsoft Entra ID in the Azure or Entra admin portal.
  • Go to Enterprise applications and select Saario.
  • Delete the application, or remove its permission grants under Permissions.

The moment access is revoked, Microsoft stops issuing tokens to Saario and no further data can be read from your tenant.

7. Reporting a security issue

If you believe you have found a security vulnerability in Saario, we want to hear from you. Email info@saario.app with the details and we will acknowledge your report promptly, investigate, and keep you informed. We ask that you give us a reasonable opportunity to remediate before any public disclosure, and that you do not access data belonging to other customers in the course of your research.

8. Questions

If you have questions about Saario's security, permissions or data handling — including anything your IT team, auditors or insurers need answered — contact us at info@saario.app.

Saario

Search · Audit · Analyse · Report · Intelligent · Orchestration — designed for Microsoft 365 tenants, powered by the Microsoft Graph API.

Product

How it works Vitals we check Copilot Governance The Report Pricing

Company

Why it matters Contact

Trust

Security & permissions Privacy statement Terms and conditions

© 2026 Saario. Not affiliated with or endorsed by Microsoft. Microsoft, Microsoft 365, Intune, SharePoint and OneDrive are trademarks of the Microsoft group of companies.