Security & Permissions
Last updated: 3 August 2026 · Version 1.0
Contents
Saario exists to make Microsoft 365 tenants safer — so we hold ourselves to the standard we audit others against. This page explains exactly how Saario connects to your tenant, which permissions it asks for and why, what it can never do, and how the data it reads is protected.
1. How Saario connects
Saario connects to your Microsoft 365 tenant through the Microsoft Graph API, using a Microsoft Entra ID application registration and Microsoft's standard admin-consent process. There is nothing to install: no agents on devices, no servers in your network, no changes to your infrastructure.
Connection works like this:
- A Global Administrator signs in through Microsoft's own login page. Saario never sees, receives or stores the administrator's password — authentication happens entirely with Microsoft.
- Microsoft displays the exact list of permissions Saario is requesting. Nothing is granted until the administrator explicitly approves it.
- Once consent is granted, Saario appears as an enterprise application in your Microsoft Entra ID, where its access can be reviewed — or removed — at any time.
Every permission Saario requests is read-only. This is not a configuration choice that could drift over time; the application is registered without any write scopes, so Microsoft itself will not permit Saario to change anything in your tenant.
2. Permissions we request
The table below describes the Microsoft Graph application permissions Saario requests and what each one is used for. The authoritative list is always the one Microsoft shows on the consent screen, and the one visible against the Saario enterprise application in your Microsoft Entra ID.
| Permission | Why Saario needs it |
|---|---|
| Directory.Read.AllRead-only | Reads users, groups, licences and admin role assignments — used to check MFA coverage, privileged accounts, stale users and guest access. |
| Policy.Read.AllRead-only | Reads Conditional Access and authentication policies to verify that identity protections auditors expect are actually in place. |
| AuditLog.Read.AllRead-only | Reads sign-in and directory audit logs to spot risky sign-ins, legacy authentication and unusual administrative activity. |
| Reports.Read.AllRead-only | Reads Microsoft 365 usage and activity reports that feed trend data into your Saario Score. |
| SecurityEvents.Read.AllRead-only | Reads security alerts and Microsoft Secure Score signals so findings can be prioritised alongside Microsoft's own telemetry. |
| DeviceManagementManagedDevices.Read.AllRead-only | Reads Intune device inventory and compliance state — used to find unmanaged, non-compliant or out-of-date devices. |
| DeviceManagementConfiguration.Read.AllRead-only | Reads Intune configuration and compliance policies to check device baselines against best practice. |
| Sites.Read.AllRead-only | Reads SharePoint and OneDrive sharing settings and link metadata — used to find anonymous links, expired-owner shares and external exposure. Saario does not open or analyse the contents of your documents. |
| MailboxSettings.ReadRead-only | Reads mailbox settings such as forwarding and inbox rules — a common exfiltration route — without reading any message content. |
| Organization.Read.AllRead-only | Reads tenant profile and licence information so checks are matched to the capabilities your subscription actually includes. |
If a future version of Saario ever requires an additional permission, Microsoft will require fresh administrator consent before it takes effect — permissions can never expand silently.
3. What Saario can never do
Read-only by design
Saario holds no write permissions of any kind. It cannot create, modify or delete anything in your tenant — no users, no policies, no mail flow rules, no files, no settings.
- No message or document contents. Saario reads security-relevant settings and metadata. It does not read the body of emails, the contents of files, or Teams conversations.
- No credentials. Saario never receives or stores Microsoft passwords, and holds no standing credentials for your users.
- No changes to your tenant. Recommendations in the Saario Report are for your team to action — Saario itself changes nothing.
- No data selling. Data read from your tenant is used solely to deliver the service to you, as set out in our Privacy Statement.
4. How your data is protected
- Encryption in transit. All communication with the Microsoft Graph API and with your browser uses TLS.
- Encryption at rest. Audit results, scores and reports are encrypted at rest.
- Data minimisation. Saario stores findings, scores and the metadata needed to explain them — not a copy of your tenant.
- Access controls. Access to customer data within Saario is restricted to authorised personnel who need it to operate and support the service, and is logged.
- Secure development. The platform is developed and operated against the same security best practices Saario audits for.
5. Data retention
Audit findings and score history are retained for the life of your subscription so that trends can be reported over time. When a subscription ends, customer data is deleted in accordance with our Privacy Statement and clause 9 of our Terms and Conditions, save where retention is required by law.
6. Revoking access
You stay in control at all times. A Global Administrator can remove Saario's access to your tenant in minutes, without contacting us:
- Open Microsoft Entra ID in the Azure or Entra admin portal.
- Go to Enterprise applications and select Saario.
- Delete the application, or remove its permission grants under Permissions.
The moment access is revoked, Microsoft stops issuing tokens to Saario and no further data can be read from your tenant.
7. Reporting a security issue
If you believe you have found a security vulnerability in Saario, we want to hear from you. Email info@saario.app with the details and we will acknowledge your report promptly, investigate, and keep you informed. We ask that you give us a reasonable opportunity to remediate before any public disclosure, and that you do not access data belonging to other customers in the course of your research.
8. Questions
If you have questions about Saario's security, permissions or data handling — including anything your IT team, auditors or insurers need answered — contact us at info@saario.app.