Users & Access
This section explains the supported group-role scope and Tenaxis administrator access. Microsoft remains the source for permissions outside that scope.
Supported access scope
Tenaxis records M365 group owner/member roles. Not every SharePoint site has an M365 group. SharePoint Owners/Members/Visitors groups, direct permissions, sharing links and unique item permissions are not a complete supported access inventory.
Users, Guests and the access matrix show cached observations. Legacy visitor records are historical and unverified; an empty cell does not prove no access. An external guest can hold an M365 group role; guest identity and visitor access are different concepts. Confirm current permissions in Microsoft before acting.
Managing group roles
For a supported group-connected site, open Sites → Members to add or remove OWNER/MEMBER roles. Inspect the operation result and readback evidence. Removing a group role does not prove all SharePoint access was removed. Assign a replacement before removing a sole owner. Tenaxis does not support visitor add/remove actions. Use SharePoint for access paths outside this scope.
The offboarding workflow handles recorded group roles and ownership; see Offboarding. Exported records explicitly distinguish group-role observations from legacy visitor records; see Reports & Audit.
Admins
Go to Admins in the left sidebar to manage who has administrative access to Tenaxis.
Important: Tenaxis admins are separate from SharePoint site owners. A Tenaxis admin can manage the governance platform (approve requests, apply policies, view all sites, etc.) but this doesn't automatically make them an owner on every SharePoint site.
Admin Roles
| Role | What they can do |
|---|---|
| Owner | Full access - everything, including billing, adding/removing other admins, and all governance features |
| Admin | Full governance access (sites, requests, policies, access reviews, etc.) but cannot manage other admins or billing |
Adding an Admin
- Go to Admins
- Click Add Admin
- Search for the user by name or email
- Select their role (Owner or Admin)
- Click Add
Administrators are not limited. You can appoint as many as you need at no extra cost. Sharing one administrator account is never necessary, and never advisable - the audit trail records who performed each action.
Removing an Admin
- Go to Admins
- Find the admin you want to remove
- Click Remove
- Confirm
You cannot remove the last Owner admin from a workspace. There must always be at least one Owner.
Changing an Admin's Role
- Go to Admins
- Click the role badge next to the admin
- Select the new role
- Confirm
Microsoft Teams
Go to Teams in the left sidebar to manage Microsoft Teams associated with your SharePoint sites.
Many SharePoint sites have an associated Microsoft Team (they share the same M365 Group). This view gives you governance visibility over Teams as well.
What You See
For each team:
- Name and Description
- Owner count - Number of people with Owner access
- Member count - Total members
- External member count - How many members are from outside your organization
- Status indicators:
- Orphaned - No owners; the team has no one responsible for it
- Archived - The team has been archived in Teams
- Has External Members - External/guest members are present
- Last Synced - When Tenaxis last pulled data from Microsoft Graph
Filtering Teams
Use the filter buttons to view:
- Orphaned - Teams with no owners (governance risk)
- External Members - Teams with external participants
- Archived - Teams that have been archived
Managing Orphaned Teams
Orphaned teams are a significant governance risk - they have data but no one responsible for it. To fix an orphaned team:
- Click on the team in the Teams list
- Click Assign Owner
- Search for a user to assign as owner
- Click Save
The user will be added as an owner both in Tenaxis and in Microsoft Teams/M365.
Syncing Teams
Like sites, Teams data is synced automatically on a schedule. To force an immediate update:
- Click Sync All Teams from the Teams list, or
- Trigger a sync for a specific team from its detail view
User Self-Service: The Portal
Regular employees (non-admins) access Tenaxis through the Portal - a simplified interface that shows:
- Governance Inbox - Governance actions requiring attention
- My Sites - Sites associated with recorded roles; any legacy visitor entries are unverified
- My Requests - Their request history
- Request a Site - The form to request a new site
See the Portal Guide for the full user-facing documentation.