HOME / RESOURCES / SECURITY & DATA
⌑ SECURITY & YOUR DATA
Your workplace.
Your data.
Your control.
Brillienta products have no vendor cloud. They run in each person’s browser inside SharePoint, read and write only your site’s lists with that person’s own permissions, and send email through flows in your own Power Automate environment. This page is written for your security review.
Nothing leaves your tenant. Exports are created in the browser.
THE ARCHITECTURE
Six facts for
your security review.
These hold for HRMS, Helpdesk, Asset Management, Employee Directory and TaskManager. Intranet Builder follows the same model, with a provisioning engine for installation.
MICROSOFT GRAPH
Permissions, only where
a feature needs them.
All delegated, approved once by a SharePoint or global administrator under API access. If one isn’t approved, only that feature is unavailable.
| Product | Permission | Used for |
|---|---|---|
| Helpdesk | None | The package requests no Graph permissions. Email, reminders and email-to-ticket run through your flows. |
| HRMS | User.Read.All, Presence.Read.All, DeviceManagementManagedDevices.Read.All | Directory sync, Teams presence, Intune device sync (Enterprise) |
| Asset Management | DeviceManagementManagedDevices.Read.All, Device.Read.All | “Sync now” device sync from the browser. The daily flow uses your own app registration. |
| Employee Directory | User.Read.All, Presence.Read.All, Mail.Send, Mail.Send.Shared | Sync and photos, Teams status, email notifications from the acting person or a shared mailbox |
| TaskManager | User.Read.All, Device.Read.All, Tasks.ReadWrite, Teams channel scopes | Only for the integrations you switch on: directory and device sync, Planner, Teams channel posts |
| Intranet Builder | User.Read, User.Read.All, Tasks.Read | Audience targeting, directory and org chart, My tasks — per package, per module |
DEFENCE IN DEPTH
Not just
hidden buttons.
Enforced.
What an app hides is also closed in SharePoint. Three independent layers decide what anyone can do: SharePoint permissions, the app role, and the plan.
Read the security chapters ↗Roles kept in step
Saving a role in the app updates the matching SharePoint group, so app roles and real permissions always agree. Nobody can promote themselves.
Verified, not trusted
Employee writes are checked: receipt confirmations against SharePoint’s Created By, approvals against version history, kudos authors against the recorded author.
Sensitive lists closed
Payroll closed to HR, reviews closed to employees, licence keys hidden, internal ticket notes kept from requesters — in SharePoint itself.
Safe content
Safe HTML cleaning on formatted text, unguessable 20-character ticket links, and CSV exports that neutralise spreadsheet formulas.
Offline licence checks
Keys are digitally signed and bound to your tenant. The app verifies them itself — no licence server, no phone-home.
Additive upgrades
New releases only add lists, columns and choices. Validation and repair can run any time; nothing is deleted.
AI FEATURES
AI that respects
the same boundaries.
AI is optional, scoped and transparent about where processing happens.
Built-in, in the browser
TaskManager’s quick add, suggestions, duplicate warnings, risk scores, focus plan and triage run in the browser. Nothing leaves SharePoint.
Your own model
Generative features (Enterprise) use your own Azure OpenAI deployment through a flow in your tenant — not a vendor model.
Copilot, as the user
The Helpdesk Copilot agent reads through Microsoft Graph with delegated permissions; changes execute as the requester, under the app’s rules.
SECURITY & DATA QUESTIONS
Reasonable
questions.
We would rather answer these early than during procurement.
Ask a data question ↗Is our data really inside our own tenant?
Yes. Records live in SharePoint lists on a site you choose, and move only through SharePoint and your own Power Automate flows. There is no vendor database, analytics or tracking.
What happens if we stop?
Your data stays where it always was, readable in list views, Excel and Power BI. After a licence ends there are 14 days’ grace before the app locks or turns read-only.
Can a technical user bypass the app?
The app’s rules are backed by SharePoint permissions on each list. Where records must be private per person — tickets, payslips, reviews — switch on privacy so SharePoint itself returns only a person’s own items, even over REST.
Which account sends email?
The account that runs your imported flow, sending from the mailbox you choose. Use a dedicated service account with Send As, so mail doesn’t stop when someone leaves.
How is background work done without a server?
Jobs such as SLA checks, reminders and sync run in an open staff page with shared locks and run logs. When nobody is online, scheduled Power Automate flows do the same work.
Do you need access to our tenant?
No. You install the package yourself. For consulting or rollout help we work with the access you grant, under your change process.
YOUR DATA. YOUR CALL.