Checkpoint runs inside your own Microsoft 365 tenant. This guide covers what we need from you, what happens during setup, and exactly which permissions we ask for and why. Setup normally takes under an hour, most of which is your administrator clicking approve once.
Read this part first
Checkpoint has no database and no server. It is a set of static files served from our website that runs entirely in your browser. Every record it creates — your risk register, controls, evidence, policies, audit findings — is written straight into your own Microsoft 365 tenant, into SharePoint lists in a site you choose.
Compliance365 never holds a copy. We cannot read your registers, we are not a processor of your data, and there is nothing for us to lose in a breach. Your existing Microsoft 365 backup, retention, permission and audit policies apply to Checkpoint's data automatically, because it is simply SharePoint content in your tenant.
If you stop using Checkpoint, you keep everything. There is no export step and nothing to migrate — the lists are yours and they stay exactly where they are.
Before we start
Some of the posture checks read Microsoft Entra ID Protection, Intune and Microsoft Secure Score. If your licensing does not include a given feature, Checkpoint reports that check as Manual and explains why, rather than counting it against your score.
The setup
In the SharePoint admin centre, create a Team site named something like Compliance. Note its address — it will look like /sites/compliance.
We strongly recommend a dedicated site rather than your intranet home. Compliance records include audit findings and management review minutes, and a dedicated site lets you control precisely who can see them, retain and back it up as one unit, and hand it over or close it cleanly later.
We will send you an admin consent link. Your Global Administrator opens it, reviews the permissions listed in the next section, and approves. This is a single approval covering your whole organisation, so nobody is prompted individually afterwards.
Then send us one thing. After approving, the browser returns to Checkpoint with your tenant's identifier in the address bar — it looks like ?admin_consent=True&tenant=00000000-1111-…. Copy that whole address and send it to us; we need the identifier to issue your activation file in the next step.
If the tab has already been closed, either of these works just as well: your organisation's primary domain (for example yourcompany.com.au), or the Tenant ID shown on the Overview page of the Microsoft Entra admin centre.
Using the identifier from step 2, we issue a small signed file that unlocks the frameworks you have licensed and is bound cryptographically to your tenant. It cannot be used anywhere else — the file is checked against the tenant it is opened in, so a copy of it is worthless to anybody else. We send it to you along with your Checkpoint address.
Open Checkpoint and sign in with a Microsoft 365 account in your tenant. A short wizard asks three things: which SharePoint site to use (the one from step 1), your activation file, and which frameworks to switch on.
It creates its lists and a document library in the site you chose, then fills the control set for each licensed framework — for ISO 27001 that is all 93 Annex A controls, ready to work through. This takes a few minutes and needs nothing from you.
Nothing is copied from anywhere else. Your control set is generated fresh in your tenant.
Finally, decide access. Most organisations use three groups: Practitioners who run the management system and can edit everything; Viewers such as executives or board members who get read-only access; and Staff, who need only to read policies assigned to them and record that they have done so.
We will walk you through this and can do it with you on a call. It is the one step worth not rushing.
Transparency
| What it covers | Why we need it | Exact permission names |
|---|---|---|
| Read your security configuration | Conditional Access policies, admin role assignments, device compliance, risky sign-ins, sensitivity labels, access reviews and Secure Score. This is what the posture scan reads to tell you where you actually stand. All of it is read-only — Checkpoint cannot change a single setting in your tenant. | Policy.Read.All SecurityEvents.Read.All DeviceManagementManagedDevices.Read.All DeviceManagementConfiguration.Read.All RoleManagement.Read.Directory IdentityRiskyUser.Read.All SensitivityLabels.Read.All AccessReview.Read.All SharePointTenantSettings.Read.All |
| Read your directory | To resolve your organisation's name, and to list staff when you assign a policy or a training course to people. Read-only. | User.Read Directory.Read.All |
| Manage the SharePoint site you chose | The only permission that can write anything. It is what creates and updates Checkpoint's own lists. Because it is delegated, it is bounded by the signed-in person's existing SharePoint access — Checkpoint cannot reach a site they could not already reach. | Sites.Manage.All |
| Send mail as you | Requested only the first time you actually send something — a policy acknowledgement request, a training reminder, or a status update. If you never use those features, this is never requested. | Mail.Send |
The approval screen shows Microsoft's own technical names — the third column above — rather than the descriptions we have used here. Two things are worth knowing before you read it:
You should see thirteen permissions and nothing else. If the list does not match the third column above, stop and contact us before approving.
Checkpoint requests permissions progressively rather than all at once. Signing in asks only for the read-only set; the SharePoint permission is requested when your records are first created; mail is requested the first time you send something. Approving up front simply means nobody is prompted again later.
There is nothing to register or configure on your side. Checkpoint is a single application registered once by Compliance365, and your approval grants it access to your tenant only — it is the same application every client consents to, and it can never read across tenants.
After setup
Questions we are usually asked
No. There is no backend and no copy. Your records exist only in your tenant, under your own permissions. We can see what you choose to show us during an engagement, in the same way any consultant would.
No. Every permission touching your tenant configuration is read-only. The only thing Checkpoint can write is its own SharePoint lists in the site you nominated.
Your lists, documents and evidence stay in your tenant exactly as they are. Withdraw the app's consent in Entra and Checkpoint simply stops being able to reach them.
Only people who use Checkpoint need access to it. Staff being asked to acknowledge a policy or complete training sign in with the Microsoft 365 account they already have, see only their own items, and see nothing else.
In the SharePoint site you chose, in your tenant, in whichever Microsoft region your tenant is hosted. Checkpoint does not move it anywhere.
The technical steps take about fifteen minutes. The admin consent needs a Global Administrator to be available, and deciding your permission groups is worth a short conversation — so allow an hour end to end, with us on a call if that helps.
Help
Stop and send us what you see, including any error message. Setup is safe to retry — Checkpoint never creates a duplicate of something it has already made, so running the wizard again after a failure picks up where it left off rather than starting over.
Reach us at hello@compliance365.com.au.