COMPLIANCE365
Checkpoint · Client onboarding
For your IT administrator

Setting up Checkpoint in your Microsoft 365 tenant

Checkpoint runs inside your own Microsoft 365 tenant. This guide covers what we need from you, what happens during setup, and exactly which permissions we ask for and why. Setup normally takes under an hour, most of which is your administrator clicking approve once.

Read this part first

Your data never leaves your tenant

Checkpoint has no database and no server. It is a set of static files served from our website that runs entirely in your browser. Every record it creates — your risk register, controls, evidence, policies, audit findings — is written straight into your own Microsoft 365 tenant, into SharePoint lists in a site you choose.

Compliance365 never holds a copy. We cannot read your registers, we are not a processor of your data, and there is nothing for us to lose in a breach. Your existing Microsoft 365 backup, retention, permission and audit policies apply to Checkpoint's data automatically, because it is simply SharePoint content in your tenant.

If you stop using Checkpoint, you keep everything. There is no export step and nothing to migrate — the lists are yours and they stay exactly where they are.

Before we start

What we need from you

  • A Microsoft 365 tenant with SharePoint Online. Business Standard and above are all fine.
  • A Global Administrator available for roughly five minutes, to approve Checkpoint's access once for the whole organisation.
  • A named person to own the management system day to day — usually whoever will hold the ISMS Manager role. They do not need to be technical.
  • A decision on where the records should live. We recommend a dedicated SharePoint site (see step 1). If you already have a compliance or governance site, that works too.
  • Your tenant's identifier, which we need to issue your activation file. Step 2 hands it to you automatically, so there is nothing to look up in advance — your primary domain works too if it is easier.
  • An account for your Compliance365 consultant in your tenant, if we are running the engagement with you rather than handing over. A standard licensed account is enough; guest accounts are not sufficient for the posture checks.

Some of the posture checks read Microsoft Entra ID Protection, Intune and Microsoft Secure Score. If your licensing does not include a given feature, Checkpoint reports that check as Manual and explains why, rather than counting it against your score.

The setup

Six steps, in this order

You · SharePoint admin

Create a site for your compliance records

In the SharePoint admin centre, create a Team site named something like Compliance. Note its address — it will look like /sites/compliance.

We strongly recommend a dedicated site rather than your intranet home. Compliance records include audit findings and management review minutes, and a dedicated site lets you control precisely who can see them, retain and back it up as one unit, and hand it over or close it cleanly later.

You · Global administrator

Approve Checkpoint's access, once

We will send you an admin consent link. Your Global Administrator opens it, reviews the permissions listed in the next section, and approves. This is a single approval covering your whole organisation, so nobody is prompted individually afterwards.

Then send us one thing. After approving, the browser returns to Checkpoint with your tenant's identifier in the address bar — it looks like ?admin_consent=True&tenant=00000000-1111-…. Copy that whole address and send it to us; we need the identifier to issue your activation file in the next step.

If the tab has already been closed, either of these works just as well: your organisation's primary domain (for example yourcompany.com.au), or the Tenant ID shown on the Overview page of the Microsoft Entra admin centre.

Compliance365

We issue your activation file

Using the identifier from step 2, we issue a small signed file that unlocks the frameworks you have licensed and is bound cryptographically to your tenant. It cannot be used anywhere else — the file is checked against the tenant it is opened in, so a copy of it is worthless to anybody else. We send it to you along with your Checkpoint address.

You or us · first sign-in

Sign in and run the setup wizard

Open Checkpoint and sign in with a Microsoft 365 account in your tenant. A short wizard asks three things: which SharePoint site to use (the one from step 1), your activation file, and which frameworks to switch on.

The Checkpoint sign-in screen. Use Sign in with MicrosoftExplore the demo opens sample data and touches nothing in your tenant.
Paste or upload the activation file we sent you. It is verified in your browser; nothing is sent anywhere to check it.
Enter the site you created in step 1. Validate & continue confirms it exists before anything is written to it.
Switch on the frameworks you have licensed. More can be added later without re-running setup.
Automatic

Checkpoint builds your records

It creates its lists and a document library in the site you chose, then fills the control set for each licensed framework — for ISO 27001 that is all 93 Annex A controls, ready to work through. This takes a few minutes and needs nothing from you.

Nothing is copied from anywhere else. Your control set is generated fresh in your tenant.

You · SharePoint admin

Set who can see what

Finally, decide access. Most organisations use three groups: Practitioners who run the management system and can edit everything; Viewers such as executives or board members who get read-only access; and Staff, who need only to read policies assigned to them and record that they have done so.

We will walk you through this and can do it with you on a call. It is the one step worth not rushing.

Transparency

What we ask for, and why

Every permission below is delegated, meaning Checkpoint acts only as the person signed in and can never see or do more than that person already could.
What it coversWhy we need itExact permission names
Read your security configuration Conditional Access policies, admin role assignments, device compliance, risky sign-ins, sensitivity labels, access reviews and Secure Score. This is what the posture scan reads to tell you where you actually stand. All of it is read-only — Checkpoint cannot change a single setting in your tenant. Policy.Read.All SecurityEvents.Read.All DeviceManagementManagedDevices.Read.All DeviceManagementConfiguration.Read.All RoleManagement.Read.Directory IdentityRiskyUser.Read.All SensitivityLabels.Read.All AccessReview.Read.All SharePointTenantSettings.Read.All
Read your directory To resolve your organisation's name, and to list staff when you assign a policy or a training course to people. Read-only. User.Read Directory.Read.All
Manage the SharePoint site you chose The only permission that can write anything. It is what creates and updates Checkpoint's own lists. Because it is delegated, it is bounded by the signed-in person's existing SharePoint access — Checkpoint cannot reach a site they could not already reach. Sites.Manage.All
Send mail as you Requested only the first time you actually send something — a policy acknowledgement request, a training reminder, or a status update. If you never use those features, this is never requested. Mail.Send

Reading the consent screen

The approval screen shows Microsoft's own technical names — the third column above — rather than the descriptions we have used here. Two things are worth knowing before you read it:

  • .Read. means read-only, however broad the name sounds. Directory.Read.All permits reading your directory and nothing more; there is a separate .ReadWrite. form for changing things, and Checkpoint does not request any of them.
  • Every permission is Delegated, not Application. The screen will say so. Delegated means Checkpoint can only ever act as the person signed in — it has no standing access of its own and cannot run when nobody is using it.

You should see thirteen permissions and nothing else. If the list does not match the third column above, stop and contact us before approving.

Checkpoint requests permissions progressively rather than all at once. Signing in asks only for the read-only set; the SharePoint permission is requested when your records are first created; mail is requested the first time you send something. Approving up front simply means nobody is prompted again later.

There is nothing to register or configure on your side. Checkpoint is a single application registered once by Compliance365, and your approval grants it access to your tenant only — it is the same application every client consents to, and it can never read across tenants.

After setup

What happens next

The dashboard after a first scan, shown here with sample data. Posture score, framework readiness, open risks and overdue actions in one view.
The document control register. Every controlled document carries an owner, a version, an approval and a next-review date — overdue reviews are flagged, which is what an auditor checks first.

Questions we are usually asked

Before you approve anything

Can Compliance365 see our data?

No. There is no backend and no copy. Your records exist only in your tenant, under your own permissions. We can see what you choose to show us during an engagement, in the same way any consultant would.

Can Checkpoint change our security settings?

No. Every permission touching your tenant configuration is read-only. The only thing Checkpoint can write is its own SharePoint lists in the site you nominated.

What if we stop using it?

Your lists, documents and evidence stay in your tenant exactly as they are. Withdraw the app's consent in Entra and Checkpoint simply stops being able to reach them.

Do all our staff need a licence or a login?

Only people who use Checkpoint need access to it. Staff being asked to acknowledge a policy or complete training sign in with the Microsoft 365 account they already have, see only their own items, and see nothing else.

Where exactly does the data sit?

In the SharePoint site you chose, in your tenant, in whichever Microsoft region your tenant is hosted. Checkpoint does not move it anywhere.

How long does setup really take?

The technical steps take about fifteen minutes. The admin consent needs a Global Administrator to be available, and deciding your permission groups is worth a short conversation — so allow an hour end to end, with us on a call if that helps.

Help

If anything does not go to plan

Stop and send us what you see, including any error message. Setup is safe to retry — Checkpoint never creates a duplicate of something it has already made, so running the wizard again after a failure picks up where it left off rather than starting over.

Reach us at hello@compliance365.com.au.