Investigations

Who changed access?

An investigation starts with a resource, an identity or a date and ends with a defensible story: which change happened, who made it, what the access looked like before and after, and which other identities and resources it touched.

Event timeline

Every change, attributed

Inheritance breaks, role assignment changes, group membership changes and sharing-link events are brought together in one timeline with the actor, the UTC timestamp and the state before and after.

The Access Witness Investigations page: search filters above the recorded changes, newest first, each with when it happened, what happened, the kind of change, the access before and after, and whether it gave more or less access.
The Investigations page: filter by who made the change, whose access changed, where, the kind of change and when; every row says who did it, when, and the access before and after. Sample Contoso Finance data.

Workflow

From a question to exportable evidence

  • Scope the investigation

    Start from a resource, an identity, an actor or a time window. Changes are listed newest first, one per row, and each opens with the before and after, the actor and the original audit record.
  • Attribute the actor

    Each event names the administrator, owner or user who made the change, as recorded by the Microsoft 365 audit log.
  • See the blast radius

    The person or group whose access changed, and the resource it changed on, are listed for every change.
  • Export evidence

    Export the event list as CSV, or the answer with its access paths, before/after state and confidence as a JSON evidence file.

Worked example

The Payroll privilege increase

On Jan 20, 2026 the Finance Visitors group on the Payroll folder was changed from Read to Edit; on Jan 28 it was changed back. For eight days every member of Finance Visitors, including the external guest Alex Turner via the Finance Contractors group, could edit payroll files.

What changed

Finance Visitors' permission on the Payroll folder: raised from Read to Edit, then set back to Read.

Who and when

Jordan Ellis, Global Administrator, at 2026-01-20 15:05:41 UTC and 2026-01-28 10:00:00 UTC.

Who was affected

Finance Visitors members: Finance Contractors (Entra ID group) including Alex Turner and, via nesting, External Auditors and Elena Vance.

A current-state permission report taken today shows Finance Visitors with Read and nothing unusual. The investigation timeline is the only place the eight-day window exists.

Investigations

Turn permission changes into an investigation timeline.

See how Access Witness records SharePoint permissions as they change and answers who had access on any past date, on a server you control.

Private deployment. Customer-controlled SQL database. Outbound-only connectivity.