Users & Access
This section covers all aspects of user management in Tenaxis - who has access to sites, how to view and manage that access, handling guest users, managing Microsoft Teams, and controlling who are Tenaxis admins.
Overview: How Access Works in M365 + Tenaxis
In Microsoft 365, access to a SharePoint site is controlled through an M365 Group. Each site has a group with:
- Owners - Full control; can add/remove members and change site settings
- Members - Can collaborate (read, edit, create files)
- Visitors - Read-only access; typically used for guests or external users
Tenaxis reads this membership data from Microsoft and displays it in a unified dashboard, giving you visibility across all sites at once - something M365's admin center doesn't easily provide.
Users Page
Go to Access → Users (or the Users section in the sidebar) to see a directory of all users who have been given access to any site.
For each user you can see:
- Display Name
- UPN (email) - their Microsoft 365 email address
- Account Status - Enabled or disabled in Azure AD
- Sites they can access - a list of sites and their role on each
Filtering Users
Use the filter options to narrow the list:
- Members - Users who are owners or members on sites
- Visitors - Users with guest/read-only access
- Disabled Accounts - Users whose M365 accounts have been disabled (useful for spotting offboarding gaps)
Access Matrix
The Access page shows a full matrix of sites versus users - who has access to what, at a glance.
This is one of the most powerful views in Tenaxis. Instead of looking at one site at a time, you can see your entire access landscape in one place.
Reading the Matrix
- Rows represent users
- Columns represent sites (or vice versa, depending on the view)
- Cells show the role at the intersection: OWNER, MEMBER, or VISITOR
- Empty cells mean that user doesn't have access to that site
Using the Matrix
- Search - Filter by user name or site name to focus on specific people or sites
- Export - Download the access matrix as a CSV report for compliance reviews
Common Use Cases
- Over-provisioning audit - Quickly spot users who have OWNER access to many sites (potential over-privilege)
- User offboarding - See all sites a departing employee has access to before removing them
- Compliance check - Show an auditor exactly who has access to what
Managing Site Members
Adding a Member to a Site
- Go to Sites and open the site you want to manage
- Click on the Members tab
- Click Add Member
- Search for the user by name or email address
- Select their Role - OWNER or MEMBER
- Click Add
The user will be added to the M365 Group immediately.
Removing a Member from a Site
- Open the site detail view → Members tab
- Find the user you want to remove
- Click the Remove button next to their name
- Confirm the removal
Important: Removing the last owner from a site creates an "orphaned" site. Tenaxis will warn you if this happens.
Changing a Member's Role
Currently, you can remove a member and re-add them with the new role, or use Microsoft 365 Admin Center to change roles directly. Direct role-change within Tenaxis is in the roadmap.
Guests & External Users
External users - people from outside your organization - appear with #EXT# in their email address in Microsoft 365 (e.g., jane.smith_contoso.com#EXT#@yourdomain.onmicrosoft.com).
Go to Guests in the left sidebar to see all external users and what sites they can access.
What You See
For each external user:
- Their display name
- Their real email address (extracted from the #EXT# format for readability)
- All sites they have access to, with their access type (member with role, or visitor)
Why This Matters
Guest access is one of the most common sources of data oversharing. The Guests view helps you:
- Identify guests who may no longer need access (e.g., a project ended)
- Spot unexpected external access to sensitive sites
- Prepare for a compliance audit by proving you know who your external users are
Removing a Guest
Guests are removed through the normal member removal flow:
- Find the site they have access to
- Open the site detail → Members or Visitors tab
- Remove them
For bulk removal of a guest across all sites, use the Offboarding workflow (see Offboarding).
Admins
Go to Admins in the left sidebar to manage who has administrative access to Tenaxis.
Important: Tenaxis admins are separate from SharePoint site owners. A Tenaxis admin can manage the governance platform (approve requests, apply policies, view all sites, etc.) but this doesn't automatically make them an owner on every SharePoint site.
Admin Roles
| Role | What they can do |
|---|---|
| Owner | Full access - everything, including billing, adding/removing other admins, and all governance features |
| Admin | Full governance access (sites, requests, policies, access reviews, etc.) but cannot manage other admins or billing |
Adding an Admin
- Go to Admins
- Click Add Admin
- Search for the user by name or email
- Select their role (Owner or Admin)
- Click Add
Admin seat limits: Starter plan includes 1 admin seat; Pro includes 5; Enterprise is unlimited.
Removing an Admin
- Go to Admins
- Find the admin you want to remove
- Click Remove
- Confirm
You cannot remove the last Owner admin from a workspace. There must always be at least one Owner.
Changing an Admin's Role
- Go to Admins
- Click the role badge next to the admin
- Select the new role
- Confirm
Microsoft Teams
Go to Teams in the left sidebar to manage Microsoft Teams associated with your SharePoint sites.
Many SharePoint sites have an associated Microsoft Team (they share the same M365 Group). This view gives you governance visibility over Teams as well.
What You See
For each team:
- Name and Description
- Owner count - Number of people with Owner access
- Member count - Total members
- External member count - How many members are from outside your organization
- Status indicators:
- Orphaned - No owners; the team has no one responsible for it
- Archived - The team has been archived in Teams
- Has External Members - External/guest members are present
- Last Synced - When Tenaxis last pulled data from Microsoft Graph
Filtering Teams
Use the filter buttons to view:
- Orphaned - Teams with no owners (governance risk)
- External Members - Teams with external participants
- Archived - Teams that have been archived
Managing Orphaned Teams
Orphaned teams are a significant governance risk - they have data but no one responsible for it. To fix an orphaned team:
- Click on the team in the Teams list
- Click Assign Owner
- Search for a user to assign as owner
- Click Save
The user will be added as an owner both in Tenaxis and in Microsoft Teams/M365.
Syncing Teams
Like sites, Teams data is synced automatically on a schedule. To force an immediate update:
- Click Sync All Teams from the Teams list, or
- Trigger a sync for a specific team from its detail view
User Self-Service: The Portal
Regular employees (non-admins) access Tenaxis through the Portal - a simplified interface that shows:
- My Sites - Sites they're a member or visitor of
- My Requests - Their request history
- Request a Site - The form to request a new site
See the Portal Guide for the full user-facing documentation.