Tenaxis
/Docs
Sign in

Admin Guide

Users & Access

This section covers all aspects of user management in Tenaxis - who has access to sites, how to view and manage that access, handling guest users, managing Microsoft Teams, and controlling who are Tenaxis admins.


Overview: How Access Works in M365 + Tenaxis

In Microsoft 365, access to a SharePoint site is controlled through an M365 Group. Each site has a group with:

  • Owners - Full control; can add/remove members and change site settings
  • Members - Can collaborate (read, edit, create files)
  • Visitors - Read-only access; typically used for guests or external users

Tenaxis reads this membership data from Microsoft and displays it in a unified dashboard, giving you visibility across all sites at once - something M365's admin center doesn't easily provide.


Users Page

Go to Access → Users (or the Users section in the sidebar) to see a directory of all users who have been given access to any site.

For each user you can see:

  • Display Name
  • UPN (email) - their Microsoft 365 email address
  • Account Status - Enabled or disabled in Azure AD
  • Sites they can access - a list of sites and their role on each

Filtering Users

Use the filter options to narrow the list:

  • Members - Users who are owners or members on sites
  • Visitors - Users with guest/read-only access
  • Disabled Accounts - Users whose M365 accounts have been disabled (useful for spotting offboarding gaps)

Access Matrix

The Access page shows a full matrix of sites versus users - who has access to what, at a glance.

This is one of the most powerful views in Tenaxis. Instead of looking at one site at a time, you can see your entire access landscape in one place.

Reading the Matrix

  • Rows represent users
  • Columns represent sites (or vice versa, depending on the view)
  • Cells show the role at the intersection: OWNER, MEMBER, or VISITOR
  • Empty cells mean that user doesn't have access to that site

Using the Matrix

  • Search - Filter by user name or site name to focus on specific people or sites
  • Export - Download the access matrix as a CSV report for compliance reviews

Common Use Cases

  • Over-provisioning audit - Quickly spot users who have OWNER access to many sites (potential over-privilege)
  • User offboarding - See all sites a departing employee has access to before removing them
  • Compliance check - Show an auditor exactly who has access to what

Managing Site Members

Adding a Member to a Site

  1. Go to Sites and open the site you want to manage
  2. Click on the Members tab
  3. Click Add Member
  4. Search for the user by name or email address
  5. Select their Role - OWNER or MEMBER
  6. Click Add

The user will be added to the M365 Group immediately.

Removing a Member from a Site

  1. Open the site detail view → Members tab
  2. Find the user you want to remove
  3. Click the Remove button next to their name
  4. Confirm the removal

Important: Removing the last owner from a site creates an "orphaned" site. Tenaxis will warn you if this happens.

Changing a Member's Role

Currently, you can remove a member and re-add them with the new role, or use Microsoft 365 Admin Center to change roles directly. Direct role-change within Tenaxis is in the roadmap.


Guests & External Users

External users - people from outside your organization - appear with #EXT# in their email address in Microsoft 365 (e.g., jane.smith_contoso.com#EXT#@yourdomain.onmicrosoft.com).

Go to Guests in the left sidebar to see all external users and what sites they can access.

What You See

For each external user:

  • Their display name
  • Their real email address (extracted from the #EXT# format for readability)
  • All sites they have access to, with their access type (member with role, or visitor)

Why This Matters

Guest access is one of the most common sources of data oversharing. The Guests view helps you:

  • Identify guests who may no longer need access (e.g., a project ended)
  • Spot unexpected external access to sensitive sites
  • Prepare for a compliance audit by proving you know who your external users are

Removing a Guest

Guests are removed through the normal member removal flow:

  1. Find the site they have access to
  2. Open the site detail → Members or Visitors tab
  3. Remove them

For bulk removal of a guest across all sites, use the Offboarding workflow (see Offboarding).


Admins

Go to Admins in the left sidebar to manage who has administrative access to Tenaxis.

Important: Tenaxis admins are separate from SharePoint site owners. A Tenaxis admin can manage the governance platform (approve requests, apply policies, view all sites, etc.) but this doesn't automatically make them an owner on every SharePoint site.

Admin Roles

RoleWhat they can do
OwnerFull access - everything, including billing, adding/removing other admins, and all governance features
AdminFull governance access (sites, requests, policies, access reviews, etc.) but cannot manage other admins or billing

Adding an Admin

  1. Go to Admins
  2. Click Add Admin
  3. Search for the user by name or email
  4. Select their role (Owner or Admin)
  5. Click Add

Admin seat limits: Starter plan includes 1 admin seat; Pro includes 5; Enterprise is unlimited.

Removing an Admin

  1. Go to Admins
  2. Find the admin you want to remove
  3. Click Remove
  4. Confirm

You cannot remove the last Owner admin from a workspace. There must always be at least one Owner.

Changing an Admin's Role

  1. Go to Admins
  2. Click the role badge next to the admin
  3. Select the new role
  4. Confirm

Microsoft Teams

Go to Teams in the left sidebar to manage Microsoft Teams associated with your SharePoint sites.

Many SharePoint sites have an associated Microsoft Team (they share the same M365 Group). This view gives you governance visibility over Teams as well.

What You See

For each team:

  • Name and Description
  • Owner count - Number of people with Owner access
  • Member count - Total members
  • External member count - How many members are from outside your organization
  • Status indicators:
    • Orphaned - No owners; the team has no one responsible for it
    • Archived - The team has been archived in Teams
    • Has External Members - External/guest members are present
  • Last Synced - When Tenaxis last pulled data from Microsoft Graph

Filtering Teams

Use the filter buttons to view:

  • Orphaned - Teams with no owners (governance risk)
  • External Members - Teams with external participants
  • Archived - Teams that have been archived

Managing Orphaned Teams

Orphaned teams are a significant governance risk - they have data but no one responsible for it. To fix an orphaned team:

  1. Click on the team in the Teams list
  2. Click Assign Owner
  3. Search for a user to assign as owner
  4. Click Save

The user will be added as an owner both in Tenaxis and in Microsoft Teams/M365.

Syncing Teams

Like sites, Teams data is synced automatically on a schedule. To force an immediate update:

  1. Click Sync All Teams from the Teams list, or
  2. Trigger a sync for a specific team from its detail view

User Self-Service: The Portal

Regular employees (non-admins) access Tenaxis through the Portal - a simplified interface that shows:

  • My Sites - Sites they're a member or visitor of
  • My Requests - Their request history
  • Request a Site - The form to request a new site

See the Portal Guide for the full user-facing documentation.