Launching 2026

TRACER365 · Microsoft 365 sharing and permissions auditing

See what your Microsoft 365 is sharing

TRACER365 answers the question your auditors, clients and board keep asking: what is shared from your Microsoft 365 environment — internally and externally, by whom, and with whom? Lightweight compliance for mid-sized organisations — clear answers, not another dashboard to babysit.

Visit tracer365.com ↗Built by Storrex · Microsoft ISV Partner

It’s lightweight compliance for mid-sized organisations: clear answers, not another dashboard to babysit.

Why an IT company built a software product

Because we kept solving the same problem by hand. After twenty years of securing Microsoft environments for clients in regulated sectors, the same question came up in every audit — and answering it manually didn’t scale. So Storrex, as a Microsoft ISV partner, built the tool we wished existed. TRACER365 is consultancy experience turned into software.

What it does

TRACER365 audits external sharing across your Microsoft 365 tenant — every SharePoint Online site and every OneDrive in one read-only scan — and finds the exposures that matter: anonymous “anyone” links, guest access, and inherited external access.

  • Collapses the noise. A single guest grant repeats on every file beneath it; cascade de-duplication folds those inherited duplicates under the grant that caused them — in our testing, roughly 91% of raw findings collapsed — leaving a severity-ranked list a human can actually work through.
  • Runs in your environment. TRACER365 is a Windows application with a local browser UI; audit data stays local and never leaves your tenant — a real data-residency advantage for European organisations.
  • No extra Microsoft licences. No Microsoft 365 Copilot licence, no SharePoint Advanced Management add-on — it works with what you already have.
  • Reviewable, not just runnable. A viewer role for non-IT stakeholders, scheduled email reports to the person who has to act, and scan-over-scan trending — point-in-time and change-over-time evidence for an auditor.

It leads on external exposure, and names specific internal over-exposure conditions — organisation-wide links, “everyone except external users” grants, broken permission inheritance. It’s a read-only audit: the precise discovery step before remediation, not the remediation itself.

Who it’s for

Mid-sized organisations that are audited — or want to be ready — but don’t have a full GRC team to throw at it.

Built by Storrex

TRACER365 is developed and maintained by Storrex, a Microsoft ISV partner, by the same people who secure Microsoft environments for a living. The company behind the product has been operating since 2006.

See what your own tenant is sharing

TRACER365 launches in 2026. The full product — coverage, the read-only trust model, and the free trial — lives on tracer365.com.