
Living Identity and Permission Graph for Microsoft 365
1Security builds an identity and permission visibility platform purpose-built for Microsoft 365, aimed at security, IT and compliance teams that need to answer who can reach which data. The company, registered as 1.Security Sp. z o.o. and based in Łódź, Poland, targets access reviews, breach investigations, audit preparation and Copilot readiness work, and states it has been admitted to Microsoft's Innovation Alley partner program as independent validation of the category.
The platform continuously ingests permission changes, sharing events and sign-ins from a tenant and assembles them into a single living graph rather than periodic exports or snapshots. It resolves the seven layers where access quietly accumulates: direct grants, sharing links, group memberships, SharePoint site roles, OAuth application consent, AI agent knowledge sources and inheritance chains. Identity, content, application and activity data are combined in one view, so a query can be traced from tenant scope down to an individual file.
Remediation is deliberately staged. Detection runs read-only by default, write actions require separate consent, and proposed fixes such as revoking external links, removing stale guests, reclaiming unused licences or tightening sharing defaults enter a review queue with a grace period, blast-radius preview and full audit logging. Coverage extends to non-human identities including service accounts, OAuth apps and Copilot agents that inherit their creators' permissions. The vendor cites three years of attributed activity retention, standard Microsoft licensing requirements, ISO 27001 certification and European data centres.



