Skip to content
BSE Analyzer – User Manual Skip to main content

Binera

Menu
  • Home
  • Services
  • Products
    • Binera Sharepoint Explorer
  • About us
  • Contact us
  • Book a meeting
Binera

Binera

Binera

Documentation

BSE Analyzer user manual

This guide explains how to use BSE Analyzer to review SharePoint access risk from a completed recursive Binera SharePoint Explorer scan. Analyzer shows the scan result that has been opened; it does not provide a combined view of an entire SharePoint installation, tenant or all sites.

BSE Analyzer v19.30 · User manual version 2.7 · Analyzer-only edition · Last updated: June 22, 2026

Dashboard Recommended workflow Analyzer views FAQ
Key tasks

What Analyzer helps you do

Open

Open one scan result

Open a completed BSE Analyzer report from the selected tree node in BSE, or load one BSE CSV file when using the support/upload version.

Prioritize

Prioritize findings

Start with the dashboard, split KPI tiles, clickable drilldowns, critical/high risk paths and Findings before drilling into raw data.

Understand

Understand access

Review object types, users, groups, guests, external access, direct permissions, sharing links and permission combinations.

Export

Export follow-up lists

Filter, sort and export the current view to create focused review and remediation lists.

Contents

On this page

Overview

Purpose and scope

Scan result

How reports are created

Open a report

BSE menu and support upload

Dashboard

Main screen and actions

Workflow

Recommended review order

Risk levels

Scores and signals

Analyzer views

Navigation and view purpose

Users and groups

Access review

Search and export

Filtering and outputs

Columns

Common fields and terms

Practical tips

How to work efficiently

FAQ

Common questions
Overview

BSE Analyzer is a read-only analysis tool

BSE Analyzer is used for a SharePoint permission scan result from Binera SharePoint Explorer. Each report is limited to the selected SharePoint area that was scanned in BSE, such as a site, document library, folder or another defined part of the structure. Analyzer helps users understand where access risk exists within that scanned area, who has access, which groups are involved and which items should be reviewed first.

Scope limitation

Analyzer shows only the result from the scan you opened. It cannot show a complete SharePoint installation, tenant or all sites in one view. To review multiple libraries, folders or sites, run and open one scan per selected area.

Read-only

What Analyzer does not do

Analyzer does not change SharePoint permissions. It supports review and follow-up. Permission changes must still be performed in SharePoint, Entra ID or the relevant administration tool.

Risk signals

What Analyzer helps you find

High-risk paths, object types, external users, guests, direct permissions, sharing links, broad access, owner-level access, keyword matches in file or folder paths and unusual permission combinations.

Privacy

Content privacy

Analyzer uses permission-report data from the loaded scan result, such as file and folder paths, file names, users, groups, roles and permission metadata. It does not open files or inspect document content.

Point-in-time report

A scan result reflects SharePoint access in the scanned area when the scan was created. If permissions have changed after the scan, configure or run a new scan for that area before making decisions based on the result.

Scan result

How the scan result is created

BSE is used to browse SharePoint and select the site, document library, folder or tree node that should be reviewed. A recursive scan collects permission data across folders and sublevels inside the selected scope. The scan result includes the Object Type field when available, so Analyzer can distinguish between different kinds of scanned SharePoint objects.

Recursive scan

Selected tree node

The scan follows the selected SharePoint structure and includes permissions from underlying folders and items, so access deviations deeper in the structure are included in the result.

Configure

Configure from BSE

Use Configure Scan of folder tree from this tree node from the BSE right-click menu to configure the recursive scan.

Scheduled scan

Run after 17:00

The dialog shows scheduled scans with Site, Folder, Schedule and Last run. Jobs can only run after 17:00 to reduce impact during working hours.

Completed report

Open from BSE

When a completed report exists, it can be opened from the BSE right-click menu with Open BSE Analyzer report.

Standard flow

Select a site or folder in BSE → configure recursive scan from the tree node → run after 17:00 → open the completed report from the BSE right-click menu → review the result in BSE Analyzer.

Open report

Open a scan result

The normal user flow is to open Analyzer from the selected tree node in BSE when a completed report exists. Analyzer loads that specific scan result and starts the browser-based analysis.

Standard user flow

Open from BSE

Right-click the relevant site or folder in BSE and select Open BSE Analyzer report. This option is shown only when a completed report exists for the selected tree node.

Support flow

Manual upload version

Use this for internal, support or controlled manual analysis. Drag one BSE CSV file into the upload area, or click the upload area and select the file from your computer. The upload represents one scan result.

Open

Open the report

Start from the right-click menu in BSE for the selected tree node.

Load

Wait for analysis

Analyzer reads the loaded scan result and prepares dashboards, risk scores and views.

Review

Start with dashboard

Review the summary before moving into detailed views.

Export

Export only what you need

Use filters, sorting and current-view export for practical follow-up lists.

Tip

Use the newest completed scan result for the area you are reviewing. Old reports may no longer match the current SharePoint permission setup.

Dashboard

Dashboard and main screen

The Dashboard is the starting point after a scan result has been opened. It combines the main navigation, scan metadata, status chips, KPI cards and the Access Risk Snapshot in one screen.

Use this screen to understand the size, scope and risk profile of the scan before opening the detailed views.

Header
Shows the loaded file name, file scan date, document library, full path and number of source data rows when these values are available in the scan result.
Status chips
Show the active rule set, configured internal domains and number of keyword rules.
KPI cards
Summarise CSV rows, unique paths, unique principals and permission combinations. External/guests and Critical/high paths are shown as split values so the counts can be interpreted separately.
Access Risk Snapshot
Provides dashboard cards for risk distribution, findings by severity, permission combinations, object types, external/guest principals, keyword rules and top risk paths.
Left navigation
Moves between Dashboard, Findings, access risk views, users and groups, Group access chains and Raw data. The light UI uses a white sidebar with the blue Analyzer accent.

Split KPI values

The top KPI area separates values that are often reviewed differently:

External / guestsShows external identity count and guest identity count as separate values.
Critical / high pathsShows Critical path count and High path count as separate values.

Dashboard drilldowns

Some dashboard tiles can be used as shortcuts into more detailed views.

External and guest principalsOpens the Users/principals view for review of identities in the loaded scan result.
Keyword rulesOpens the Keyword rules dialog so the matched rule set can be reviewed.

Click the tile with the mouse, or use keyboard focus and press Enter or Space.

Top action buttons

The buttons in the top-right corner are global actions for the loaded scan result.

Back to BSEReturn to Binera SharePoint Explorer.
User manualOpen this help and reference page.
SettingsOpen Analyzer settings and rule configuration where available.
Export original CSVDownload the original scan data for audit or support use.
Dashboard v19.30: Shows the main Analyzer screen after a scan result has loaded, including split KPI values, Access Risk Snapshot, Object types, dashboard drilldowns and Top risk paths. Click the image to view it larger.
Recommended workflow

Start broad, then drill into detail

A BSE scan result can contain many rows. The easiest way to work is to start with the summary and risk-prioritized views, then drill into users, groups or raw data only when needed.

Dashboard

Start with the summary

Check the scan result size, split external/guest counts, split critical/high path counts, object types, keyword rules and permission combinations.

Top Risk paths

Review priority paths

Identify files and folders that should be reviewed first.

Findings

Use Findings as actions

Use Findings as an action list for review and follow-up.

Users and groups

Understand access

Understand who has access and how access is assigned before changing anything.

Start with Top Risk paths

Top Risk paths is normally the best first detailed view because it sorts the loaded scan result around items that have the strongest risk indicators.

  • Review Critical and High items first.
  • Use search to focus on a folder, path keyword, group or user within the scanned area.
  • Check risk indicators before deciding whether access is actually wrong.
  • Export the filtered view when you need a review list.
Top Risk paths: Shows high-priority files and folders with risk level, score and risk indicators. Click the image to view it larger.
Findings: An action-oriented view for review, cleanup and reporting. Click the image to view it larger.

Use Findings as the action list

Findings collects important observations into a practical list. This is useful when the result needs to be reviewed by an owner, security team, compliance team or administrator.

  • Use Findings to explain what should be reviewed.
  • Sort or search to focus on the most relevant items.
  • Export the view to support cleanup or documentation.
Risk levels

Risk levels and signals

Analyzer assigns relevant items a risk score to help prioritize review. The score is a prioritization aid, not a decision by itself.

Typical signals that can increase risk include external users, guest identities, sharing links, direct permissions, owner-level access, many users or groups with access, keyword matches in file or folder paths and unusual permission combinations.

The Dashboard also shows findings using action-oriented labels: Review first, Review soon, Review when relevant and Lower priority. These labels map the technical risk signals to a practical review order.

Risk levelScore rangeHow to read it
Critical90–100Review first. These items usually combine several risk signals or have very strong indicators.
High60–89Review soon. These items have clear signals that should be checked.
Medium30–59Review when relevant. These items may need attention depending on business context.
Low0–29Usually lower priority, but still part of the complete access picture.

Remember

A Critical or High score does not automatically mean that access is wrong. Some access may be intentional, approved and necessary. Review the context before changing permissions.

Views

Analyzer views

The left navigation menu groups Analyzer into views for overview, access risk, users and groups, and raw data. Each view is limited to the loaded scan result.

Navigation menu

The navigation menu is the fastest way to move between summary, risk, user, group and data views.

  • Overview: Dashboard and Findings.
  • Access risk: Top Risk paths, Path analysis and Permission combinations.
  • Users and groups: Users/principals, User access, Groups, Group members, Group access and Group access chains.
  • Data: Raw data.
Navigation menu: Shows the main Analyzer views. Click the image to view it larger.
ViewUse it for
DashboardQuick overview of the loaded scan result size, split KPI values, risk distribution, findings by severity, object types, keyword rules, dashboard drilldowns and important access signals.
FindingsAction-oriented list of items in the loaded scan result that should be reviewed or documented.
Top Risk pathsFiles, folders and other scanned objects in the loaded scan result, prioritized by risk score and risk indicators.
Path analysisReview of paths, object types and path-level access information within the loaded scan result.
Permission combinationsPermission patterns that repeat across the report. Useful for finding similar access setups.
Users/principalsOverview of identities that appear in the loaded scan result, including users, groups, guests and sharing-link identities. This view can also be opened from the External and guest principals dashboard tile.
User accessChoose a user or principal and see matching files and folders within the loaded scan result.
GroupsReview groups found in the loaded scan result.
Group membersReview member information when available in the report.
Group accessChoose a group and see files and folders the group can access within the loaded scan result.
Group access chainsReview how group-based access is connected when chain information is available in the loaded scan result.
Keyword rules dialogReview the keyword rules used for dashboard counts and keyword-related findings. It can be opened from the Keyword rules dashboard tile.
Raw dataDetailed source rows, Object Type, RootGroupType and Analyzer-derived fields for validation or deeper analysis.
Users and groups

Users, groups and access

Access in SharePoint is often assigned through groups, direct permissions and sharing links. Use the user and group views to understand how access reaches a file or folder inside the scanned area before deciding what to change.

User access

Select a user or principal to list the files and folders that match that identity in the loaded scan result. This is useful when you need to answer “what can this user access in this scanned area?”

  • Search for a user, guest or external identity.
  • Review the files and folders connected to that identity.
  • Check whether access is direct, group-based or link-based when the fields are available.
User access: Select a user or principal and list matching files and folders. Click the image to view it larger.
Group access: Select a group and list the files and folders it can access. Click the image to view it larger.

Group access

Select a group to list the files and folders the group has access to within the loaded scan result. This is useful when access is mainly assigned through SharePoint groups or Entra groups.

  • Start with a group that appears in a risky path or finding.
  • Check where the group appears across the loaded scan result.
  • Use Group members when membership information is available and relevant.
Search and export

Search, sort, rows and export

Most Analyzer views are designed to be filtered, sorted and exported. This makes it easier to move from a detailed scan result to a practical follow-up list.

Search

Search inside a view

Use the search field to narrow down the rows shown. This can also be used to find specific object types, such as Site, Subsite, Channel or Pages, when the view includes the Object Type field.

Sort

Sort columns

Click a column header to sort the table. Click again to reverse the order.

Rows

Control page size

Use the Rows selector to control how many rows are visible on the current page.

Export

Export current view

Exports the current view with active search, selected dropdown and table sorting. The export is not limited to only the rows visible on the current page.

Export current view: The export follows the current search, selected dropdown and table sorting. Click the image to view it larger.

Export options

ExportWhat it containsWhen to use it
Export current viewThe rows from the selected view in the loaded scan result, using the current search, dropdown selection and sorting.Use this for practical review lists, audit follow-up or cleanup tasks for the scanned area.
Export original CSVThe original source CSV exactly as it was loaded.Use this when you need to keep, resend or archive the unchanged source report for the scanned area.
Raw data → Export current viewThe Raw data view with Analyzer-derived fields, filtering and sorting.Use this for validation or deeper technical analysis.
Columns and terms

Common columns and terms

The exact columns vary by view. These are the most important fields to understand when reviewing an Analyzer result.

Column or termMeaning
RiskLevelThe risk category: Critical, High, Medium or Low.
RiskScoreThe calculated score used to prioritize review.
PathThe file or folder path from the loaded BSE scan result.
Document LibraryThe document library associated with the loaded row or scan context when this value is available in the scan result.
Full PathThe full path display used to show the document library and item path together when Analyzer has enough source information to build it.
Object TypeThe SharePoint object classification included in the BSE scan result when available. The Dashboard can summarize object types such as Site, Subsite, Channel and Pages. Use this field to separate different object classes when reviewing, filtering or exporting data.
RootGroupTypeGroup classification information from the source scan when available. This can help explain how group-based access is represented and supports group access chain analysis.
Report scopeThe selected SharePoint area that was scanned in BSE. Analyzer does not expand this to other areas, sites or the tenant.
File scan dateThe timestamp shown for when the loaded BSE scan result was created.
Rule setThe active analysis rule set used by Analyzer for the loaded result.
DomainsThe configured internal domains used to distinguish internal identities from external users and guests.
PrincipalA user, group, guest, sharing link or another identity that appears in the loaded scan result.
RoleThe permission role shown in the source report, for example read, edit, contribute or owner-level access depending on the SharePoint setup.
IsExternalIndicates that the identity appears to be outside the internal domain rules used by Analyzer.
IsGuestIndicates that the identity appears to be a guest identity, for example when guest or #EXT# is detected for the same principal.
IsDirectPermissionIndicates that access appears to be assigned directly rather than only through inherited group access.
IsLinkPermissionIndicates that access appears to come from a sharing link.
PermissionCombinationIdIdentifies a permission combination used in the source report. This helps compare similar access patterns.
KeywordHitCountThe number of keyword matches found in the file or folder path.
KeywordMatchesThe keyword terms that matched the file or folder path. This does not mean that file content was scanned.
KeywordScoreThe score contribution from keyword matches.
KeywordRuleIdsTraceability for the keyword rules that matched. This is mainly useful for support and audit follow-up.
Tips

Practical tips

Start focused

Start with priority views

Begin with Dashboard, Top Risk paths and Findings for the loaded scan result before using Raw data.

Context

Review context before changing access

A high score means “review first”, not automatically “remove access”. Check business context and ownership.

Access path

Use user and group views

When a path looks risky, identify which users and groups are involved before deciding what to change.

Export

Filter before exporting

Search and sort before exporting so the export becomes a focused follow-up list.

Traceability

Keep the original report

Export or archive the original CSV if the review needs traceability.

Refresh

Re-scan the area when needed

Configure or run a new scan for the same selected area if permissions have changed since the report was created.

Important

Analyzer helps identify and prioritize access risk inside the loaded scan result. Permission changes must still be planned and performed in the relevant Microsoft 365 or SharePoint administration tools.

FAQ

Frequently asked questions

Does Analyzer change SharePoint permissions?
No. Analyzer is a reporting and review tool. It does not change permissions.
Does Analyzer read file contents?
No. Analyzer uses permission-report data only, such as file and folder names, paths, users, groups, roles and permission information from the loaded scan result. It does not open documents, PDFs, images or other files.
Can Analyzer show a whole SharePoint installation or tenant?
No. Analyzer shows only the result from the BSE scan that has been opened. A scan is scoped to the selected SharePoint area, such as a document library, folder or site. Analyzer does not provide a combined view of a full SharePoint installation, tenant or all sites.
How do I review several SharePoint areas or sites?
Run one BSE scan per selected area, document library, folder or SharePoint site and open each scan result separately in Analyzer. Treat each report as a separate point-in-time view of that specific scope.
Why does a file or folder have a high score?
A high score usually means that several risk signals are present, such as guests, external users, direct permissions, sharing links, broad access, keyword matches in the file or folder path or unusual permission combinations.
Does Critical or High mean the access is wrong?
No. It means the item should be reviewed before lower-priority items. Some high-risk access may be intentional, approved and correct.
Why do I see both external users and guests?
An external user is an identity outside the internal domain rules. A guest is a specific type of external identity where guest indicators such as #EXT# are detected. An external identity is not always a guest.
What does Object Type mean?
Object Type identifies the SharePoint object classification included in the scan result when available. The Dashboard can summarize object types such as Site, Subsite, Channel and Pages. This is useful when you want to filter, compare or export different object classes separately.
What is Group access chains?
Group access chains is a view for reviewing how group-based access is connected when chain information exists in the loaded scan result. It helps explain access paths that are not obvious from a single group or user row.
What should I export?
Use Export current view when you want the filtered and sorted data you are working with. Use Export original CSV when you need the unchanged source CSV.
Why does the result not match current SharePoint permissions?
The report is a point-in-time scan for one selected SharePoint area. If permissions changed after the scan was created, run a new scan for that area before using the result for decisions.

Need help interpreting a scan result?

If you have questions about BSE Analyzer or need help interpreting a scan result, contact Binera or request a review session.

Book a walkthrough Back to top
Built with BoldGrid