BSE Analyzer user manual
This guide explains how to use BSE Analyzer to review SharePoint access risk from a completed recursive Binera SharePoint Explorer scan. Analyzer shows the scan result that has been opened; it does not provide a combined view of an entire SharePoint installation, tenant or all sites.
BSE Analyzer v19.30 · User manual version 2.7 · Analyzer-only edition · Last updated: June 22, 2026
What Analyzer helps you do
Open one scan result
Open a completed BSE Analyzer report from the selected tree node in BSE, or load one BSE CSV file when using the support/upload version.
Prioritize findings
Start with the dashboard, split KPI tiles, clickable drilldowns, critical/high risk paths and Findings before drilling into raw data.
Understand access
Review object types, users, groups, guests, external access, direct permissions, sharing links and permission combinations.
Export follow-up lists
Filter, sort and export the current view to create focused review and remediation lists.
On this page
Overview
Purpose and scopeScan result
How reports are createdOpen a report
BSE menu and support uploadDashboard
Main screen and actionsWorkflow
Recommended review orderRisk levels
Scores and signalsAnalyzer views
Navigation and view purposeUsers and groups
Access reviewSearch and export
Filtering and outputsColumns
Common fields and termsPractical tips
How to work efficientlyFAQ
Common questionsBSE Analyzer is a read-only analysis tool
BSE Analyzer is used for a SharePoint permission scan result from Binera SharePoint Explorer. Each report is limited to the selected SharePoint area that was scanned in BSE, such as a site, document library, folder or another defined part of the structure. Analyzer helps users understand where access risk exists within that scanned area, who has access, which groups are involved and which items should be reviewed first.
Scope limitation
Analyzer shows only the result from the scan you opened. It cannot show a complete SharePoint installation, tenant or all sites in one view. To review multiple libraries, folders or sites, run and open one scan per selected area.
What Analyzer does not do
Analyzer does not change SharePoint permissions. It supports review and follow-up. Permission changes must still be performed in SharePoint, Entra ID or the relevant administration tool.
What Analyzer helps you find
High-risk paths, object types, external users, guests, direct permissions, sharing links, broad access, owner-level access, keyword matches in file or folder paths and unusual permission combinations.
Content privacy
Analyzer uses permission-report data from the loaded scan result, such as file and folder paths, file names, users, groups, roles and permission metadata. It does not open files or inspect document content.
Point-in-time report
A scan result reflects SharePoint access in the scanned area when the scan was created. If permissions have changed after the scan, configure or run a new scan for that area before making decisions based on the result.
How the scan result is created
BSE is used to browse SharePoint and select the site, document library, folder or tree node that should be reviewed. A recursive scan collects permission data across folders and sublevels inside the selected scope. The scan result includes the Object Type field when available, so Analyzer can distinguish between different kinds of scanned SharePoint objects.
Selected tree node
The scan follows the selected SharePoint structure and includes permissions from underlying folders and items, so access deviations deeper in the structure are included in the result.
Configure from BSE
Use Configure Scan of folder tree from this tree node from the BSE right-click menu to configure the recursive scan.
Run after 17:00
The dialog shows scheduled scans with Site, Folder, Schedule and Last run. Jobs can only run after 17:00 to reduce impact during working hours.
Open from BSE
When a completed report exists, it can be opened from the BSE right-click menu with Open BSE Analyzer report.
Standard flow
Select a site or folder in BSE → configure recursive scan from the tree node → run after 17:00 → open the completed report from the BSE right-click menu → review the result in BSE Analyzer.
Open a scan result
The normal user flow is to open Analyzer from the selected tree node in BSE when a completed report exists. Analyzer loads that specific scan result and starts the browser-based analysis.
Open from BSE
Right-click the relevant site or folder in BSE and select Open BSE Analyzer report. This option is shown only when a completed report exists for the selected tree node.
Manual upload version
Use this for internal, support or controlled manual analysis. Drag one BSE CSV file into the upload area, or click the upload area and select the file from your computer. The upload represents one scan result.
Open the report
Start from the right-click menu in BSE for the selected tree node.
Wait for analysis
Analyzer reads the loaded scan result and prepares dashboards, risk scores and views.
Start with dashboard
Review the summary before moving into detailed views.
Export only what you need
Use filters, sorting and current-view export for practical follow-up lists.
Tip
Use the newest completed scan result for the area you are reviewing. Old reports may no longer match the current SharePoint permission setup.
Dashboard and main screen
The Dashboard is the starting point after a scan result has been opened. It combines the main navigation, scan metadata, status chips, KPI cards and the Access Risk Snapshot in one screen.
Use this screen to understand the size, scope and risk profile of the scan before opening the detailed views.
Split KPI values
The top KPI area separates values that are often reviewed differently:
Dashboard drilldowns
Some dashboard tiles can be used as shortcuts into more detailed views.
Click the tile with the mouse, or use keyboard focus and press Enter or Space.
Top action buttons
The buttons in the top-right corner are global actions for the loaded scan result.
Start broad, then drill into detail
A BSE scan result can contain many rows. The easiest way to work is to start with the summary and risk-prioritized views, then drill into users, groups or raw data only when needed.
Start with the summary
Check the scan result size, split external/guest counts, split critical/high path counts, object types, keyword rules and permission combinations.
Review priority paths
Identify files and folders that should be reviewed first.
Use Findings as actions
Use Findings as an action list for review and follow-up.
Understand access
Understand who has access and how access is assigned before changing anything.
Start with Top Risk paths
Top Risk paths is normally the best first detailed view because it sorts the loaded scan result around items that have the strongest risk indicators.
- Review Critical and High items first.
- Use search to focus on a folder, path keyword, group or user within the scanned area.
- Check risk indicators before deciding whether access is actually wrong.
- Export the filtered view when you need a review list.
Use Findings as the action list
Findings collects important observations into a practical list. This is useful when the result needs to be reviewed by an owner, security team, compliance team or administrator.
- Use Findings to explain what should be reviewed.
- Sort or search to focus on the most relevant items.
- Export the view to support cleanup or documentation.
Risk levels and signals
Analyzer assigns relevant items a risk score to help prioritize review. The score is a prioritization aid, not a decision by itself.
Typical signals that can increase risk include external users, guest identities, sharing links, direct permissions, owner-level access, many users or groups with access, keyword matches in file or folder paths and unusual permission combinations.
The Dashboard also shows findings using action-oriented labels: Review first, Review soon, Review when relevant and Lower priority. These labels map the technical risk signals to a practical review order.
| Risk level | Score range | How to read it |
|---|---|---|
| Critical | 90–100 | Review first. These items usually combine several risk signals or have very strong indicators. |
| High | 60–89 | Review soon. These items have clear signals that should be checked. |
| Medium | 30–59 | Review when relevant. These items may need attention depending on business context. |
| Low | 0–29 | Usually lower priority, but still part of the complete access picture. |
Remember
A Critical or High score does not automatically mean that access is wrong. Some access may be intentional, approved and necessary. Review the context before changing permissions.
Analyzer views
The left navigation menu groups Analyzer into views for overview, access risk, users and groups, and raw data. Each view is limited to the loaded scan result.
Navigation menu
The navigation menu is the fastest way to move between summary, risk, user, group and data views.
- Overview: Dashboard and Findings.
- Access risk: Top Risk paths, Path analysis and Permission combinations.
- Users and groups: Users/principals, User access, Groups, Group members, Group access and Group access chains.
- Data: Raw data.
| View | Use it for |
|---|---|
| Dashboard | Quick overview of the loaded scan result size, split KPI values, risk distribution, findings by severity, object types, keyword rules, dashboard drilldowns and important access signals. |
| Findings | Action-oriented list of items in the loaded scan result that should be reviewed or documented. |
| Top Risk paths | Files, folders and other scanned objects in the loaded scan result, prioritized by risk score and risk indicators. |
| Path analysis | Review of paths, object types and path-level access information within the loaded scan result. |
| Permission combinations | Permission patterns that repeat across the report. Useful for finding similar access setups. |
| Users/principals | Overview of identities that appear in the loaded scan result, including users, groups, guests and sharing-link identities. This view can also be opened from the External and guest principals dashboard tile. |
| User access | Choose a user or principal and see matching files and folders within the loaded scan result. |
| Groups | Review groups found in the loaded scan result. |
| Group members | Review member information when available in the report. |
| Group access | Choose a group and see files and folders the group can access within the loaded scan result. |
| Group access chains | Review how group-based access is connected when chain information is available in the loaded scan result. |
| Keyword rules dialog | Review the keyword rules used for dashboard counts and keyword-related findings. It can be opened from the Keyword rules dashboard tile. |
| Raw data | Detailed source rows, Object Type, RootGroupType and Analyzer-derived fields for validation or deeper analysis. |
Users, groups and access
Access in SharePoint is often assigned through groups, direct permissions and sharing links. Use the user and group views to understand how access reaches a file or folder inside the scanned area before deciding what to change.
User access
Select a user or principal to list the files and folders that match that identity in the loaded scan result. This is useful when you need to answer “what can this user access in this scanned area?”
- Search for a user, guest or external identity.
- Review the files and folders connected to that identity.
- Check whether access is direct, group-based or link-based when the fields are available.
Group access
Select a group to list the files and folders the group has access to within the loaded scan result. This is useful when access is mainly assigned through SharePoint groups or Entra groups.
- Start with a group that appears in a risky path or finding.
- Check where the group appears across the loaded scan result.
- Use Group members when membership information is available and relevant.
Search, sort, rows and export
Most Analyzer views are designed to be filtered, sorted and exported. This makes it easier to move from a detailed scan result to a practical follow-up list.
Search inside a view
Use the search field to narrow down the rows shown. This can also be used to find specific object types, such as Site, Subsite, Channel or Pages, when the view includes the Object Type field.
Sort columns
Click a column header to sort the table. Click again to reverse the order.
Control page size
Use the Rows selector to control how many rows are visible on the current page.
Export current view
Exports the current view with active search, selected dropdown and table sorting. The export is not limited to only the rows visible on the current page.
Export options
| Export | What it contains | When to use it |
|---|---|---|
| Export current view | The rows from the selected view in the loaded scan result, using the current search, dropdown selection and sorting. | Use this for practical review lists, audit follow-up or cleanup tasks for the scanned area. |
| Export original CSV | The original source CSV exactly as it was loaded. | Use this when you need to keep, resend or archive the unchanged source report for the scanned area. |
| Raw data → Export current view | The Raw data view with Analyzer-derived fields, filtering and sorting. | Use this for validation or deeper technical analysis. |
Common columns and terms
The exact columns vary by view. These are the most important fields to understand when reviewing an Analyzer result.
| Column or term | Meaning |
|---|---|
| RiskLevel | The risk category: Critical, High, Medium or Low. |
| RiskScore | The calculated score used to prioritize review. |
| Path | The file or folder path from the loaded BSE scan result. |
| Document Library | The document library associated with the loaded row or scan context when this value is available in the scan result. |
| Full Path | The full path display used to show the document library and item path together when Analyzer has enough source information to build it. |
| Object Type | The SharePoint object classification included in the BSE scan result when available. The Dashboard can summarize object types such as Site, Subsite, Channel and Pages. Use this field to separate different object classes when reviewing, filtering or exporting data. |
| RootGroupType | Group classification information from the source scan when available. This can help explain how group-based access is represented and supports group access chain analysis. |
| Report scope | The selected SharePoint area that was scanned in BSE. Analyzer does not expand this to other areas, sites or the tenant. |
| File scan date | The timestamp shown for when the loaded BSE scan result was created. |
| Rule set | The active analysis rule set used by Analyzer for the loaded result. |
| Domains | The configured internal domains used to distinguish internal identities from external users and guests. |
| Principal | A user, group, guest, sharing link or another identity that appears in the loaded scan result. |
| Role | The permission role shown in the source report, for example read, edit, contribute or owner-level access depending on the SharePoint setup. |
| IsExternal | Indicates that the identity appears to be outside the internal domain rules used by Analyzer. |
| IsGuest | Indicates that the identity appears to be a guest identity, for example when guest or #EXT# is detected for the same principal. |
| IsDirectPermission | Indicates that access appears to be assigned directly rather than only through inherited group access. |
| IsLinkPermission | Indicates that access appears to come from a sharing link. |
| PermissionCombinationId | Identifies a permission combination used in the source report. This helps compare similar access patterns. |
| KeywordHitCount | The number of keyword matches found in the file or folder path. |
| KeywordMatches | The keyword terms that matched the file or folder path. This does not mean that file content was scanned. |
| KeywordScore | The score contribution from keyword matches. |
| KeywordRuleIds | Traceability for the keyword rules that matched. This is mainly useful for support and audit follow-up. |
Practical tips
Start with priority views
Begin with Dashboard, Top Risk paths and Findings for the loaded scan result before using Raw data.
Review context before changing access
A high score means “review first”, not automatically “remove access”. Check business context and ownership.
Use user and group views
When a path looks risky, identify which users and groups are involved before deciding what to change.
Filter before exporting
Search and sort before exporting so the export becomes a focused follow-up list.
Keep the original report
Export or archive the original CSV if the review needs traceability.
Re-scan the area when needed
Configure or run a new scan for the same selected area if permissions have changed since the report was created.
Important
Analyzer helps identify and prioritize access risk inside the loaded scan result. Permission changes must still be planned and performed in the relevant Microsoft 365 or SharePoint administration tools.
Frequently asked questions
Does Analyzer change SharePoint permissions?
Does Analyzer read file contents?
Can Analyzer show a whole SharePoint installation or tenant?
How do I review several SharePoint areas or sites?
Why does a file or folder have a high score?
Does Critical or High mean the access is wrong?
Why do I see both external users and guests?
#EXT# are detected. An external identity is not always a guest.What does Object Type mean?
What is Group access chains?
What should I export?
Why does the result not match current SharePoint permissions?
Need help interpreting a scan result?
If you have questions about BSE Analyzer or need help interpreting a scan result, contact Binera or request a review session.
