Running in production
Deployed, with the guest rollout continuing: an invitation is not access until it has been accepted.
The situation
Most care staff use personal email addresses, so they are guest accounts. Over time the agency’s Microsoft 365 tenant had accumulated overlapping groups and sites, and nobody could say with confidence who actually had access to what.
The cost of leaving it alone
Access nobody can explain is access nobody can defend. For a HIPAA risk analysis, “who can see this?” has to have an answer.
What we built
Groups were consolidated by purpose: operations, clinical, care staff, office and HR. A care-staff team and resource site were set up with guest invitations driven from a reviewed roster. Access is verified by effective permissions and by whether each guest has actually accepted, never by group membership alone.
Microsoft 365 groups, Teams, SharePointEntra guest accountsMicrosoft Graph and PowerShell
Why AI, or why not
No. This is plain configuration and scripting. It is also the foundation that makes every AI deployment on top of it safe to approve.
The results
How PHI was protected
- Separate sites per audience, and care staff are never added to the operations group.
- The credential board is visible to office staff only.
- Access is checked with effective permissions, not site user lists.
What we would tell you to skip
Deleting a group deletes everything it owns. And permission is not redemption: a guest who never accepted the invitation has no working access, whatever the roster says.
Reusable for
Agencies whose field staff are mostly guest accounts.