Home / Case studies / Identity and access
Identity and access

Staff access to resources without opening up the agency’s data

Overlapping groups and sites were consolidated by purpose, and care staff, most of them guests, get their own site without any path to office data.

Status
Running in production
Result
14 groups became 9 plus one distribution list, each with a stated purpose.

Running in production

Deployed, with the guest rollout continuing: an invitation is not access until it has been accepted.

The situation

Most care staff use personal email addresses, so they are guest accounts. Over time the agency’s Microsoft 365 tenant had accumulated overlapping groups and sites, and nobody could say with confidence who actually had access to what.

The cost of leaving it alone

Access nobody can explain is access nobody can defend. For a HIPAA risk analysis, “who can see this?” has to have an answer.

What we built

Groups were consolidated by purpose: operations, clinical, care staff, office and HR. A care-staff team and resource site were set up with guest invitations driven from a reviewed roster. Access is verified by effective permissions and by whether each guest has actually accepted, never by group membership alone.

Microsoft 365 groups, Teams, SharePointEntra guest accountsMicrosoft Graph and PowerShell

Why AI, or why not

No. This is plain configuration and scripting. It is also the foundation that makes every AI deployment on top of it safe to approve.

The results

14 → 9+1
groups consolidated into nine plus one distribution list, each with a written purpose
14
guest invitations sent, with no failures
1 → 16
members in the care-staff group once it was rebuilt from the reviewed roster
0
care-staff accounts in the group that holds payroll, invoices, the audit ledger and phone data

How PHI was protected

  • Separate sites per audience, and care staff are never added to the operations group.
  • The credential board is visible to office staff only.
  • Access is checked with effective permissions, not site user lists.

What we would tell you to skip

Deleting a group deletes everything it owns. And permission is not redemption: a guest who never accepted the invitation has no working access, whatever the roster says.

Reusable for

Agencies whose field staff are mostly guest accounts.

Tell us the one workflow that costs you the most time.

A working session is free of obligation: we look at one process, tell you plainly whether AI belongs in it, and what keeping it inside HIPAA would take.

Book a working session