A team can check this by comparing the access permission on each connector with a written statement of who should have access and what content should be available. For the connector controls described in the documentation, this review can be performed in the admin center through each connector’s connection details pane.
Define the intended use first
Before reviewing permissions, the team should identify:
- The users or groups intended to use the connector.
- The content that needs to be available through it.
- Whether access is intended for a limited group or a broader audience.
- Any case in which broader access is necessary.
Without a defined baseline, the team cannot determine whether a setting is appropriately narrow or too broad.
Review every connector
The team can open the connection details pane in the admin center and review and validate the configured access permission for each connector. It should compare the actual setting with the intended-use statement rather than assuming that similar connectors have equivalent permissions.
Broad access requires particular attention. The cited documentation warns that incorrect permission settings, including granting access to Everyone, can lead to oversharing of sensitive content. If the intended use covers only a defined group, an Everyone setting is broader than that use and should be treated as a mismatch requiring review.
Resolve and record mismatches
For each connector, the team can record:
- The intended access group.
- The configured access setting.
- Whether the setting matches the intended use.
- Any exception and the internal approval supporting it.
A broader setting should go through the team’s applicable access-change or approval process. The documentation confirms where permissions can be reviewed, but it does not define the organization’s internal approval requirements.
What the team must still confirm
The team must determine the appropriate user group, content boundary, exceptions, and approval rules for its own environment. The documentation does not provide a universal permission standard.
A connector is not validated merely because its permission page has been checked. The configured audience must still be demonstrably appropriate for the connector’s stated purpose, with any broader access consciously approved.