Access model first: intranet success is who can see what

Most intranet programs open with a homepage mockup. Colors, hero image, mega-menu. Those choices matter for adoption. They do not decide whether the intranet is safe to use in a regulated environment.

The decision that does is simpler and harder: who can see what.

If your Microsoft 365 intranet ships with a polished shell and a muddy access model, people will still find documents they should not find—or, just as often, they will see greyed-out links and learn that something sensitive exists by title alone. That is not a design quirk. It is a permission leak with a friendlier UI.

This note is about putting the access model first: Entra ID groups, role-based access, and SharePoint permission design that respects boundaries without turning collaboration into a ticket queue.

What “access model first” means

An access model is not a spreadsheet of site owners. It is a deliberate map of:

  1. Audiences — who the content is for (department, function, role, location, contractor status).

  2. Sensitivity — what must stay inside a known boundary (HR, legal, finance, operations, executive).

  3. Groups — Entra ID (Azure AD) security groups or Microsoft 365 groups that express those audiences, not ad-hoc site permissions.

  4. Inheritance — when a site or library inherits, and when it deliberately breaks inheritance for a controlled reason.

  5. Exceptions — who may grant one-off access, for how long, and where that grant is logged.

If you cannot answer those five lines before you build hubs and pages, you are decorating a system that will fight you later.

Why greyed-out links are not harmless

SharePoint and Microsoft 365 collaboration features sometimes show a person that a link or navigation item exists even when they cannot open the target. In a consumer product that might be fine. In a regulated workplace it is often not.

A greyed-out menu item teaches the workforce that a “2026 compensation review” site exists. A search snippet that respects document ACL but still surfaces a library name can do the same. The access model has to account for existence disclosure, not only open-and-read.

Practical standards we use with teams that already live in Microsoft 365:

  • Prefer navigation that only appears for people who can open the target.

  • Prefer audience targeting that is backed by real Entra groups, not wishful page design.

  • Prefer libraries that do not advertise sensitive titles in shared hub navigation.

  • Prefer search refiners and promoted results that never outrun the underlying ACL.

Permission-respecting collaboration is the product. Pretty navigation that leaks titles is not.

RBAC with Entra groups—not site-by-site folklore

Role-based access control on SharePoint Online works when roles are expressed as groups you can audit:

  • Owners — few, named, accountable for structure and membership.

  • Members — people who contribute day to day.

  • Visitors / readers — broad audiences that should consume, not edit.

  • Special roles — records, compliance, finance reviewers, or similar, when the work actually requires them.

Those roles should map to Entra groups that HR, IT, or identity already maintain when possible. Nested groups are fine when nesting is intentional and documented. Site-level sharing links that bypass the model are the usual failure mode: someone forwards a link, a guest appears, and six months later nobody can explain why.

A calm operating rule: new sites inherit the org’s group pattern. Custom permission sets are exceptions that require a named owner and a review date and not the default craft of every project team.

Regulated environments need boring clarity

In regulated and audit-sensitive landscapes, the intranet is not a second system of record for the books. It is often where people open policy, procedures, contracts, drawings, and working papers. That adjacency to systems of record is exactly why access discipline matters.

You do not need a dramatic breach narrative. You need patterns like:

  • A hub that mixes public news with a library only half the company should know about.

  • A “temporary” unique permission that outlived the project.

  • External sharing left on for convenience on a site that later held internal HR content.

  • Owners who left the company still listed as site owners.

Boring clarity beats clever exceptions. Name the groups. Name the owners. Name the review cadence.

A practical sequence before you launch

  1. Inventory audiences with business owners—not only IT. Who must not see what, and why.

  2. Define group patterns in Entra before you create hubs. Reuse existing identity groups where they already track role or department.

  3. Decide inheritance defaults for communication sites, team sites, and document libraries.

  4. Write the exception path — who may break inheritance, how long, and how it is reviewed.

  5. Test with real accounts — including a user who should not see sensitive navigation—not only admins.

  6. Then apply branding, news web parts, and adoption campaigns.

Adoption after a leaky access model is not a win. It is distribution of the problem.

What this is not

This is not a pitch to rip and replace Microsoft 365. It is not a call to invent a fourth practice or a SharePoint SI shop. It is not résumé language or named individuals. It is the operating choice we see when intranet modernization is done carefully: access first, then findability, then optional AI on a foundation people already trust.

McCloy Data’s Content & Process and AI & Engineering work sits next to OpenText and SAP landscapes that already open work in Microsoft 365. The same stewardship applies: permission-respecting collaboration, groups you can explain, and a bench that has implemented this pattern in real tenant work—not theater.

A short checklist for sponsors

  • Can every sensitive site answer “which Entra groups grant access” without opening SharePoint UI archaeology?

  • Do greyed-out or targeted links still reveal titles to people outside the audience?

  • Are sharing links and guest access on by policy, or by accident?

  • Is there a quarterly access review with named owners—not a distribution list?

  • Would you defend the model to audit as written, or only as practiced in hallway knowledge?

If those answers are soft, finish the access model before you celebrate the homepage.

If you want help finishing the model

McCloy Data works with organizations that already run Microsoft 365 and need an intranet that is usable and permission-respecting and especially where content sits next to governed records and ERP landscapes. If that is the work in front of you, we would welcome a brief conversation.

Jason

I talk about hope and faith. I like to be with family, friends, laugh, and live. Jesus is King. ✝️

https://www.mccloyhall.com
Next
Next

Own the exceptions you actually see after go-live on OpenText VIM on S/4HANA