GUIDES · POWER AUTOMATE

Suggest who should have access to every new SharePoint file

A file is added to a library. Your flow sends its location to a StayCharted model trained on your own permission history, and gets back the groups that would normally have access, such as Finance Owners:Full Control; Payroll Team:Edit, and whether a person should check. You decide what is applied.

What you get

  • Suggestions from your own decisions. The model learns from the access your admins have already granted. There are no classification rules to write.
  • A person checks anything unusual. Each answer says whether it needs review. Your flow can send those, and anything that would widen access, for approval.
  • Nothing changes on its own. StayCharted doesn’t connect to your tenant or change permissions. Your flow and your approvers do.
Purview labels how sensitive a file is. This suggests who should be able to open it. They work side by side.

Before you start

  • A StayCharted plan with API access (Essentials or Business), and an API key from Settings → API keys.
  • Permission to create a Power Automate cloud flow, and a license that includes the HTTP action. Your Microsoft administrator can confirm both.
  • A SharePoint admin who can export permissions for the sites you want to cover.

This flow has not yet been verified end to end in a Microsoft tenant. Test the trigger’s file URL and request body in your own tenant before using it. See Microsoft’s SharePoint connector reference and Power Automate licensing.

1. Train on your permission history

  1. Export the permissions for one site or department: the PnP PowerShell permission report, SharePoint's sharing report, or Microsoft Graph JSON.
  2. Upload the export as it is. StayCharted combines it into one row per file with the groups that can open it, and leaves out Limited Access, site administrators and people who came in through a sharing link.
  3. Train, check the report, and publish. The report shows, for each group, how often the model added it wrongly or missed it.

Start with one department and see how often the model agrees with the access your team already chose.

2. Start a flow when a file is added

In Power Automate, create an automated cloud flow with SharePoint's When a file is created (properties only) trigger, and choose the site and library.

3. Ask the model

Add the HTTP action:

Field Value
Method POST
URI https://amt.staycharted.com/api/v1/models/<MODEL_ID>/classify
Headers Authorization: Bearer <YOUR_API_KEY>, Content-Type: application/json
Body { "input": { "URL": "@{triggerOutputs()?['body/{Link}']}" } }

Send the file's Link to item. The model reads the site, folder and file name from it the same way it read your export. Keep the key in your organization's approved secret store, and turn on Secure inputs and Secure outputs.

The answer:

{
  "labels": ["Finance Owners:Full Control", "Payroll Team:Edit"],
  "confidence": 0.92,
  "needsReview": false
}

Confirm that Link to item contains the file’s full URL, not a form link. If needed, use the site address plus Full Path. Check the dynamic-content expression against your trigger’s actual output. The JSON above illustrates the response shape; the groups and confidence will depend on your model.

If the request fails or required answer fields are missing, record an error and send the item for review. Do not treat a missing answer as approved access.

4. Record the suggestion and route review

Write the suggestion to the file’s properties, or to an Access suggestions list with the file’s link, labels, confidence and needsReview.

Keep an administrator-approved baseline of groups and permission levels for each library in a list or flow variable. Compare both the groups and the permission levels: changing an existing group from Read to Edit also widens access. If the baseline is missing or a permission cannot be compared, send it for review.

Add a Condition: when needsReview is true, or the suggestion would widen access, start Start and wait for an approval, assigned to the site owner. Record other suggestions for the owner to apply; this example does not change permissions automatically.

Answers below the model’s review cutoff also appear in StayCharted’s Review Queue on Essentials and Business. Reviewing a model answer there is separate from authorizing access in SharePoint. Keep the site owner’s approval as the access decision.

5. Apply what's approved

When an approval comes back approved, the site owner applies the access in Manage access, or an admin-built step applies it for them. Rejected or changed suggestions are worth keeping: add them to the next export, retrain, and the model learns the correction.

Common questions

Does StayCharted read the file’s contents?

No. In this flow, it reads the file’s location and name supplied in the API request. It does not fetch the file’s contents.

Does it change permissions?

No. It suggests; your flow and your approvers decide.

How is this different from Purview?

Purview’s sensitivity labels say how sensitive a file is and apply the protection you set. StayCharted suggests which of your groups should have access, learned from your own past decisions.

What if a file is unlike anything before?

The model may return lower confidence and flag the answer for review. Confidence is not a guarantee: unfamiliar files can still receive confident suggestions. Route anything that would widen access for approval regardless of confidence.

Which plans?

Essentials and Business include the API. Your Microsoft license must also cover the HTTP action.

Full API reference → · Train on your permission export → · Security and your data →