Back to blog

Manage Permissions in Microsoft Teams and SharePoint — Without Permission Chaos

Microsoft Teams only ships with two roles — Owner and Member — forcing IT into manual SharePoint configuration after every workspace. Access Profiles introduces custom roles linked to real SharePoint permission groups, applied automatically from templates.

Feb 18, 2026 7 min read

Introduction

Valprovia Governance introduces Access Profiles: custom roles defined in workspace templates and automatically linked to SharePoint permission groups. Project managers select roles from dropdowns when adding members, with permissions configured automatically in the background.

What Are Access Profiles — and Why Now?

Organizations have long struggled with Microsoft Teams' limitation of only two roles — Owner and Member. External guests receive implicit Member status without distinct role categories. This creates practical challenges: project managers need different permissions than team members, and external partners need different access than steering committees.

Previously, the solution required manual SharePoint configuration after each workspace creation. Access Profiles now provides a better approach by enabling custom roles linked to SharePoint permission groups. When someone adds a person and assigns a role, permissions are set automatically.

The Problem: Why Project Permissions in Microsoft 365 Lead to Chaos

Typical Scenario

A consulting project requires:

  • Project manager: full access and approval authority
  • Team members: document editing without structural changes
  • Controlling officer: read-only access to financial documents
  • External consultant: access only to shared project documents

The Dilemma

Microsoft Teams recognizes only Owner or Member roles, forcing administrators into two problematic choices:

  1. Assign everyone as Members with identical permissions (security risk)
  2. Manually configure SharePoint groups after each workspace creation (error-prone, unscalable)

Organizational Scale

Organizations managing dozens or hundreds of parallel projects face compounded challenges:

  • Inconsistent permissions across projects
  • Forgotten permission assignments
  • Security gaps
  • IT teams overwhelmed with permission requests

This problem extends to pure SharePoint workspaces, where the absence of consistent SharePoint Governance creates sprawl: giving users extensive management permissions leads to uncontrolled structural changes, while restricting permissions creates bottlenecks requiring IT intervention for every modification.

How Does Access Profiles Solve This Problem?

Configuration occurs once in the workspace template. Every new workspace automatically inherits the defined roles and permissions.

Step 1: Define Project Roles

Administrators define roles needed for daily project work. Unlike Microsoft Teams' implicit guest grouping, Valprovia Governance explicitly distinguishes three user types:

Owners: Example: "Project Manager" (full access), "Deputy" (backup role)

Members: Example: "Team Member" (editing rights), "Controlling Reader" (read-only access)

Guests: Example: "External Partner" (restricted shared area access)

This explicit separation ensures external users receive dedicated roles with appropriate permissions rather than blanket Member rights.

Custom role configuration for Owners, Members and Guests in a Valprovia Governance workspace template
Custom roles defined per user type inside the workspace template.
Dialog for creating a new Owner role with name and description fields
Creating a new role takes a name and a description — no code, no SharePoint groups yet.

Step 2: Configure Behavior

Two optional settings control user workflows:

  • Enforce role selection: Ensures every project member receives a role (essential for regulated environments and audit compliance)
  • Allow multiple selection: Enables assigning multiple roles to individuals (useful when someone holds dual responsibilities, such as team member and controlling officer)

Step 3: Link Roles to SharePoint Permissions

Each role is assigned to a SharePoint group defining folder and library access. If groups don't exist during workspace creation, they're automatically generated.

Role-to-SharePoint-group mapping for Owners, Members and Guests
Each role is mapped to a SharePoint permission group — the link between business role and real access.
Inline editing of a role assignment with dropdown and SharePoint group input field
Inline editing of a single role-to-group assignment.
Full overview of workspace template with all role-based permission assignments
The completed template — every role tied to a real SharePoint permission group.

What Do Project Managers and End Users Experience?

Project Manager Workflow

Instead of filing IT tickets and waiting for permission setup, project managers:

  1. Open the workspace
  2. Add a new team member
  3. Select the appropriate role from a dropdown
  4. SharePoint permissions are set automatically
Project manager selecting a permission role from a dropdown when adding a workspace member
The project manager picks a role from a dropdown — no SharePoint config required.

Visual Experience

  • Role selection appears as a tag next to the username
  • Roles can be changed or confirmed with a single click
  • Confirmation message confirms automatic background processing
  • No additional action required from the project manager
Assigned role displayed as a tag next to the username in the workspace
The assigned role shows up as a tag right next to the username.
Workspace owners with assigned roles Project Manager and Partner before submitting the request
Workspace owners with their assigned roles, ready to submit.
Confirmation message after automatic permission update in the workspace
Confirmation that permissions were updated automatically in the background.

Roles Are Not Labels — They Control Real Permissions

Key Distinction

Many governance solutions allow assigning role tags or labels that remain purely visual — labeling users without affecting actual SharePoint permissions. Valprovia Governance links each role directly to a SharePoint permission group, making labels into real, functional permissions that sync automatically with every change.

Concrete Example

Starting Point: Two users have different roles (Partner and Project Manager), each linked to different SharePoint permission groups.

Two workspace users with different roles: Partner and Project Manager
Two users in the same workspace — different roles, different permissions.

Project Manager Access: Visible folders include:

  • 01_Project Calculation
  • 02_Controlling
  • 03_Development
SharePoint document library showing three project folders visible to the Project Manager role
Project Manager sees all three project folders.

Role Change to Partner: When the role changes via dropdown, Valprovia Governance automatically removes the user from the old SharePoint group and adds them to the new one.

Role change from Project Manager to Partner via the dropdown in the workspace
A single dropdown change rewires SharePoint permissions automatically.

Partner Access After Change: Only visible folder:

  • 03_Development
SharePoint document library showing only one visible folder after role change to Partner
After the role change, only the Development folder remains visible.

The folders 01_Project Calculation and 02_Controlling become invisible because the "Partner" SharePoint permission group lacks access to them.

What Valprovia Governance Focuses On

Valprovia Governance operates as a preventive governance solution, addressing problems before they occur. Security and permission management form its core — not just at the workspace level but particularly within workspaces, addressing who can do what and why. To verify these permissions stay correct over time, pair it with recurring permissions analytics and access-review campaigns.

Access Profiles embodies this approach:

  • Project managers retain permission control without IT tickets
  • IT administrators benefit from consistent structures and automatic synchronization
  • Compliance officers receive enforced role assignments and automatic protection against uncontrolled changes
  • End users experience simple dropdown selection with automatic correct permissions

Frequently asked questions about Access Profiles

  • How do Access Profiles differ from native Microsoft Teams roles?

    Microsoft Teams offers two fixed roles: Owner and Member, with guests treated as implicit Members. Valprovia Governance extends this to three explicit user types — Owners, Members, and Guests — enabling unlimited custom roles per type with individual SharePoint permissions. This allows distinguishing "Project Manager" with full access from "Controlling Reader" with read-only access, plus dedicated external guest roles.

  • How do organizations with many parallel projects benefit?

    Roles are defined once per template. Every new project created with that template automatically inherits identical permission structures. This eliminates manual SharePoint configuration for each project and ensures organizational consistency.

  • Can external partners and consultants get their own roles?

    Yes. Roles are definable for all three user types, including guests. An external consulting partner can have different permissions than an external auditor, with each accessing only designated project areas.

  • Is Access Profiles suitable for regulated industries with audit requirements?

    Yes. The "Enforce role selection" setting ensures every project member has a documented role assignment. This creates traceable permission structures serving as audit evidence.

Conclusion

Project permissions in Microsoft 365 become manageable through Access Profiles. It replaces manual SharePoint configuration with one-time automated processes. Project managers manage permissions independently through simple dropdowns, IT administrators recover time, and compliance officers gain required traceability.

The essential difference: roles become more than labels, controlling actual SharePoint permissions automatically with every assignment, change, and removal. Once configured in templates, every new project benefits from consistent permission structures.

See Valprovia live
in 30 minutes

Your use cases, one demo, one pricing proposal. No sales pressure - directly from the Valprovia team.