AegentraNew Zealand

Harden / New Zealand

Data protection and access

Aegentra reviews information access, sharing and protection across the agreed Microsoft 365 services. We connect business use with permissions, ownership and control options rather than applying the same restriction to every file.

On this page

Start with the boundary

Define the work that is needed.

For organisations concerned about oversharing, unclear ownership, sensitive information or access that persists after roles change.

  • Information locations and ownership
  • Sharing links, guest access and permissions
  • Protection and retention options within available licences
  • Access-review and operational responsibilities

Keep the responsibilities distinct

Technical controls do not by themselves establish privacy-law compliance or complete a records-retention programme. Legal, business and security requirements need to be agreed before destructive or restrictive changes.

What the engagement can produce

Useful outputs, agreed in advance.

  • A scoped view of information-access exposure
  • Prioritised protection and permissions changes
  • Business-impact and licence dependencies
  • Evidence and handover guidance for agreed changes

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How we work

From evidence to a practical next step.

Agree

Confirm the objective, authority, systems, criteria, access and exclusions. Establish how information will be shared and handled.

Examine

Gather the records and context required by the scope. Distinguish what evidence supports from what is still uncertain.

Act or report

Carry out the agreed consulting, audit, assessment or implementation task. Obtain approval before operational changes.

Verify and hand over

Document outcomes, limitations, owners and follow-up. Retesting or ongoing work is included only when expressly scoped.

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

An illustrative starting point

What a useful first decision looks like.

Fictional example to explain the service, not a New Zealand client case study or a promised outcome.

A project site has external guests who no longer work on the engagement. Removing all sharing could disrupt current work; review ownership and legitimate access before applying a targeted change.

Questions for the first discussion

  • What information needs protection and where is it held?
  • Who owns access decisions?
  • Which external users and collaboration workflows must continue?

Before you begin

Your questions, answered.

Can you guarantee there will be no data loss?

No. A scoped review and controlled improvements can address identified risks, but no consultancy can guarantee zero loss or exposure. Recovery arrangements, user behaviour, integrations and ongoing administration remain important.

What can be included in data protection and access?

The agreed scope can include information locations and ownership; sharing links, guest access and permissions; protection and retention options within available licences; access-review and operational responsibilities. We confirm the exact deliverables and exclusions before work begins, rather than treating every organisation as the same project.

How much does this service cost?

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How do you deliver the work in New Zealand?

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

What should we provide before a proposal?

Bring answers to these starting questions: What information needs protection and where is it held? Who owns access decisions? Which external users and collaboration workflows must continue? A short initial discussion should establish the boundary and next evidence needed. Do not email secrets or detailed personal records before secure handling has been agreed.

Reference points

Check the underlying guidance.

Page prepared and source references checked . References explain the relevant standard or technology; they are not endorsements of Aegentra.

Discuss your requirement

Start with your business.

Start with the requirement, the systems involved and the outcome you need. Please do not send passwords, sensitive records or unrestricted tenant access in an initial enquiry.