TimeOpera Security & Permissions | Least-Privilege Microsoft 365 Access
Your timesheets, projects, approvals, reports, and invoice information remain in the SharePoint site selected by your organization. TimeOpera uses Microsoft Entra ID for sign-in and accesses only the Microsoft 365 resources needed to provide the service.
Security at a glance
TimeOpera is aligned to standard enterprise security controls and utilizes native Microsoft boundaries.
Customer-controlled storage
Business records stay in the selected SharePoint workspace.
Selected-site access
TimeOpera is approved for the configured SharePoint site, not every site.
Read-only AI assistant
TimeOpera Assistant cannot create, edit, approve, submit, send, or delete records.
Microsoft 365 sign-in
Users sign in with their existing Microsoft Entra ID account.
Mailbox-scoped email
Workflow emails are restricted to the approved notification mailbox.
Tenant isolation
Customer tenants, sites, users, roles, and records are validated independently.
Your data stays in your Microsoft 365 tenant
TimeOpera is built to give corporate administrators full sovereignty over business records. Review the data breakdown below.
Stored in SharePoint Workspace
TimeOpera stores your main business information in the TimeOpera SharePoint workspace selected during onboarding:
- Timesheets and worklogs
- Customers and projects
- Sections and tasks
- Approval information
- Reports
- Invoice and billing records
- TimeOpera settings stored in the workspace
TimeOpera does not create a separate external database containing copies of your real timesheets, projects, notes, approvals, or invoices.
Required Service Metadata
To authenticate users and validate licensing, the SaaS service stores limited administrative metadata:
- Microsoft tenant ID
- Company and administrator details
- Approved SharePoint site URL
- Onboarding and provisioning status
- Application version information
- Licensing information
- Notification mailbox configuration
Your real TimeOpera business records stay in the SharePoint workspace chosen by your organization. TimeOpera stores only the limited operational information needed to run and support the service.
For Microsoft 365 administrators
Review the narrow scope of Graph and Exchange Online permissions configured for your organization.
Access to one selected SharePoint site
TimeOpera uses the Microsoft Graph Sites.Selected permission. This means TimeOpera is not automatically given access to every SharePoint site in your organization.
During onboarding, your administrator selects and approves the specific SharePoint site where TimeOpera will operate. TimeOpera uses this site to create and manage the lists, pages, and records required by the application.
Secure notification mailbox
TimeOpera sends automated notifications (timesheet reminders, overdue approvals). Your organization selects the mailbox that TimeOpera is allowed to use.
TimeOpera uses Exchange Online Application RBAC to restrict email sending specifically to that approved mailbox:
timeopera@yourcompany.com
TimeOpera is not given permission to send as every user in your tenant. The sender address is read from trusted configuration.
User directory access
TimeOpera uses Microsoft Graph User.Read.All to identify active users who can be added to the workspace. It reads basic directory attributes:
- User name & Email address
- Microsoft Entra object ID
- Account status (Active/Disabled)
User.Read.All does not allow TimeOpera to read users’ email messages, calendars, chats, passwords, or OneDrive files.
For TimeOpera users
Sign in with your Microsoft 365 account
TimeOpera uses Microsoft Entra ID for authentication. Users do not need separate credentials. Your Microsoft 365 identity determines your role permissions and project assignments. Access rules are enforced on the backend.
| Role | Typical access |
|---|---|
| Timesheet User | Create and manage their own permitted time entries, view assigned projects, submit timesheets, and view their own reports and approval status. |
| Project Manager | View and manage assigned projects, review relevant project timesheets, approve or reject timesheets where permitted, and view project-related reports. |
| Finance Admin | View customer and project information, view timesheets according to the Finance Admin access model, access reports, and create or manage invoices. |
| Administrator | Manage customers, projects, roles, reports, application settings, and TimeOpera configuration. |
Project-based access: A user's access can also depend on whether they are assigned as a Project Member, Project Manager, Project Coordinator, or Timesheet Approver. A user cannot log time against projects they are not assigned to.
TimeOpera Assistant security
TimeOpera Assistant works inside Microsoft 365 Copilot and follows the same TimeOpera security rules. It is read-only, role-aware, project-aware, assignment-aware, and tenant-aware.
Assistant can help find:
- Missing timesheets
- Timesheet status
- Pending approvals
- Project & Client hours
- Team utilization statistics
- Recent worklogs
- Invoice readiness details
Assistant cannot:
- Create or edit time entries
- Submit or approve timesheets
- Create customers, projects, or invoices
- Delete records or change role access
- Bypass TimeOpera access controls
No write actions are supported by TimeOpera Assistant for security purposes.
Report a Security Concern
Help us keep TimeOpera secure. If you have discovered a vulnerability or believe you have found a security issue in our services, please disclose it to us responsibly.
Or send directly to support@timeopera.app with subject "Security Report".
Reporting Guidelines
- Include details: Description of the issue and step-by-step instructions to reproduce it.
- Attach media: Screenshots, request payloads, or sanitized technical logs if available.
- Contact info: Your name and email address so we can coordinate and keep you updated.