Product AI Assistant Onboarding Training Pricing Security
Start Onboarding →
Book a Demo
Security & Trust

TimeOpera Security & Permissions | Least-Privilege Microsoft 365 Access

Your timesheets, projects, approvals, reports, and invoice information remain in the SharePoint site selected by your organization. TimeOpera uses Microsoft Entra ID for sign-in and accesses only the Microsoft 365 resources needed to provide the service.

Overview

Security at a glance

TimeOpera is aligned to standard enterprise security controls and utilizes native Microsoft boundaries.

Customer-controlled storage

Business records stay in the selected SharePoint workspace.

Selected-site access

TimeOpera is approved for the configured SharePoint site, not every site.

Read-only AI assistant

TimeOpera Assistant cannot create, edit, approve, submit, send, or delete records.

Microsoft 365 sign-in

Users sign in with their existing Microsoft Entra ID account.

Mailbox-scoped email

Workflow emails are restricted to the approved notification mailbox.

Tenant isolation

Customer tenants, sites, users, roles, and records are validated independently.

Data Sovereignty

Your data stays in your Microsoft 365 tenant

TimeOpera is built to give corporate administrators full sovereignty over business records. Review the data breakdown below.

Stored in SharePoint Workspace

TimeOpera stores your main business information in the TimeOpera SharePoint workspace selected during onboarding:

  • Timesheets and worklogs
  • Customers and projects
  • Sections and tasks
  • Approval information
  • Reports
  • Invoice and billing records
  • TimeOpera settings stored in the workspace
SaaS Database Excluded:
TimeOpera does not create a separate external database containing copies of your real timesheets, projects, notes, approvals, or invoices.

Required Service Metadata

To authenticate users and validate licensing, the SaaS service stores limited administrative metadata:

  • Microsoft tenant ID
  • Company and administrator details
  • Approved SharePoint site URL
  • Onboarding and provisioning status
  • Application version information
  • Licensing information
  • Notification mailbox configuration
Simple Message:
Your real TimeOpera business records stay in the SharePoint workspace chosen by your organization. TimeOpera stores only the limited operational information needed to run and support the service.
Tenant Management

For Microsoft 365 administrators

Review the narrow scope of Graph and Exchange Online permissions configured for your organization.

Access to one selected SharePoint site

TimeOpera uses the Microsoft Graph Sites.Selected permission. This means TimeOpera is not automatically given access to every SharePoint site in your organization.

During onboarding, your administrator selects and approves the specific SharePoint site where TimeOpera will operate. TimeOpera uses this site to create and manage the lists, pages, and records required by the application.

Secure notification mailbox

TimeOpera sends automated notifications (timesheet reminders, overdue approvals). Your organization selects the mailbox that TimeOpera is allowed to use.

TimeOpera uses Exchange Online Application RBAC to restrict email sending specifically to that approved mailbox:

Example approved mailbox:
timeopera@yourcompany.com

TimeOpera is not given permission to send as every user in your tenant. The sender address is read from trusted configuration.

User directory access

TimeOpera uses Microsoft Graph User.Read.All to identify active users who can be added to the workspace. It reads basic directory attributes:

  • User name & Email address
  • Microsoft Entra object ID
  • Account status (Active/Disabled)
What this permission does not provide:
User.Read.All does not allow TimeOpera to read users’ email messages, calendars, chats, passwords, or OneDrive files.
Role-Based Authorization

For TimeOpera users

Sign in with your Microsoft 365 account

TimeOpera uses Microsoft Entra ID for authentication. Users do not need separate credentials. Your Microsoft 365 identity determines your role permissions and project assignments. Access rules are enforced on the backend.

Role Typical access
Timesheet User Create and manage their own permitted time entries, view assigned projects, submit timesheets, and view their own reports and approval status.
Project Manager View and manage assigned projects, review relevant project timesheets, approve or reject timesheets where permitted, and view project-related reports.
Finance Admin View customer and project information, view timesheets according to the Finance Admin access model, access reports, and create or manage invoices.
Administrator Manage customers, projects, roles, reports, application settings, and TimeOpera configuration.

Project-based access: A user's access can also depend on whether they are assigned as a Project Member, Project Manager, Project Coordinator, or Timesheet Approver. A user cannot log time against projects they are not assigned to.

AI Boundary

TimeOpera Assistant security

TimeOpera Assistant works inside Microsoft 365 Copilot and follows the same TimeOpera security rules. It is read-only, role-aware, project-aware, assignment-aware, and tenant-aware.

Assistant can help find:

  • Missing timesheets
  • Timesheet status
  • Pending approvals
  • Project & Client hours
  • Team utilization statistics
  • Recent worklogs
  • Invoice readiness details

Assistant cannot:

  • Create or edit time entries
  • Submit or approve timesheets
  • Create customers, projects, or invoices
  • Delete records or change role access
  • Bypass TimeOpera access controls
Security rule:
No write actions are supported by TimeOpera Assistant for security purposes.
Common Queries

Frequently asked questions

Everything you need to know about TimeOpera security, data residency, and permissions.

Contact Support
No. TimeOpera is granted access only to the selected TimeOpera SharePoint workspace site.
Timesheets and other TimeOpera business records are stored in the configured SharePoint workspace inside your Microsoft 365 tenant.
TimeOpera does not maintain a separate external database containing copies of your real timesheets, projects, approvals, notes, or invoice records. Limited operational information is stored separately to support onboarding, licensing, configuration, and service operation.
It is used to identify active Microsoft Entra users and synchronize the names, email addresses, user IDs, and account status needed for TimeOpera roles. It is not used to read emails, files, chats, calendars, or passwords.
No. TimeOpera’s supported email configuration restricts sending to the notification mailbox approved by your organization.
Not currently. TimeOpera will not claim a certification it does not hold.
Responsible Disclosure

Report a Security Concern

Help us keep TimeOpera secure. If you have discovered a vulnerability or believe you have found a security issue in our services, please disclose it to us responsibly.

Email Security Report

Or send directly to support@timeopera.app with subject "Security Report".

Reporting Guidelines

  • Include details: Description of the issue and step-by-step instructions to reproduce it.
  • Attach media: Screenshots, request payloads, or sanitized technical logs if available.
  • Contact info: Your name and email address so we can coordinate and keep you updated.
Do not send: Passwords, access tokens, customer names, or sensitive business records.