Bus-Factor Report · Guide
What email metadata reveals without reading a single email
Headers versus bodies: what email and calendar metadata can and cannot show about who does what, why that is the ethical line, and how the data is deleted.
Headers vs bodies
Every email has two parts: the envelope and the letter. The envelope says who sent it, who received it, when, and which conversation it belongs to. The letter is what was said. You can learn a surprising amount about how work flows through a firm from envelopes alone, and you never need to open one.
This is exactly what the Bus-Factor Report reads, copied word for word from our data-handling page:
- Directory: your organization’s name and domain; each user’s name, email address, job title, department, manager, and account status. Last sign-in date where your tenant has a Microsoft Entra ID P1 or P2 license; without it we report sign-in as unknown, never as inactive.
- Membership: security groups, Microsoft 365 groups, Teams, and distribution lists, with their owners where Microsoft exposes them. Owners of Exchange-created distribution lists and on-premises synced groups are not available, and we report them as unknown.
- Ownership, where available: the names of all SharePoint sites, with owners for group-connected sites (other sites’ owners are not available and we report them as unknown), owners and assigned users of enterprise apps, and admin role holders. Who has full access to a shared mailbox needs extra Exchange permissions we do not ask for, so we report it as unknown and still see who sends from it (below).
- Recurring meetings: the meeting title, organizer, and attendees. The title is kept because it names the process (for example, “Run payroll”). Not the meeting description, notes, chat, recordings, or transcripts.
- Mail metadata: sender and recipient email addresses (including people outside your company), date, and thread relationships for the last 90 days. For shared mailboxes, we read their name and address and which people sent from them in that window. Not the subject line, not the body, not attachments.
What we can and cannot infer
From envelopes we can see that one person sent every message from the vendor-payments mailbox for 90 days (a lead, since we cannot see who else holds access), that one person organizes the monthly close meeting, and that one person is the only owner of the finance site. That is enough to ask whether the work depends on them.
Meeting titles are read, for recurring meetings only, because a title like "Monthly close" is how a report tells a finance meeting from a lunch order. We are telling you that plainly because it is the one piece of calendar text we see.
What we cannot infer: what anyone said, whether they did the work well, or anything about their personal life. Where the tenant does not show us something, such as the owners of a shared mailbox, the report marks it unknown. It never counts as covered. And what we never read:
- Message bodies, attachments, or subject lines.
- Files, documents, chat messages, meeting descriptions, recordings, or transcripts.
- Passwords, MFA state, or anything from personal devices.
Why this is the ethical line
A continuity report answers a structural question: how many people can do this? Content answers a different question: what did this person say? The first question helps a firm protect its people from being irreplaceable. The second is surveillance, and no continuity finding needs it.
Drawing the line at metadata also keeps the report honest. It reports what the tenant shows and grades each finding, rather than guessing at intent from what someone wrote.
How we delete
Tenant data is processed in memory to build your report. When the report is delivered it is deleted. We keep the report itself for you to download for 90 days, then delete that too. We keep your email address and purchase record because we have to.
No human on our team reads your tenant data, and it is not used to train anything. You can also revoke the application from your tenant at any time, and new access is cut off as soon as you do.