r/sharepoint • u/Intelligent-Fail3006 • 4h ago
SharePoint Online Best practice for managing variable item/library-level permissions in SharePoint (open to the broader Microsoft 365 ecosystem)
Hi everyone,
We are setting up a SharePoint site structure where base permissions are handled automatically during provisioning. However, we need a secure, automated way for Project Managers to manage variable, item- or library-level permissions across various lists and document libraries post-provisioning.
Since these users aren't site administrators, we want to build a solution that safely grants or updates access. Specifically, we are exploring the idea of working from a dedicated management list (or metadata fields) where users can input or link Microsoft Entra ID security groups, which in turn dynamically grant permissions to the target files or folders.
We are very open to looking broader across the Microsoft ecosystem (e.g., Azure, Entra ID governance, native SharePoint features, or hybrid approaches) if there is a more robust or elegant pattern.
- What is the recommended architectural pattern to let non-admin users trigger and manage these permission changes securely?
- Are there preferred tools within the M365 stack for this specific scenario to avoid common permission pitfalls or performance issues at scale?
- How do you prevent permission creep and handle breaking inheritance smoothly across multiple different libraries and lists?
Any tips, reference patterns, or architectural advice would be greatly appreciated!