What Governance as Code is
Governance as Code means the judgement is a file, not an opinion. A rule states what it requires and on what basis it requires it. A collector observes the tenant read-only and preserves what it saw, when, and under which identity. An Assessment carries the conclusion together with the material needed to check it.
This Knowledge explains how each of those judgements was established. It is not a second rule engine, and it never evaluates a tenant: it documents the evidence path that the Engine already publishes.
Where to begin
Three entry paths. They are ordered by what you arrived to do, not by where an article sits in the tree.
- 01
I need the command
Go straight to the workload. Each article opens with the exact command, the output it returns, and the reading of that output, before any explanation.
Enumerate every site in a tenant → - 02
I need to trust the result
Start with provenance. What must travel with a finding, why identity kind is not a detail, and why a count can be a lower bound rather than a number.
How provenance changes a finding → - 03
I am deciding whether to adopt this
Read the engine's own contract: what a rule may claim, which bases are normative, and what an Assessment declares about itself.
Governance as Code →
What is covered
Each area is as deep as its verified paths, and no deeper. The full list of articles is in the navigation beside this page.
Governance as Code
32Inactive and archived sites · Copilot agents · Sensitivity labels · Licences and what they cost to prove · Permissions · Classic and modern sites · Connecting and identity · Custom script · Sharing and external access · Sites, owners and storage · SPFx and custom code
Locked and archived sites →Microsoft Entra ID
1Conditional Access and sign-in
What report-only mode enforces →
What Knowledge is, and is not
Knowledge owns verified answers about Microsoft 365, written as if this product did not exist. It is the only place on this site that does.
What does not belong here, and where each lives instead:
- The product itself Microsoft 365 Governance as Code · Product
- How the product works Documentation · Product
- A migration method Field Guide · Practice
- Engineering arguments and lessons Analysis · Practice
Recently verified
When the evidence path was last confirmed against a live tenant, not when the text was last edited.
- What does a Conditional Access policy in report-only mode actually enforce?
- What does "custom script disabled" actually establish in SharePoint Online?
- What does a Microsoft 365 licence assignment actually give a user?
- What can Microsoft 365 usage reports actually establish about a user?
- How to inventory SharePoint agents without pretending you saw the whole tenant
- How to read which sources a SharePoint agent was pointed at
When an article is not enough
An article answers one question against one evidence path. These do not.
Field Guide
A chapter, not an answer. Where a decision has to be taken across a whole tenant and the trade-offs matter more than the command.
SharePoint Compass
Advisory. You answer questions about your own environment and it gives an indicative reading. It collects nothing and produces no finding.
The Engine
The only thing here that observes a tenant, evaluates rules and produces an Assessment. Everything else explains it.