KnowledgeCapital

KnowledgeCapital › Guides

SharePoint knowledge base: what the connector reads, and what it reveals

The SharePoint connector reads your site pages and document libraries via Microsoft Graph, read-only, and links each file to the knowledge it describes.

In short

Yes: KnowledgeCapital reads SharePoint and Microsoft 365 through Microsoft Graph, read-only — site pages and document libraries (Word, PDF, PowerPoint, Excel). Once confirmed, each document is linked to the knowledge it describes. You then see who actually masters that knowledge, how critical it is, and which critical knowledge has no document at all.

What SharePoint does very well, and what it cannot tell you

In many organisations the knowledge base already exists: it is a SharePoint site. Procedures live in document libraries, work instructions keep their version history, site pages introduce teams and their rules. Microsoft 365 does what it was built for: store, share, find, and control who may open what.

What a library cannot tell you comes down to three questions: who can actually apply the procedure filed there, how many people still know how, and which critical knowledge has no document at all. A file called "Restarting line 2" proves that somebody once wrote something down. It does not tell you that the only person able to do it retires in eighteen months.

That is the whole gap between a document repository and knowledge management: the first keeps what was written, the second measures what the organisation knows and what it is about to lose. The SharePoint connector bridges the two without moving a single file.

What the connector reads, exactly

Images, videos, archives and legacy Office formats (.doc, .xls, .ppt, pre-2007) are skipped without failing the run. A file is only read again when its version has changed: a second sync of an unchanged site downloads nothing, and your Microsoft 365 tenant is not hammered for no reason.

What it never does

It writes nothing to SharePoint: the permission requested is a read permission, and the driver has no write function at all. It uses no person's account and no user password: it signs in as an application registered in your own tenant, which you can revoke at any time. The access token issued by Microsoft lives for one hour and stays in memory; it is never written to the database. The application secret is encrypted in the server's vault and never shown again on screen.

Confinement remains the rule. When you save the connector, the only hosts it needs — graph.microsoft.com, login.microsoftonline.com and your sharepoint.com address — are allowed by name, for this connector only; they are removed with it, and every call is written to the outbound log. The product's AI stays local: the text it reads is never sent to an outside AI service.

Connecting it, in five steps

Allow about twenty minutes, plus someone who administers your Microsoft 365 for the first three steps (Application Administrator or Global Administrator role). They are done once.

  1. Register an application in the Microsoft Entra admin center: App registrations › New registration, accounts in this organisational directory only, no redirect URI. Write down the Application (client) ID and the Directory (tenant) ID.
  2. Create a client secret (Certificates & secrets) and copy its value straight away: Microsoft will not show it again.
  3. Grant the permission: API permissions › Microsoft Graph › Application permissions › Sites.Read.All, then "Grant admin consent". If your policy requires it, pick Sites.Selected instead and have access granted site by site: the connector works the same way and only sees those sites.
  4. Connect it in KnowledgeCapital: Administration › Sources › Connect a system › SharePoint / Microsoft 365. Paste the address of any page of your site (the base address is detected), the application ID and the secret.
  5. Check, then sync. The check requests a token from Microsoft and lists each site's libraries; nothing is saved until you connect.

The tenant is inferred from the site address (acme.sharepoint.com gives acme.onmicrosoft.com). If yours was renamed, type "directory-ID/application-ID" in the Identifier field.

When "Check" says no

MessageLikely causeWhat to do
Microsoft rejects the application (401)Wrong or expired secretCreate a new secret and paste it again
Unknown tenant (400)Tenant wrongly inferred from the addressType "directory-ID/application-ID"
Access denied (403)Admin consent not granted, or Sites.Selected without access to the siteGrant consent, or open the site to the application
Address not found (404)Wrong site address, or site closed to the applicationPaste the address of a page of the site

From document to knowledge: the links

Every page and file read is compared with your knowledge catalogue. When the full name of a piece of knowledge appears in a document — in the title the suggestion is strong, in the body only it is weaker — the system suggests a link, showing its score and the evidence behind it. The knowledge manager confirms or rejects: nothing is linked automatically, and a rejected suggestion does not come back.

The rule that explains almost everything: the knowledge name must be written as it is in your catalogue. A file called "Oven work instruction" will never meet a piece of knowledge named "Running the curing oven". Renaming the file, or naming the knowledge the way teams actually say it, is enough. The "Recompute links" button then runs every page already read against today's catalogue, without a single call to Microsoft.

What it changes on the knowledge map

To give an order of magnitude: if six files in a library changed since the last run, only those six are downloaded and read again, however many documents the site holds.

SharePoint, Confluence, a DMS: which one to connect?

As many as you have. Each system is one more connector, on the same screen and under the same rules: Confluence (the only one that can also receive the sheets your committees validate), your document management system through CMIS or WebDAV, Notion, your intranet, and any other tool through the API. An on-premises SharePoint Server that exposes a CMIS root connects through the DMS connector.

Connectors are included from the Professional plan upwards, and in the sovereign edition installed on your servers. On the hosted service, an hourly clock re-reads every connector whose frequency is due; on your own servers, a scheduled task does the same. To decide where to start, the guide on building a knowledge management system from scratch gives the order of the steps.

SharePoint, Microsoft 365, Microsoft Entra and Microsoft Graph are trademarks of Microsoft Corporation; Confluence is a trademark of Atlassian. KnowledgeCapital is neither affiliated with nor endorsed by these companies.

Frequently asked questions

Does the SharePoint connector change our documents?

No. It requests a read permission (Sites.Read.All or Sites.Selected) and contains no write function. Nothing is created, changed or deleted in SharePoint.

Do we have to hand over a user's password?

No. The connector signs in as an application registered in your Microsoft Entra tenant, with a client secret that you create and can revoke at any time. The secret is encrypted on the server and never shown again.

Can reading be limited to some sites or libraries?

Yes. List the sites to read, one address per line, and restrict to one library if needed. With the Sites.Selected permission, the application only ever sees the sites an administrator opened to it.

Which file formats are read?

Word (.docx), PDF, PowerPoint (.pptx), Excel (.xlsx), plain text, Markdown, HTML and CSV, plus the text of site pages. Images, videos, archives and pre-2007 Office formats are skipped.

Do we need to migrate our SharePoint knowledge base?

No. Documents stay in SharePoint, where your teams keep working. KnowledgeCapital keeps their text for search and linking, and always points back to the original.

No card. A space pre-filled with five years of demonstration data.

Try it free for 14 days   Watch the guided tour

Going further

Updated on

The other guides

Knowledge transfer before retirement: the method

How to organise know-how transfer before an employee retires: spot what leaves, measure the risk, train a successor, prove it is done.

Knowledge management software: how to choose

Knowledge base, wiki, document management or knowledge mapping: which knowledge management software answers which need, and the five questions that decide.

Knowledge management system: a 12-point evaluation grid

Twelve criteria to compare knowledge management software without solving the wrong problem: tacit knowledge, criticality, connectors, sovereignty, cost.

Skills mapping: method and software

How to map an organisation's skills: reference list, mastery levels, criticality. What separates an Excel matrix from a living map.

How to build a knowledge management system from scratch

The exact order for building knowledge management on a blank space: org chart, people, knowledge catalogue, processes, holders, criticality, assessments.

Key-person risk: knowledge held by one person

Spot knowledge that depends on one person, measure the exposure and organise a successor before the incident: the single point of failure of knowledge.

Lessons learned software with validation

Capture lessons learned from the field: contribution, validation by a committee, links to knowledge, search across four languages.

Industrial knowledge management for maintenance

Knowledge management for industry, mining and energy: maintenance know-how, rare skills, departures, and a method that holds up on site.

Sovereign knowledge management with local AI

Self-hosted knowledge management software: no outbound connection, local AI, built-in video conferencing, isolated data, full reversibility.

A knowledge ERP: what your ERP does not manage

An ERP manages stock, orders and payroll. It does not know who is the only person able to restart the line. KnowledgeCapital is the ERP of that resource.

Internal expert network: find who knows

Locate expertise in the organisation: an expert network based on measured mastery, questions routed to who knows, answers captured.

Succession planning for critical knowledge

A succession plan that starts from critical knowledge: who leaves, what leaves with them, who can take over, and proof that the successor is ready.

SharePoint knowledge base connector: setup and limits

The SharePoint connector reads your site pages and document libraries via Microsoft Graph, read-only, and links each file to the knowledge it describes.

DMS and knowledge management: Alfresco, Nuxeo, CMIS, WebDAV

Your DMS keeps documents; it does not say who knows. The connector reads Alfresco, Nuxeo or Nextcloud through CMIS or WebDAV, read-only.

Notion as a company knowledge base: a practical guide

Notion is great for writing together. How to structure a Notion knowledge base, and connect it to learn who actually masters what it describes.

Intranet knowledge management: map knowledge, no migration

Your intranet publishes procedures; it does not say who can apply them. The connector reads its pages, even without a sitemap, and feeds the knowledge map.