Tenant Connect

Publish open data straight from SharePoint — no file moves, no new workflows.

Tenant Connect turns the SharePoint document libraries you choose into a standards-compliant open data catalogue that portals can harvest, while your files and your team stay exactly where they are.

Sign in with your Microsoft work account — first time here, you'll be walked through connecting your organisation.

Sign in with Microsoft

Frequently asked questions

What is Tenant Connect?

Tenant Connect is a hosted service from Derilinx that publishes open data directly from your Microsoft 365 tenant. It reads the file listings and metadata columns of the SharePoint document libraries you select and serves them as a DCAT‑AP catalogue — the metadata standard that national and EU open data portals harvest.

SharePoint stays the home of your files — your team keeps managing documents and metadata with the tools they already use, and nothing is manually moved or re-uploaded. When a portal harvests your catalogue, it fetches the published files through the service, so the portal serves the public while SharePoint remains the single source of truth.

How does it work?
  1. Sign in and connect. A tenant administrator signs in with their Microsoft work account and approves the connection for the organisation.
  2. Choose libraries. Pick the document library (or libraries) to publish, and grant the service access to just those sites — by browsing, by pasting a library URL, or by running the grant yourself in PowerShell.
  3. Verify and activate. Tenant Connect confirms its access, reads the library's metadata columns, and builds your catalogue.
  4. Harvest. You receive a private catalogue endpoint and API key. An open data portal (CKAN, for example) harvests from that endpoint on its own schedule.

When files change in SharePoint, Microsoft's change notifications tell the service immediately, so the catalogue stays current — with scheduled re-scans as a fallback.

What are the security implications?
  • Least privilege by design. The service's only standing application permission is Sites.Selected — a permission that grants access to no sites at all until your administrator grants each site individually.
  • Read-only. Site access is granted with the read role. The service cannot modify, move, or delete anything in your tenant.
  • You control visibility during setup. Browsing your sites in the setup wizard uses a broader signed-in-administrator permission; if you prefer, paste the library URL instead — or grant access yourself in PowerShell, so the service never sees anything beyond what you granted.
  • Purpose-bound access. A library connected for catalogue publishing is used for catalogue publishing only. Any additional service is off by default and must be switched on per library, explicitly.
  • No file storage on our side. The service stores catalogue metadata only, never your file content — files are streamed from SharePoint at the moment a caller holding your API key requests them.
  • Authenticated endpoints. The catalogue and file endpoints require an API key, stored only as a cryptographic hash and revocable key-by-key at any time.
  • Revocable. Disconnecting from the dashboard removes the service's site access; the remaining organisation-level consent can be removed by your administrator in the Microsoft Entra admin centre, and the disconnect page documents exactly how.
What can I use Tenant Connect for?
  • Open data publishing. Feed a national or organisational open data portal directly from the SharePoint libraries where your data already lives.
  • Standards compliance. The catalogue is DCAT‑AP, the metadata standard required by EU and national open data infrastructure.
  • Always-current publishing. Change notifications keep the catalogue in step with SharePoint — no manual re-uploads, no stale copies.
  • Library insights. An optional, per-library view of formats, sizes, and metadata completeness — switched on only where you choose.

Tenant Connect is built as a platform: further services and sources are added over time, each behind the same explicit, per-library consent.