SharePoint security context

List Creator is a SharePoint Framework application. Its operations are performed in the customer's Microsoft 365 environment and are subject to the permissions of the signed-in user and the customer's SharePoint configuration.

Least privilege

The application is designed to rely on existing SharePoint authorization. It does not intentionally bypass Microsoft 365 access controls or grant a user additional rights.

Credentials and secrets

Users should never enter passwords, access tokens, API keys, or other secrets into list names, column values, screenshots, or support requests. The core List Creator workflow does not require a user to provide Microsoft 365 credentials directly to Ackerman Technologies.

Customer responsibilities

Customers are responsible for Microsoft 365 identity controls, tenant configuration, SharePoint permissions, data governance, retention, audit policies, and security monitoring appropriate to their organization.

Reporting a security concern

Report product security concerns using the publisher support contact information associated with the List Creator offer in Microsoft Marketplace. Include enough technical detail to reproduce the concern, but do not include live credentials or unnecessary sensitive data.