Rollup
One web part that gathers documents, news and list items from every site a visitor can already see, filtered by the metadata you use today.
Before you install
A SharePoint Online tenant with a site collection app catalogue, or a tenant app catalogue if you want the web part available everywhere at once. Classic pages are not supported.
Someone with SharePoint administrator rights to approve the API permission request. The approval is a single screen in the Microsoft 365 admin centre and takes about a minute.
Rollup never widens what a visitor can see. It queries as the signed in user, so a document that person has no access to does not appear in their results. There is no service account and no stored credential.
Installing it
- 01Upload the package to your app catalogue and choose whether to deploy it tenant wide.
rollup_2.8.0.sppkg - 02Approve the pending permission request in the admin centre.
Sites.Read.All - 03Add the web part to any modern page and pick the metadata to filter on.
toolbox: Rollup
Specification
Questions
Does Rollup copy our documents anywhere?
No. It queries the Graph at page load and renders the results. Nothing is copied, cached outside the browser session, or sent to any server we run.
What happens to results a user should not see?
They never reach the browser. The query runs as the signed in user, so SharePoint applies the same permissions it would on the source site.
Can we install it on one site first?
Yes. Use a site collection app catalogue rather than the tenant one, and the web part appears only on that site.
What does the licence cover?
One tenant, unlimited sites, unlimited users, no expiry. It is a purchase rather than a subscription, so nothing stops working if you never pay again.