BETAVotra is in public beta — every feature on this page is live, and your feedback shapes what we build next.

Documentation

Documentation

How Votra works end to end: connecting Microsoft 365, what an operation does, how approvals and verification behave, and what the evidence contains. Written for the administrator running it.

1. Connect Microsoft 365

An administrator signs in and completes delegated administrator consent. Votra requests Files.ReadWrite.All, User.Read.All, MailboxSettings.ReadWrite — read and write scopes on ownership, permission and sharing metadata. No scope grants access to file contents, and none is requested that would let Votra read a document. Account, member, role, policy and billing settings work without a connection; only operations need one.

More on the connection

2. Discover

Selecting an employee produces an inventory of the resources they own across OneDrive and SharePoint, each classified by sharing state: owned outright, shared, inherited, or exposed to external guests. The inventory is reviewable before execution, which is the point — the common manual failure is an incomplete inventory, and it is cheap to fix here and impossible to fix after deletion.

3. Approve

Nothing changes until an operation is approved. Role-based access control keeps the initiator and the approver distinct, and the policy layer can require approval for every operation rather than only high-risk ones. The approver sees the same inventory the initiator reviewed.

4. Transfer and verify

Ownership moves item by item through Microsoft Graph, in resumable batches. After each change, Votra re-reads the resource and compares what the provider reports against what was requested. A failure marks that specific item, so the operation can pause and be retried or skipped without losing the rest. This is the difference between a transfer that reported success and one that provably landed — see ownership transfer with verification for why each level of ownership is a separate record.

5. Export evidence

A completed operation exports a signed record: what changed, when, who initiated it, who approved it, and the post-change provider state for each item. Retention follows your plan (90-day retention on Starter, longer above it), so the evidence outlives the tool. How offboarding evidence is scoped for an audit covers what an auditor can rely on.

Troubleshooting

  • An item stays failed after a retry: it is usually a permissions problem on the destination owner, not on the source. Check that the successor account is licensed and not external.
  • A site transfer succeeds but libraries look unchanged: expected. Site primary owner, site collection admin, and library/item ownership are three separate records, and only the third is what Votra moves.
  • An operation cannot be approved by you: the separation-of-duties rule blocks the initiator from approving their own operation. Ask a second member with the approver permission.
  • Discovery looks empty: the Microsoft 365 connection has expired. Reconnect it and re-run discovery — the operation itself is unaffected.

Frequently asked

What Microsoft 365 permissions does Votra request?
Delegated administrator consent for Files.ReadWrite.All, User.Read.All, MailboxSettings.ReadWrite. These are read and write scopes on ownership and permission metadata. Votra never requests a scope that grants access to file contents, and it never downloads file contents.
How long does an offboarding operation take?
The work around the operation is minutes: connect, pick the employee, review the discovered inventory, and get approval. The transfers run in resumable batches whose duration depends on how many items the employee owns, and progress is tracked item by item throughout.
What happens if a transfer fails partway through?
The operation pauses and flags the exception on the specific item rather than the whole run. You can retry or skip that item, and the audit trail records exactly what happened, so a partial transfer is visible instead of silent.
Does Votra delete the employee's account or mailbox?
No. Votra changes ownership and access metadata. License removal, mailbox conversion and account deletion stay in your Microsoft 365 admin console, because those are account-lifecycle decisions with their own retention and legal-hold implications.
Can I keep using Votra without a Microsoft 365 connection?
Yes. The account, members, roles, policies and billing settings all work without a provider connection. The offboarding and ownership-transfer operations are what require a live Microsoft 365 connection, and the app tells you so before you start one.

Guides

What Votra is

Votra is a platform for running employee offboarding and resource-ownership transfers on Microsoft 365 — with more workspace integrations on the roadmap. Operations discover what an employee owns, move ownership and access through provider APIs without ever moving file content, enforce approval before anything changes, and export a signed audit trail of every action.