For IT and security
Vedetta runs inside your Microsoft 365.
It is a SharePoint web part and nothing else. It runs in each person's browser, with that person's own SharePoint permissions, and it sends nothing to Vedetta or anyone else.
No Vedetta server, no telemetry and no API permissions to approve. Your methodologies, templates and projects stay on your SharePoint sites.
Installing
An App Catalog administrator installs Vedetta from the SharePoint Store, Microsoft's catalogue of SharePoint apps, or uploads the package file (.sppkg) to the App Catalog. There are no API permission requests to approve in Microsoft Entra ID, because Vedetta makes none. The code is served from your own App Catalog, so there are no external script sources to allow.
If your organisation doesn't allow apps from the store, request the package and upload it to the App Catalog instead. It is the same app.
New versions are not installed automatically. An administrator chooses Upgrade Store App in the App Catalog, or uploads the new package. We email a short note to billing contacts when a version is available.
How it runs
- In the browser, as ordinary SharePoint requests with the signed-in person's own rights. Vedetta can never do more than that person could do in SharePoint.
- No Vedetta server. The web part makes no requests outside your SharePoint: no telemetry, no licence checks, no update checks and no content from us.
- No separate accounts. People use their Microsoft 365 sign-in. There is nothing to provision.
- SharePoint's permissions are the only rules. Site owners run Set up and choose authors, authors write and publish methodologies, and everyone who can read the site can start projects. Vedetta changes who can read the site only when a site owner asks it to in Settings, by adding “Everyone except external users” to the site’s Visitors group.
What Set up adds to your site
A site owner chooses the central site, usually the PMO's, and runs Set up. It adds:
| Vedetta authors | A SharePoint group for the people who write methodologies, managed by the site's owners. |
|---|---|
| Drafts and draft uploads | A hidden list and library that only site owners and authors can open. |
| Published methodologies and templates | A hidden list and library that everyone who can read the site can read, and only authors and owners can change. |
| Settings | A hidden list with the licence key, the start of the free trial and the sensitivity label for project sites. Only site owners can change it. |
Set up configures Vedetta's own lists, libraries and permissions, leaving the site's other content alone. Running it again repairs configuration without deleting methodology or project content. Every list and library Set up adds is excluded from search, so drafts can't surface there.
Project sites
When someone starts a project, Vedetta creates a SharePoint team site without a Microsoft 365 group, through SharePoint's documented site creation, as that person. It adds a Project documents library with a numbered folder for every stage and every deliverable the project includes, a copy of each starting document, and a link to the guidance. If the methodology defines project lists, such as a risk log, it also creates them as ordinary SharePoint lists, which search finds under the site's permissions. The person who starts the project owns the site and shares it with the team using SharePoint's normal controls.
If your organisation doesn't let people create SharePoint sites, Vedetta says so. IT creates the site and makes the project lead its owner, and the project lead chooses Use an existing SharePoint site. Owning the site matters when the methodology defines project lists, because creating lists needs that right. If your organisation requires a sensitivity label on new sites, a site owner chooses one in Vedetta's Settings and Vedetta applies it to every project site.
Where your data is
On your SharePoint sites: the methodologies, templates and settings on the central site, and each project's documents on its own site. Project sites are ordinary SharePoint sites and never depend on Vedetta. If you remove Vedetta, everything stays where it is.
Expert method packs are obtained separately from the expert, outside the app. An author imports the downloaded .vedetta file into your SharePoint as a draft, reviews it and publishes it when ready. The web part never contacts the expert's store. The expert sets the pack's price and terms; it is not included in the Vedetta licence.
The licence
A licence key is one line of text, signed by us and checked in the browser against the public half of our signing key, which ships in the package. Nothing is looked up online. Set up starts a 30-day free trial. When a licence ends, 30 days of grace follow, after which writing methodologies and starting new projects pause. Reading and existing projects never depend on the licence.
Buying happens outside the app. A site owner chooses Buy a licence in Settings, which opens our checkout in a new browser tab with your organisation's Microsoft 365 ID and the Vedetta page's address filled in, so the key can be linked to the right place. The key email's activation link carries the key after #, which browsers never send to any server; Vedetta removes it from the address bar as soon as the page opens, and a site owner confirms before it is saved.
For your supplier questionnaire
| Does the application send data to external parties? | No. The web part makes no requests outside your SharePoint. |
|---|---|
| Does Vedetta store or process our data? | No. Everything stays in your Microsoft 365. We have no access to it. |
| Does it need API permissions or admin consent? | No. |
| Is it a SharePoint Add-in? | No. It is built on the SharePoint Framework (SPFx), the model Microsoft recommends in place of add-ins, so the add-in retirement of April 2026 doesn't affect it. |
| Where is the code hosted? | In your App Catalog, from which SharePoint serves it. |
| How are updates delivered? | Through the SharePoint Store or a new package, installed by your administrator. |
| What do you process when we buy? | Billing details, through Stripe, and the key email, through our email provider. See the privacy policy. |
| Does it log activity? | Vedetta keeps no logs. SharePoint's own audit log records actions as usual. |
Supplier
Vedetta · CVR 45339254 · Denmark. Questions from IT: Help.