16 articles
Backups·4 min read

Change Watch

Change Watch helps administrators identify navigation drift after a site has a known-good backup. It does not replace backup history. Instead, it compares the site's current navigation with an approved backup version and saves the result as a reviewable change record.

Approve a baseline

  1. Open Recovery Center and select a protected site.
  2. Open its version history.
  3. Select a successful version that represents the expected navigation state.
  4. Choose Approve baseline.

The portal records the approved version, the approving administrator, and the approval time. You can replace the baseline later by approving another successful version from the same site.

Run a scan

In version history, use Run scan in the Change Watch panel. The scan is queued to the background worker. It reads the current site navigation, compares it with the approved baseline, and stores the result.

ℹ️ NoteA Change Watch scan does not create a backup version and does not change the approved baseline.

Review the result

The result can be none, low, medium, or high severity.

  • Removed navigation, destination URL changes, visibility changes, and audience-targeting changes are high severity.
  • Label changes and order-only changes are medium severity.
  • Added navigation alone is low severity.
  • No detected difference is shown as none.

The panel provides a short explanation, such as a removed item, changed destination, or changed visibility rule. Operations lists unacknowledged high- and medium-severity findings in Needs review, while Change Control provides the review queue.

Respond to a finding

After review, an admin can:

  • Acknowledge an expected change from the Change Control review queue.
  • Approve a new known-good backup as the baseline.
  • Create a backup before taking further action.
  • Restore an eligible historical version after reviewing the restore-readiness summary.

Acknowledgement records the administrator and time. It does not alter SharePoint navigation, delete the scan, or change the approved baseline.

Permissions and scope

Admins can approve baselines, queue scans, and acknowledge findings. Users with backup-view permission can see results only for sites in their scope. The server enforces tenant isolation and role scope for every Change Watch request.