Integrations

    Microsoft 365 AI Integration

    If your company runs on Microsoft 365, then mail, documents, and conversation are already where your people work. Software that ignores that fact asks everyone to keep a second place open and remember to look at it. This integration is about the opposite: connecting a custom build to the tools your staff already have open, through the tenant your IT team already governs, with nothing bolted on the side.

    What we connect

    Outlook mail, through a connection each user authorizes for themselves. SharePoint document libraries, browsable from inside the application so files can be reached where the work is happening. And sharing out to Teams, so something produced in the build can land in the channel where the conversation about it is going to happen anyway.

    That is the list. Microsoft 365 is a large surface and it is tempting to imply more; we would rather name three things we do and let your team scope the rest deliberately.

    How the integration works

    An application is registered in your Microsoft Entra tenant. Domain ownership is verified through the standard identity-association file, and the application is then authorized against consented Graph permissions.

    Your IT or security team reviews and grants those scopes. This is the part we consider a feature rather than an obstacle: the permissions are inspected by the people responsible for them, in the tenant they administer, using the same consent flow as every other application they have already approved. The app holds no standing credentials outside that grant, which means withdrawing consent is a complete revocation and not a request we have to honour.

    What it makes possible

    • Outlook mail reachable from the build, under a connection the user authorized.
    • SharePoint document libraries browsable without leaving the application.
    • Sharing out to Teams, so output lands where the conversation is.
    • Access governed by your tenant, revocable by your administrators.

    What we need from you

    An administrator in your Entra tenant who can review the requested Graph permissions and grant consent, and the short cooperation needed to place the identity-association file that verifies domain ownership.

    A decision on which users get the Outlook connection and which SharePoint libraries are in scope. Both are your governance calls, and both are easier to make before anyone is using the build than after.

    Questions owners ask

    Who approves this, and what exactly are they approving?

    Your IT or security team, and they are approving a named set of Graph permissions on an application registered in your own Entra tenant. The scopes are visible to them at the point of consent, and consent is what makes the connection work at all. If they decline a scope, the capability that depends on it does not function — there is no path around the grant.

    Does the application store our Microsoft credentials?

    No. The app holds no standing credentials outside the grant. Access exists because your tenant consented to a registered application, and it stops existing when that consent is withdrawn.

    How do we revoke access?

    Through your tenant, by withdrawing consent for the registered application. That is deliberately the same mechanism your team already uses for every other application in the tenant, rather than a proprietary switch inside our software that they would have to learn and trust.

    Why does domain ownership have to be verified?

    Because the standard identity-association file is how Microsoft establishes that the party registering the application actually controls the domain it claims. It is a routine step, it is a short one, and it exists so that a tenant administrator granting permissions knows who they are granting them to.

    What does the SharePoint side actually do?

    It makes your document libraries browsable from inside the application, so documents can be found where the work is happening rather than in a second tab. The files stay in SharePoint, under your existing permissions.

    Related

    Ready to put engineers on it?

    Start with a complimentary industry analysis. You leave with the one project worth deploying first.

    Schedule a Consultation