What we're allowed to read
It can only answer from what you connect, and it only ever reads. We ask for read permission and nothing else.
SharePoint
Specific sites and document libraries you pick.
Outlook
Specific mailboxes, with a date floor.
Google Drive
Only the folders you select in the picker.
Box
Specific folders you pick.
Drop files in
Anything else. Drag a folder.
These five are the whole list. We don't connect to Teams, Slack, or your practice-management system.
What your IT admin would approve
Shown here before you click anything, so nothing in the consent screen is new.
| Permission | Why | Admin consent |
|---|---|---|
| Sites.Selected | Read only the specific SharePoint sites you pick. Granted per site. | Yes |
| Mail.Read | Read the mailboxes you name, from the date floor you set. | Yes |
| User.Read.All | Map who is who, so answers can say who wrote something. | Yes |
Sites.FullControl.All · Files.ReadWrite.All · Mail.Send · Mail.ReadWrite · Directory.ReadWrite.All
We never ask for these, so there is no setting that turns writing on. An hour after you connect, your own Microsoft audit log will show reads and no writes.
Coverage
Connected · partial coverage. Nothing was modified.
| 31 items | Excluded by your own rules — libraries named Personnel, Payroll, Independence. |
| 7 items | Could not be read — access denied, or password-protected. Your admin can grant these. |
Answers don't include these 38 items, and an answer that touches one of them says so. We try them again on the next sync instead of marking them done.