Microsoft, Microsoft 365, Outlook, SharePoint, OneDrive, Microsoft Teams, Microsoft Graph, Azure, and Entra are trademarks of the Microsoft group of companies. ImpressionsDirect360 is an independent provider and is not affiliated with, sponsored by, or endorsed by Microsoft.
No black box. Here is exactly how our automations connect to your Microsoft 365, what they are allowed to touch, and how you can see every access.
Your Outlook, OneDrive, SharePoint and Teams — your data, in your name. Microsoft calls this your tenant; it just means your company's own copy of Microsoft 365.
You consent to a named ID360 application in your own Microsoft 365 admin center, and you can withdraw it at any time. We never hold a standing password to your tenant. Be clear about the limit, because it is easy to overstate: the permissions the application holds are tenant-wide, not confined to the mailboxes and sites you nominate. Pointing the automations at only those is our configuration choice, not a boundary Microsoft enforces on us. The terms set out how wide the access is, and the ApplicationAccessPolicy you can apply in your own tenant to narrow the Exchange half of it.
Every automation talks to your tenant through Microsoft Graph. There is one fixed set of five application permissions for all of them — a workflow does not get its own narrower grant.
The automation logic runs on Microsoft's own cloud — event-driven Functions and Logic Apps we build and operate.
When a step needs drafting or summarising, it calls ID360 AI, which is built on Google's Gemini API. That content is sent to Google for processing and the result is written back into your tenant — Google is named on our subprocessor page rather than hidden behind a generic label.
The result lands where you work — a filed document, a drafted reply, an updated list — inside your own Microsoft 365.
This is the complete set, and it is the same for every customer — it is not assembled per tenant and buying fewer automations does not shrink it. These are application permissions, so they are tenant-wide rather than limited to the mailboxes and sites you nominate; we point the automations only at those, but that is our configuration, not a boundary Microsoft enforces on us. Microsoft's own consent screen is the authoritative statement of what you are granting.
Mail.ReadWriteRead the mail an automation is built to handle, file its attachments, and leave a drafted reply in Drafts. Tenant-wide: it reaches every mailbox in your tenant, not only the one an automation points at.
Mail.SendSend the message an automation composes — a morning brief, a meeting prep note, an acknowledgement. Tenant-wide: it can send as any mailbox in your tenant.
Calendars.ReadRead today's meetings so a brief can list them. Read only — we cannot create, move, or cancel anything in a calendar.
Sites.ReadWrite.AllFile documents into the SharePoint library an automation is configured for. This is the broadest permission we hold: it reaches every SharePoint site in your tenant, and there is no per-site restriction on it today.
User.Read.AllResolve who owns what, so a notification reaches the right person and a filed document is attributed correctly. Read only — we cannot create, change, or disable an account.
Mail and documents live in your own Microsoft 365. Automations read and write there; nothing is copied out to a place you cannot see.
The permissions are tenant-wide, not scoped to what you nominate, and the consent does not run on a timer — it lasts until you withdraw it. You can review it, and revoke it, in your own admin center at any time.
Every action an automation takes is recorded to a log kept for your account. Ask us and we send you that record — what ran, when, and against what. There is no self-service audit screen yet.
Bring them to the setup call — we're happy to walk through the scopes and the audit log line by line.