Microsoft 365 setup
Connecting Evidos to your Microsoft 365
One approval from your administrator lets Evidos act as your consultants — each signed-in person, within only what they can already access. Here is exactly what that means, why it is safe, and how to undo it.
one Accept clickdelegated, user-scopedno bots, no service accountreversible any time
Evidos turns your engagement’s meetings and documents into a searchable base of evidence — every finding tied to the exact words in the record, with a citation you can click straight back to. To do that it reads Microsoft 365 as the consultant who is signed in, never as a stand-alone service with its own keys.
What Evidos can and cannot see
The whole security story on one screen, before any steps.
What it can read
- ✓Through each connected person only — nothing has standing access of its own
- ✓Transcripts of Teams meetings that person organized (and only if transcription was on)
- ✓That person's own calendar, to offer their meetings for capture
- ✓SharePoint or OneDrive files that person can already open, in the folders they point Evidos at
What it cannot do
- ✕Act on its own — there is no service account and no tenant-wide feed
- ✕Join or sit in on meetings — there is no bot in the room
- ✕See anything for people who haven't connected
- ✕Read email or chat messages — not requested at all
- ✕Create, move, or delete content; the only write is an organizer-confirmed automatic meeting setting
What you control
- →The org-level approval itself — grant it, see it, revoke it in your admin portal
- →Who connects: each person's connection is individually visible and revocable
- →Instant off — disable the app in Enterprise applications, or disconnect in Evidos
- →Whether automatic recording and transcription is enabled for each eligible future meeting
The one idea that makes this safe
Evidos uses delegated access — the same mechanism Microsoft uses when any app acts on a signed-in person’s behalf. It borrows the consultant’s own key while they work; it never receives a master key to your organization. What Evidos can reach is always the intersection of two things: what that person could already open, and what they deliberately point Evidos at.
Capture is also native to Microsoft. Evidos never places a bot or recorder in your calls. For an eligible future meeting you organize, Evidos can change only the automatic recording and transcription setting after your explicit confirmation. Teams performs the capture and shows its own recording and transcription notice to every participant.
Why this matters
Remove a consultant’s access to a site, a folder, or a meeting, and Evidos’s view of it disappears with them, automatically. Your existing permission model is the boundary — Evidos never adds a new one.
How the setup works
One approval, then each consultant connects themselves. Nothing to install, no values to send anywhere.
1Your administrator clicks Accept
~1 minEvidos sends a standard Microsoft approval link. It opens Microsoft’s own consent screen listing every permission (the same list as on the technical page) — one Accept records the approval in your tenant. No app to create, no secrets, nothing to send back.
2Consultants sign in with Microsoft
~1 min eachAfter the approval, “Sign in with Microsoft” connects each person’s account in the same motion — no extra prompts. Each connection is individual and individually revocable.
3Work starts
—Consultants pick meetings from their own calendar and connect the engagement’s SharePoint folder. Everything Evidos reads arrives through those explicit choices.
Where your data goes
When Evidos reads a transcript or document, it uses a top-tier AI model under a strict Zero-Data-Retention arrangement: your content is never used to train any model and is not retained by the AI provider. The evidence base itself is stored in Canada. Evidos’s promise is provenance, not paraphrase — every claim keeps the record’s exact words and a link straight back to the source, so anything it tells you is auditable.
No cost on the Microsoft side
The connection uses standard Microsoft 365 APIs that are not metered, so there is no Azure billing to set up.
Common questions
Can Evidos read every meeting in our organization?+–
No. Evidos only ever acts as a signed-in consultant, and transcripts are readable only for meetings that consultant organized. People who never connect are invisible to it.
Does Evidos record or listen to our calls?+–
Evidos never joins or listens to a call: there is no bot or Evidos recorder. If an organizer explicitly opts in, Evidos asks Teams to enable its native automatic recording and transcription setting. Teams performs the capture and notifies every participant.
What can it see in SharePoint?+–
Only what the connected consultant can already open, and in practice only the project folders they deliberately connect to an engagement. Evidos holds no site access of its own — revoke the person’s access and Evidos’s view goes with it.
Can Evidos change or delete anything in our environment?+–
Evidos cannot write to, move, or delete your files, mail, chats, or calendar events. Its only scoped mutation is the automatic recording and transcription setting on a future Teams meeting organized by the connected consultant, after an explicit confirmation.
What about email?+–
Email isn’t part of this at all — no mailbox permission is requested.
Ready for your IT administrator?
The technical page has the full permission list, the approval flow, and every way to revoke it.
See the technical setup →Back to sign in