← Overview

Microsoft 365 setup · technical

Technical setup

Everything your administrator needs — the one-click approval, the complete delegated permission list, and every way to revoke it.

Global Administratordelegated onlyone scoped meeting write~5 minutes

Before you start

A one-minute readiness check.

Who approves
A Global Administrator (or any role your organization allows to grant tenant-wide admin consent).
Time
About five minutes: open the link, read the permission screen, click Accept.
Have ready
A Microsoft 365 tenant with Teams. For transcript capture, meeting transcription must be allowed in your Teams policies (it usually already is).
Cost
None on the Microsoft side — the APIs used are not metered, and nothing is created in your Azure subscription.

The approval — one click

Evidos is a single multi-tenant application. Your approval is a standard Microsoft admin consent — the same flow you use for any vetted vendor app.

Your Evidos contact (or the firm’s first administrator, from inside Evidos) sends you Microsoft’s admin consent link for the Evidos application. It opens Microsoft’s own consent screen listing exactly the permissions in the table below. Clicking Accept records the approval in your tenant — visible afterwards under Enterprise applications in the Entra admin center, like any other approved app.

That is the whole setup on your side. There is no app registration to create, no client secret, and nothing to send back. After the approval, each consultant’s “Sign in with Microsoft” connects their own account without further prompts.

Every permission is delegated

Delegated means the app can only act while a signed-in person is using it, within that person’s own access. Evidos requests no application permissions — the kind that would let a service read tenant-wide without a user. There is no service account to audit because none exists.

If Evidos's permissions ever change

New permissions never activate silently: if the list below grows, Microsoft blocks the new capability until your administrator approves again — via the same link, or the Grant admin consent button on the Evidos entry in Enterprise applications. Evidos will tell you when that applies.

Every permission, in plain terms

The complete list on the consent screen — nothing is requested that isn't here.

PermissionWhat it lets Evidos doWhat it does not allow
OnlineMeetingTranscript.Read.All (delegated)Read meeting transcriptsRead transcripts of Teams meetings the signed-in consultant organized — and only when transcription was turned on in the meeting.No transcripts for meetings they didn't organize; nothing for people who never connect.
OnlineMeetings.ReadWrite (delegated)Match meetings and set automatic captureLook up the signed-in consultant's own Teams meetings and, only after their explicit confirmation, change only the automatic recording and transcription setting on an eligible future meeting they organize.No other users' meetings; no series-wide change; no change after a meeting starts; no other meeting fields.
Calendars.Read (delegated)Read their own calendarShow the signed-in consultant their own recent and upcoming meetings so they can pick which ones belong to the project.No other calendars; not used to mine anything — the consultant picks each meeting.
Files.Read.All (delegated)Read files they can openRead SharePoint/OneDrive files the signed-in consultant can already open — used to ingest the project folder they connect to an engagement.No access of its own: if the consultant can't open a file, neither can Evidos. No write, upload, or delete anywhere.
AllSites.Read · MyFiles.Read (SharePoint, delegated)Browse with Microsoft's file pickerLet the consultant browse their SharePoint in Microsoft's own embedded file picker to choose a project folder — again strictly as themselves.Same ceiling as above: their existing access, read-only.
openid · profile · email · offline_accessSign in and stay connectedLet your people sign in to Evidos with their Microsoft account and keep their own connection alive between sessions.Identity only — no access to any content.

Explicitly not requested: application permissions of any kind, email/mailbox access, Teams chat messages, directory export, or general file/calendar write access. Evidos cannot create, move, delete, or send content in your tenant; the single delegated write changes only the automatic recording and transcription setting described above.

If your policy requires your own registration

Optional — for organizations that only allow apps registered in their own directory.

Evidos also supports running against your own Entra app registration: your admin creates the app in your tenant with the same delegated permissions listed above and enters its identifiers in Evidos’s advanced settings. All credentials then live under your control, with your own expiry and rotation policy. Ask your Evidos contact for the walkthrough if your security policy requires this path — most organizations use the one-click approval instead.

How to undo everything

Any one of these cuts access immediately — you never have to call us to turn it off.

Org-wide, Microsoft
In Enterprise applications, open the Evidos entry and revoke its permissions or delete it. Every connection in your tenant stops working.
Org-wide, Evidos
A firm administrator can disconnect the organization in Evidos’s workspace settings — this also deletes every stored per-person connection.
One person
Each consultant can disconnect their own account in Evidos’s settings; users can also revoke the app themselves at myapps.microsoft.com.
At the source
Turn Teams transcription off — no transcripts are produced, so there’s nothing to read.

Where your data goes

Evidos reads transcripts and documents with a top-tier AI model under a strict Zero-Data-Retention arrangement: your content is never used to train any model and is not retained by the AI provider. The evidence base is stored in Canada. Every finding Evidos surfaces keeps the record’s exact words and a link back to the source, so it is auditable.

Questions your team may ask

Can Evidos read every meeting in our organization?+
No. Every permission is delegated: Evidos only acts as a signed-in consultant, and transcripts are only readable for meetings that consultant organized. Nothing is reachable for anyone who never connects.
Whose directory does the application live in?+
The application itself is Evidos’s multi-tenant registration; what lives in YOUR directory is the consent record — fully visible under Enterprise applications and revocable there at any time. Organizations that require the app itself to live in their own tenant can use the own-registration path above.
Is our data used to train AI, and where is it stored?+
Never used for training, not retained by the AI provider (Zero-Data-Retention); the evidence base is stored in Canada.
Why does the consent screen mention reading 'all' files or transcripts?+
Microsoft's scope names say “All” to mean “everything the signed-in user can access” — not everything in the tenant. Delegated access is always capped by the person's own permissions; Evidos adds nothing on top.

← Back to the overview·Sign in