Microsoft 365 setup · technical
Everything your administrator needs — the one-click approval, the complete delegated permission list, and every way to revoke it.
A one-minute readiness check.
Evidos is a single multi-tenant application. Your approval is a standard Microsoft admin consent — the same flow you use for any vetted vendor app.
Your Evidos contact (or the firm’s first administrator, from inside Evidos) sends you Microsoft’s admin consent link for the Evidos application. It opens Microsoft’s own consent screen listing exactly the permissions in the table below. Clicking Accept records the approval in your tenant — visible afterwards under Enterprise applications in the Entra admin center, like any other approved app.
That is the whole setup on your side. There is no app registration to create, no client secret, and nothing to send back. After the approval, each consultant’s “Sign in with Microsoft” connects their own account without further prompts.
Every permission is delegated
If Evidos's permissions ever change
The complete list on the consent screen — nothing is requested that isn't here.
| Permission | What it lets Evidos do | What it does not allow |
|---|---|---|
| OnlineMeetingTranscript.Read.All (delegated)Read meeting transcripts | Read transcripts of Teams meetings the signed-in consultant organized — and only when transcription was turned on in the meeting. | No transcripts for meetings they didn't organize; nothing for people who never connect. |
| OnlineMeetings.ReadWrite (delegated)Match meetings and set automatic capture | Look up the signed-in consultant's own Teams meetings and, only after their explicit confirmation, change only the automatic recording and transcription setting on an eligible future meeting they organize. | No other users' meetings; no series-wide change; no change after a meeting starts; no other meeting fields. |
| Calendars.Read (delegated)Read their own calendar | Show the signed-in consultant their own recent and upcoming meetings so they can pick which ones belong to the project. | No other calendars; not used to mine anything — the consultant picks each meeting. |
| Files.Read.All (delegated)Read files they can open | Read SharePoint/OneDrive files the signed-in consultant can already open — used to ingest the project folder they connect to an engagement. | No access of its own: if the consultant can't open a file, neither can Evidos. No write, upload, or delete anywhere. |
| AllSites.Read · MyFiles.Read (SharePoint, delegated)Browse with Microsoft's file picker | Let the consultant browse their SharePoint in Microsoft's own embedded file picker to choose a project folder — again strictly as themselves. | Same ceiling as above: their existing access, read-only. |
| openid · profile · email · offline_accessSign in and stay connected | Let your people sign in to Evidos with their Microsoft account and keep their own connection alive between sessions. | Identity only — no access to any content. |
Explicitly not requested: application permissions of any kind, email/mailbox access, Teams chat messages, directory export, or general file/calendar write access. Evidos cannot create, move, delete, or send content in your tenant; the single delegated write changes only the automatic recording and transcription setting described above.
Optional — for organizations that only allow apps registered in their own directory.
Evidos also supports running against your own Entra app registration: your admin creates the app in your tenant with the same delegated permissions listed above and enters its identifiers in Evidos’s advanced settings. All credentials then live under your control, with your own expiry and rotation policy. Ask your Evidos contact for the walkthrough if your security policy requires this path — most organizations use the one-click approval instead.
Any one of these cuts access immediately — you never have to call us to turn it off.
myapps.microsoft.com.Evidos reads transcripts and documents with a top-tier AI model under a strict Zero-Data-Retention arrangement: your content is never used to train any model and is not retained by the AI provider. The evidence base is stored in Canada. Every finding Evidos surfaces keeps the record’s exact words and a link back to the source, so it is auditable.