Skip to main content

📁 Connect Cobrief to SharePoint and OneDrive

Give the AI agent access to search and read your documents in SharePoint and OneDrive with your own permissions.

Written by Audun Wigum Arbo

With the SharePoint integration, Cobrief's AI agent can search and read your documents in SharePoint and OneDrive directly in a conversation. You no longer have to upload information manually. The agent fetches what it needs from Microsoft 365, based on what you personally have access to.

The SharePoint integration is available on paid plans and requires a work Microsoft 365 account (not a personal Microsoft account). You use it through the AI agent, so you need the administrator or member role. Contributors don't have access to the agent. Read more about roles and permissions.

What can the AI agent do?

Once you have connected, the agent can:

  • Search for documents across the SharePoint sites and OneDrive you have access to.

  • Browse sites and folders to find the right file.

  • Read the contents of documents (Word, Excel, PowerPoint, PDF, images, and more) and use the information in your bid work.

Access is read-only. Cobrief can never create, change, delete, or share anything in SharePoint or OneDrive.

How to connect

You can connect in two ways.

From settings

  1. Go to "Settings" → "Integrations".

  2. Find SharePoint and click "Connect".

  3. Sign in with your Microsoft 365 account and approve access.

Once the connection is complete, you'll see "SharePoint was connected", and the card shows which account you are connected with.

Control what the agent may do

Administrators can decide how the agent may use SharePoint for everyone in the workspace. Open the SharePoint card under "Settings" → "Integrations", then choose one of these levels:

  • Always allow: The agent can use the tool without asking for approval.

  • Needs approval: The agent asks in the conversation before using the tool.

  • Blocked: The agent cannot use the tool.

You can set the same level for all read-only tools or choose a level for each tool. Administrators see the settings even if they haven't connected SharePoint themselves. Members who have connected can view the settings, but only administrators can change them.

SharePoint tool permissions under Integrations

From a conversation

  1. Open the "Connectors" menu in a conversation.

  2. Click "Connect" next to SharePoint and sign in with Microsoft 365.

  3. Switch on the toggle next to SharePoint to let the agent use the connection in that specific conversation.

Using SharePoint in a conversation

The agent uses SharePoint when it's relevant to what you ask. For example, you can ask it to:

  • "Find the latest version of our quality manual in SharePoint"

  • "Get the key figures from last year's annual report in OneDrive"

  • "Summarize our reference projects from the SharePoint site for tenders"

You decide which conversations have access. Use the toggle next to SharePoint in the "Connectors" menu to switch the connection on or off in a single conversation.

Disconnect or reconnect

You manage the connection under "Settings" → "Integrations".

  • To disconnect, click "Disconnect" and confirm. Cobrief then loses all access to your Microsoft account.

  • If the connection expires or is revoked, you'll see a message that you need to "Reconnect". Click it to continue.

Security and privacy

We take the security of your data seriously:

  • The agent only gets access to files you already have access to in Microsoft 365. The connection uses your own permissions (delegated access) and cannot bypass your organization's access controls.

  • Read-only access. Cobrief cannot create, change, delete, or share anything.

  • The files are only retrieved when the AI is actively working, and are never persisted on Cobrief's servers.

  • The AI can reproduce content from the files and use them as a basis for new content. This may include messages and bid documents that are saved in Cobrief.

  • You can disconnect at any time under "Settings" → "Integrations".

The connection requests these read permissions from Microsoft: User.Read (your profile), Sites.Read.All (SharePoint sites you have access to), and Files.Read.All (files in SharePoint and OneDrive you have access to).

Read more about how we work with security and privacy in our Trust Center.

Can Cobrief be limited to specific SharePoint sites?

Not today. The agent can read what the connected account can read, no more and no less. You can't pick one site or folder in Cobrief and close off the rest.

The reason is search. When the agent searches SharePoint, it uses Microsoft's search across your whole organization. That search requires the Sites.Read.All permission. Microsoft offers narrower permissions that lock an app to selected sites (called "Sites.Selected"), but search doesn't honor them. If we used them, the agent couldn't search at all. This applies to every tool that searches SharePoint through Microsoft Graph, not just Cobrief.

We know many of you want to connect Cobrief to a single tender site only. Below you'll find what you can do today. Let us know if this matters to your organization.

For IT administrators: how to limit access today

The options below can be combined. The first is the only one that actually limits what Cobrief can technically read. The others control who can connect, what is searchable, and what the agent does.

Menus and settings in the Microsoft portals use the English names from Microsoft's documentation. If you use another language in the portals, the translated names appear in the same place.

Use a dedicated account for tender work

This is what we recommend when Cobrief should only reach your tender site.

  1. Create a dedicated user in Microsoft 365, for example [email protected], and give it a license that includes SharePoint (for example Microsoft 365 Business Basic).

  2. Give the user access to the tender site, and no other sites. Add it to the site's "Visitors" group (read only) if it only needs to read.

  3. Turn on multi-factor authentication for the user, and keep it out of groups that grant access to other sites.

  4. Have the person using Cobrief connect SharePoint with this user instead of their own.

The card under "Settings" → "Integrations" shows which account is connected, so it's easy to verify. Keep in mind that the agent can also search the connected account's OneDrive.

Control who can connect

In Microsoft Entra you can decide who is allowed to use the Cobrief app at all. You need the Cloud Application Administrator role or higher.

  1. Sign in to the Microsoft Entra admin center and go to "Entra ID" → "Enterprise apps" → "All applications".

  2. Search for and open the app Cobrief M365. The app appears there after someone connects for the first time, or after an administrator approves it.

  3. Select "Properties" under "Manage". Set "Assignment required?" to "Yes" and select "Save".

  4. Select "Users and groups" → "Add user/group", and add the users or the group who are allowed to connect. Group assignment requires Microsoft Entra ID P1 or higher.

When the app requires assignment, an administrator must grant consent for the whole organization once. Users can no longer consent on their own. You can also disable user consent for all apps under "Enterprise apps" → "Consent and permissions" → "User consent settings". IT then has to approve Cobrief before anyone can connect.

Hide specific sites from search

A SharePoint site owner can keep a site out of the search index. The agent then won't find its content when it searches.

  1. Open the site, select the "Settings" gear in the top right, then "Site information" → "View all site settings". On some sites, "Site settings" appears directly in the menu.

  2. Under "Search", select "Search and offline availability".

  3. Under "Indexing Site Content", set "Allow this site to appear in Search results" to "No", and select "OK".

Note that this hides the site from all search in Microsoft 365, including for your colleagues. It doesn't change permissions. If a user shares a direct link to the site, the agent can still browse it.

Limit what the agent does in Cobrief

The tool permissions under "Settings" → "Integrations" control what the agent may do for everyone in the workspace. This combination means the agent can only read folders and files the user links to:

  • "Search SharePoint": Blocked

  • "Browse SharePoint": Needs approval

  • "Read SharePoint file": Always allow

The user pastes the link to the tender site into the conversation and approves each time the agent wants to open a folder. The agent can't browse freely.

You can also tell the agent which site to use with AI instructions. For example: "Always use the SharePoint site https://yourcompany.sharepoint.com/sites/Tenders when looking for tender documents." This helps the agent find the right site in a large structure, but it isn't a security boundary.

What doesn't work

Conditional Access policies based on location or network can't be used to limit Cobrief. Cobrief fetches documents from our servers, not from the user's device. Such a policy blocks the connection entirely instead of limiting it.

Can't connect?

Some organizations require a Microsoft 365 administrator to approve new apps before they can be used. If you're told that access needs to be approved, it means your organization restricts which apps can be connected. Contact your IT lead or administrator to have access approved.

Did this answer your question?